Sovereign AI: the next cloud-sized wave for enterprise software

Disclosure: I'm a Product Manager at Microsoft, working on Azure Arc. The views below are my own, not my employer's.

AI is the biggest technological shift since the industrial revolution, and it's going to touch every company on the planet. That's a big claim, so here's why it isn't hyperbole: every previous enterprise-technology wave, cloud included, added capability to what a company already does, cheaper and faster. AI is different in kind, not degree, because what it produces is a working approximation of intelligence, and intelligence isn't a layer you sit underneath a business. It's a layer you sit inside of.

Every company draws a line between what it outsources and what it doesn't, and that line has always tracked competitive relevance, not cost. Payroll, IT helpdesk, facilities management: none of that is core to why a company wins, so it gets handed to a vendor without a second thought. Design and product architecture, manufacturing process, R&D: that never gets outsourced, because it's the edge a competitor would pay to know. Intelligence, as AI takes on more of what a company actually does, doesn't land on the payroll side of that line. It lands on the design-and-research side, and for a growing number of companies it starts to be that side: the actual mechanism by which decisions get made. That's not a layer any serious company can afford to rent indefinitely from someone else.

Compute and storage never forced companies to make that call, because compute and storage are commodity substrate: an enterprise that runs entirely on one cloud provider is making a real bet, but it's a portability bet — a VM or a storage bucket doesn't learn anything about the business running on it. Token generation is different by construction. Using a third-party-hosted closed model means feeding it the proprietary data and workflows that make it useful, and access to that model has already proven revocable for reasons that have nothing to do with the vendor relationship (more on that below). Single-sourcing a commodity is a supply-chain risk. Single-sourcing the intelligence layer of your business, one a competitor can absorb the fingerprints of and a government can switch off overnight, is a different order of exposure entirely.

That's the bet behind sovereign AI: enterprises owning their models, their data, and their deployment, rather than renting all three from a handful of closed-model providers. It's early. But the trajectory looks a lot like cloud's did in its own early years, and I think it's the next wave enterprise software companies should be building for.

How big, actually

Enterprise AI spend today is still a fraction of enterprise cloud spend: tens of billions ($24–33B) against enterprise cloud's $750–850 billion footprint today. But enterprise AI is compounding at roughly 35–38% a year against cloud's 12–17%, and the adoption curve is compressed: 78% of companies had at least one AI business function by 2025, up from 55% just two years earlier, with 71% running generative AI regularly across business functions. Cloud took the better part of a decade to reach that level of enterprise penetration. AI got there in about two years.

AWS launched in 2006, ChatGPT in 2022 — both landing in a market sitting at roughly $10–20B a year. Project that forward eight years: by 2014, pure enterprise IT spending on public cloud services reached $56.6 billion. Enterprise AI is forecast to reach $155 billion at its own year eight (2030). AI isn't just matching cloud's curve — it is projected to reach nearly 2.7 times the size of enterprise cloud at the same stage in its lifecycle.

Pasted image 20260726080652.png

AI is behaving like cloud did, just compressed and at a significantly higher enterprise volume.

This adoption curve is underpinned by multiple waves of AI, starting with technologies like vision models, which moved manufacturing quality assurance from manual inspection to automated, always-on defect detection, attacking a problem that causes 20 cents of every dollar spent in manufacturing to be wasted, roughly $8 trillion globally by Bain estimates. The next big wave is agentic control, where systems are given controlled autonomy to adjust production in real time, with humans shifting from operators to supervisors of a fleet of agents rather than the ones running the line. This is a reality at Xiaomi's smartphone plant running 24/7 with no one on the floor, powered by an AI platform (HyperIMP) that streams data from every machine, catches anomalies before they cascade, and resolves minor defects and process tweaks autonomously. A Chinese textile plant runs 5,000 looms the same way. Just two examples of enterprise AI's much faster adoption curve vs. cloud.

The AI control spectrum

Every enterprise sits somewhere on a spectrum of how much control it has over the AI it depends on:

Fully outsourced. A closed model, accessed via API, hosted on someone else's infrastructure. Zero control over availability, pricing, or what happens to your usage data.

Privately hosted, still closed. A closed model, deployed on your infrastructure or at the edge by its provider, but still their weights, still their terms.

Fully sovereign. An open-weights or custom model, deployed wherever you want, with nobody's permission required to keep running it.

Most enterprises today sit in the first category by default, simply because it was the only practical option until recently. The direction of travel is toward the second and third.

Why the first two options are shakier than they look

The first category's risk is perhaps the one people are now talking about the most: a closed-model provider can throttle access, change pricing, or lose the ability to serve you for reasons that have nothing to do with your business. This isn't hypothetical anymore. In June 2026, the U.S. government forced Anthropic to suspend access to two of its newest models for all users, worldwide, over export control concerns, reinstated a few weeks later, but not before enterprises that had built on those models got a very concrete lesson in what single-sourcing a government-reviewable technology looks like. OpenAI hit a version of the same wall days later, previewing its next model family to a short list of vetted partners rather than the public. Frontier models are being treated as national-security assets now, and that changes the calculus for anyone depending on one.

The second category, private deployment of a closed model, sounds like the answer, but it runs into a structural problem that has nothing to do with goodwill. A closed-model provider's business is built on two things: the model weights, and the telemetry of how those weights get used. Handing an enterprise a fully unrestricted, air-gapped copy of a flagship model gives away any telemetry, and potentially the weights as well, unless it's deployed carefully — orchestrating multiple products from different vendors across a nascent tech stack called confidential computing. Something closed-source model makers are still getting used to. That's not a policy a lab is likely to offer generously, and it's not a cheap solution either, pushing solutions to a seven-figure baseline for customers.

(Worth noting that this argument is about private and public companies. Governments are a different case entirely, with their own negotiated access to air-gapped models, a separate conversation.)

The only 'sustainable' option, enabled by open-weight models

Most enterprises are now realizing sovereign AI, where they control their intelligence and the infrastructure that makes it run, is perhaps the only sustainable option available to run their operations on.

This is where open-weight models stop being a side debate about model quality and become the mechanism that makes real sovereignty possible. Openness and air-gappability are close to the same property: if you have the weights, you can run the model anywhere, forever, with no one's permission and no telemetry flowing back to anyone. A restricted private deployment of a closed model can't offer that, by construction.

The performance gap between open and closed models has also been closing faster each cycle, reaching 90% of the performance on most tasks at a fraction of the cost. The qualitative trend is consistent enough that "open models are good enough for most of what enterprises actually need" is no longer a controversial claim. As that keeps happening, paying frontier prices and accepting frontier dependency risk stops making sense for a growing share of everyday token-enabled tasks.

The real moat is data, not weights

Here's the part that I think gets missed in most sovereign AI takes: the reason open models matter isn't just deployment freedom. It's that they're structurally better suited to capturing what's actually valuable, an enterprise's own data, on two counts at once: they're the ones you can actually tune on that data, and they're the ones that don't require handing it to a competitor to do so.

Start with the tuning case. A model acquires role-specific capability (the ability to act like a competent software engineer, or UX designer, or clinical analyst) in the final stage of training, where it's shown examples of what good work looks like in that domain. That requires domain-specific data. Software engineering is the one field where this data was given away for free, at scale, through decades of open source, which is a large part of why coding is the area LLMs became really capable at first. Other domains don't have that advantage. The data that would teach a model to be a great insurance underwriter, manufacturing quality engineer, or corporate lawyer sits locked inside the companies that do that work, and most of those companies haven't priced it as the asset it is.

On the ownership side, no enterprise can afford to hand its core competency to another company, and running proprietary data through a third-party closed model's API, whether for inference or fine-tuning, risks doing exactly that. Palantir CEO Alex Karp put this bluntly in a July 2026 CNBC interview: "The basic view among enterprises in this country is: I'm going to chillax and waste my time with tokens, I'm going to get no value, and they're going to get my IP." His word for what's at stake is alpha, the unique competitive edge that differentiates a business, and he says enterprise customers are increasingly unwilling to hand it over. Your data isn't just an input to a vendor's model; it's your business's edge, and once it's run through someone else's infrastructure, you no longer fully control what happens to it.

Satya Nadella is making the same point. In a July 2026 post, he calls this the "Reverse Information Paradox": you pay for intelligence twice, once in money and once in the proprietary knowledge you have to feed the model to make it useful. He quotes Karp's "alpha" line directly as the same concern.

Figma found this out directly. In April 2026, Mike Krieger, Anthropic's chief product officer and a sitting board member at Figma, resigned from Figma's board. Three days later, Anthropic launched Claude Design, a product that competed directly with Figma's core business. Figma's CEO later said, in front of Figma's own board, that Anthropic "were not consistently candid" with them. The lesson isn't that Anthropic acted in bad faith by some unusual standard: it's that "we won't train on your data" and "we won't act on what we learn about your business by watching you use our product" are two entirely different promises, and only one of them is usually made explicitly.

This is exactly where open models win on both counts. Fine-tuning a closed model through a provider's API doesn't fix the ownership problem: you're renting an adapted instance you can't take with you, still dependent on that provider's infrastructure and pricing, and still handing your training data to the exact company whose dependency you're trying to escape. Fine-tune an open model instead, and you own the resulting artifact outright: deployable anywhere, including fully air-gapped, with no one else's telemetry attached to it. The tuning capability and the IP protection aren't two separate benefits: they're the same property, because owning the weights is what makes both possible.

On top of that, you get efficiency gains. A 27-billion-parameter open model, fine-tuned on tens of thousands of domain-specific examples, outperformed Claude Sonnet 4, a much larger closed model, by 60% on a specialized clinical scribe task, while running smaller, faster, and cheaper. That's not an isolated result: fine-tuned open models in the 7–13-billion-parameter range routinely beat much larger general-purpose closed models on narrow, well-defined tasks. The honest caveat is that closed frontier models still lead on broad, open-ended reasoning and genuine edge cases, so the architecture most people are converging on is two-tier: a frontier model handling orchestration and the unexpected, fine-tuned open models handling the well-defined, high-volume domain work, with an enterprise's proprietary data never leaving its own hands.

Who captures the opportunity

Enterprise architecture moves in long pendulum swings. Everything sat on-prem through the 2000s. Then the cloud wave pulled it as far to the other extreme as it would go: for the last fifteen years, the default assumption has been "move everything you can off your own hardware." Sovereign AI is the swing back toward center: not back to on-prem, but to hybrid as the new steady state. Enterprises will keep running plenty of workloads in the cloud (there are many use cases where cloud makes sense), but the on-prem and edge share of the mix grows from here, pulled specifically by the sovereign workloads described above. Three groups are positioned to capture that shift.

The hardware layer. Dell, HPE, Lenovo, Supermicro, the OEMs that build the physical servers enterprises run on-prem, are in an unusually good spot for this cycle. Dell is already reporting share gains specifically among enterprises and sovereign-AI buyers building out their own capacity. More on-prem and edge deployment looks close to a straight tailwind for this group, not a shared one.

The hyperscalers. Their focus needs to go back to the edge: they need to make hybrid and air-gapped deployments feel like more cloud, not less, by offering a software stack that carries the same AI models, APIs, and tooling from their cloud straight onto an enterprise's own hardware. Microsoft's Foundry Local runs the same SDK and API surface as Foundry in Azure, on-prem or fully disconnected via Azure Arc, so a team can prototype in the cloud and ship the identical code to the edge. Google Distributed Cloud does the equivalent, now running Gemini itself on air-gapped, fully disconnected hardware for government and regulated industries. AWS covers the same ground with SageMaker-on-Outposts, extending SageMaker's training and inference tooling onto customer-owned hardware. All three are still early relative to the size of enterprise demand, and none has a clear lead yet; whichever hyperscaler gets sovereign AI right first gets to capitalize on a once-in-a-generation opportunity by keeping intelligence workloads at the edge that would otherwise migrate to competitors or smaller, sovereignty-focused vendors.

The systems integrators. The third group is the companies that go in and actually build and fine-tune an enterprise's sovereign models, and this one's already visible in the numbers, not just the thesis. Palantir pioneered the "forward-deployed engineer" model: send engineers to live inside a customer's operations and build the AI system alongside them, on their data, on their infrastructure. It's a real part of why Palantir's revenue grew 85% year-over-year in Q1 2026, its fastest growth since going public, with US commercial revenue up over 100%. The rest of the industry has now piled into the same model: AWS put $1 billion into its own forward-deployed engineering unit in June 2026, Microsoft launched a $2.5 billion "Frontier Company" employing roughly 6,000 embedded engineers days later, and OpenAI and Anthropic each stood up comparable units in May 2026: north of $9 billion committed to the same idea in about two months. That money isn't earmarked for sovereign AI specifically; it's a response to a broader problem: getting AI to actually work inside an enterprise has turned out to be harder than the industry expected, and off-the-shelf deployment keeps falling short of what customers need. Sovereign and edge deployments, with their added infrastructure and data-locality constraints, are simply the sharpest edge of that same problem, and they'll absorb a growing share of this forward-deployed capacity as they scale. Either way, a deployment this complex doesn't sell itself off a shelf; someone has to sit inside the customer and build it with them.

Cloud rewarded the companies that helped enterprises stop building their own data centers. Sovereign AI rewards the opposite motion: whoever helps them build, own, and scale the intelligence that matters most, instead of renting it on someone else's terms.


Sources

Market size and growth

  • Enterprise AI market, $23.9B (2024) to $155.2B (2030), 37.6% CAGR: Grand View Research
  • Enterprise AI adoption, 78% of companies with an AI function in 2025 (up from 55% in 2023), 71% using generative AI regularly: Cervicorn Consulting

Cloud market history (for the years-since-inception comparison)

Manufacturing and agentic AI

  • Bain estimate: 20 cents of every manufacturing dollar wasted, ~$8 trillion globally; Instrumental and Elementary case studies: BuildMVPFast
  • Agentic AI introducing "controlled autonomy" into quality systems, human-in-the-loop: Azilen
  • Xiaomi's "dark factory" and HyperIMP autonomous manufacturing platform: CIO VisionariesOpen Magazine
  • Chinese textile plant automating 5,000 looms, lights-out 24/7 operation: RoboHorizon

Fine-tuning: open vs. closed models

  • Fine-tuned 27B open model (Gemma 3) outperforming Claude Sonnet 4 by 60% on a clinical scribe task: Together AI / Parsed
  • Fine-tuned 7-13B open models outperforming larger general-purpose closed models on narrow tasks: MindStudio

Open models closing the gap with close models

  • Kimi K3 Model Overview: 2.8T Parameters, MXFP4 Quantization, and What the Open Weights Mean for the Community: Huggingface
  • AI open models have benefits. So why aren't they more widely used?: MITSloan

Frontier model access risk

  • June 2026 U.S. export-control suspension of Anthropic's Fable 5 and Mythos 5, restored July 1: Let's Data Science
  • Same episode, enterprise risk framing: Algo & Art
  • OpenAI's GPT-5.6 limited to vetted partners after government request: TechCrunch

Palantir / Alex Karp

  • Alex Karp's CNBC Squawk Box interview on enterprises' fear of losing IP and "alpha" to frontier AI labs: Yahoo Finance / Benzinga
  • Satya Nadella, "The Reverse Information Paradox" (July 2026), on enterprises needing their own trust boundary and learning infrastructure, quoting Karp on "alpha": sn scratchpad

Figma / Anthropic

  • Mike Krieger's board resignation and the Claude Design launch, timeline and Figma CEO's "not consistently candid" quote: Upstarts Media
  • Same episode, additional detail on dates and stock impact: CryptoBriefing

Hardware OEMs

Hyperscaler hybrid/edge software stacks

Systems integrators and forward-deployed engineering

  • Palantir Q1 2026 revenue growth of 85% YoY, US commercial revenue growth over 100%, driven by its forward-deployed engineering model: CNBCPalantir investor release
  • AWS's $1 billion forward-deployed engineering unit (June 2026): CNBC
  • Microsoft's $2.5 billion "Frontier Company," ~6,000 embedded engineers (July 2026): Tech Times
  • Overview of Microsoft, AWS, OpenAI, and Anthropic's combined $9B+ bet on forward-deployed engineering: Let's Data Science