In most European boardrooms the AI question has changed shape. Two years ago it was “should we use AI?”; in 2026 it is “where does it run, and who can see the data?” Local AI, also called on-premise or sovereign AI, is the answer a growing share of Swedish and EU organisations are giving: the models run on hardware the organisation owns and controls, inside its own walls, instead of in a vendor's cloud.
This guide covers why that shift is happening now, which sectors in Sweden and the wider EU are actually deploying local AI, what the deployment options look like, and what to demand from any vendor who says the word “sovereign”.
Why European organisations are bringing AI in-house
The baseline is the GDPR. The moment an employee pastes a customer record, a patient note or a personnel file into a cloud assistant, the organisation is processing personal data on someone else's infrastructure, which triggers processor agreements, transfer analyses and, when things go wrong, fines that can reach 4% of global turnover. None of that paperwork exists for a model that never leaves the building.
The second driver is the transfer problem the Schrems II judgment created in 2020 and no amount of contractual engineering has fully solved since. Data residency is not data sovereignty: a US-owned cloud region in Frankfurt or Stockholm is still subject to US law, including the CLOUD Act's reach into data held abroad by American providers. For Swedish public bodies and German regulated industries alike, that residual risk has quietly shaped cloud policy for half a decade.
The third driver has a timetable: the EU AI Act entered into force in August 2024 and its obligations arrive in phases. Self-hosting does not exempt anyone from the Act, but it makes the compliance file dramatically simpler, because the deployer controls the logs, the model versions and the data flows it must document.
| Date | What starts applying |
|---|---|
| 2 Feb 2025 | Bans on prohibited AI practices; AI-literacy duties |
| 2 Aug 2025 | Obligations for general-purpose AI models; governance rules |
| 2 Aug 2026 | Most high-risk system obligations (Annex III) |
| 2 Aug 2027 | High-risk rules for AI embedded in regulated products |
Around the AI Act sits a thicket of sector rules pushing the same direction: NIS2 for critical infrastructure, DORA for financial institutions since January 2025, professional privilege for law firms, and secrecy legislation for the public sector. In Germany, works councils and BSI security expectations add their own gravity toward on-premise deployment.
None of this makes cloud AI illegal. It makes cloud AI expensive to justify: every cloud assistant now carries a standing compliance burden, while a local deployment removes most of the questions instead of answering them.
Who is deploying local AI in Sweden and the EU
Adoption follows a simple pattern: the sectors deploying local AI first are the ones that were never able to use cloud AI properly in the first place.
- Healthcare, clinics and care providers running assistants over patient documentation, where GDPR Article 9 special-category data rules out external processing.
- Legal, firms that cannot put privileged client material into any third-party service, but still want drafting, summarisation and research over their own matter files.
- Financial services, banks and insurers balancing DORA, banking secrecy and outsourcing rules, where an on-premise model sidesteps the vendor-risk file entirely.
- Public sector, Swedish agencies and municipalities whose cloud caution since Schrems II is well documented, and who increasingly specify sovereignty in procurement.
- Manufacturing and defence, companies protecting product IP and export-controlled information, often on air-gapped networks where cloud AI is simply impossible.
What these organisations run locally is no longer a compromise: private ChatGPT-style chat for employees, retrieval-augmented answers over internal documents, drafting and summarisation, and OpenAI-compatible APIs that let internal tools call a local model exactly as they would call a cloud one.
The vendor landscape splits into three camps. Hyperscalers now market “sovereign cloud” regions, better than nothing, but the stack, the keys and the legal entity questions remain debated. European API providers keep inference on EU soil but still off your premises. And a third camp puts the AI inside your building: Kaldryn, built by Pontén Solutions in Stockholm, is a Swedish example of that approach, shipping Kaldryn One, a locker-sized appliance that runs a full ChatGPT-class assistant, 200+ open models and an OpenAI-compatible API entirely inside the customer's network.
Appliance or DIY: the two ways to go local
Every organisation that decides to run AI locally faces the same fork. The DIY route assembles open-source parts, an inference server such as vLLM or Ollama, open-weight models, a vector database, a chat UI, and it works, as every lab prototype proves. The hidden cost is everything around the model: SSO, DLP, audit logging, model provenance, GPU drivers, upgrades and an on-call rota. It is a realistic path only for organisations with a platform team to spare.
The appliance route buys the same outcome as a product: pre-built GPU hardware with the platform pre-installed, deployed in minutes and owned like any other piece of IT equipment.
- DIY: maximum flexibility; you own integration, hardening and lifecycle. Budget for engineering time, not licenses.
- Appliance: turnkey, plug in power and ethernet, index your documents, serve the whole team. Kaldryn One is built for exactly this.
- Hybrid: start with one appliance for a department; scale to racks or your own servers later without changing the platform.
The economics favour local more than most buyers expect. Per-seat cloud AI compounds: Microsoft 365 Copilot lists at $30 per user per month, roughly $10,800 a year for a 30-person company before add-ons. A local deployment inverts the model: a fixed hardware cost, then electricity, with unlimited users and unlimited prompts. In the Nordics, where power is comparatively cheap and largely fossil-free, running your own GPUs is also the low-carbon option.
A buyer's checklist for sovereign AI
Whatever vendor you evaluate, including us, these are the questions that separate sovereignty from sovereignty-washing:
- European entity: is the vendor an EU/EEA company, contracting under a European legal system?
- GDPR Article 28: is a data-processing agreement offered, or better, is the architecture such that the vendor never processes your data at all?
- Training clause: does the contract state, in writing, that your data is never used to train anyone's models?
- The unplug test: ask the vendor to disconnect the internet during the demo. Sovereign AI keeps working.
- Model provenance: are model weights signed and verified, so you know exactly what is running?
- Ownership and exit: do you own the hardware, and does the system keep running if the vendor disappears?
- EU AI Act artefacts: does the platform produce the logs and technical documentation the Act expects from deployers?
- Security integration: SSO/SAML, DLP, immutable audit logs and SIEM export, sovereignty includes your security team.
Sweden, Germany and the Nordic moment
There is a reason so much of this movement is centred on northern Europe. Sweden combines very high digitalisation with a strong privacy culture and a public sector that writes sovereignty into procurement. Germany brings the Mittelstand's instinct to keep IP in the house, works councils with a real say over employee-data tooling, and BSI-shaped security expectations. Add Nordic electricity prices and the region's fossil-free grid, and the calculus lands in the same place: for a Swedish or German organisation in 2026, the question is rarely whether local AI is possible, it is which box to plug in.
The bottom line
Cloud AI will remain the default for workloads that carry no sensitive data. But for the European organisations that handle patient records, client files, financial data or state secrets, the direction of travel is set: AI is becoming something you own, not something you rent. Sovereignty stopped being a philosophy the day it became a procurement checkbox.
Kaldryn publishes reference architectures and compliance checklists for self-hosted AI in this research hub, and Kaldryn One is the fastest way to see local AI running on your own desk: power, ethernet, ten minutes.