← Blog

Sovereign AI for Manufacturing SMEs: Own Your AI Instead of Renting Licenses

Hosting your own AI models instead of paying a per-user license: what sovereignty really changes for a manufacturing SME in 2026.

Sovereign AI for Manufacturing SMEs: Own Your AI Instead of Renting Licenses

Over the past two years, the question manufacturing SME executives ask has changed in nature. It is no longer "can AI be useful to us?" — that answer is settled. It is now: "if I equip my sixty employees, how long am I signing up for, and who have I handed my data to?" In other words, a question of ownership, not of features.

Sovereign AI means exactly that: an organization's ability to control the models it uses, the data it entrusts to them and the infrastructure they run on. For a manufacturing SME, this is not an abstract geopolitical debate — it is a very concrete trade-off between a subscription that grows with headcount and an asset you depreciate. This guide covers the whole question: what sovereignty actually encompasses, why the topic is unavoidable in 2026, the four possible architectures, what an AI you own really costs, and where to start without picking the wrong first step.

In brief

  • Sovereign AI breaks down into three independent levels: sovereignty over data, over the model and over the infrastructure. You can hold one without holding the others — and most "sovereign" offerings cover only two.
  • "No recurring license" does not mean "no license": an open-weight model is still governed by a contract. Some are under Apache 2.0, others under a proprietary license — the Llama Community License, for example, requires requesting a license from Meta beyond 700 million monthly active users (source: llama.com/llama4/license).
  • The per-seat business model is becoming the trigger: Microsoft 365 Copilot Business is listed at €18.20 excl. VAT per user per month at standard pricing (source: official Microsoft pricing page, accessed 09/17/2026). This spend tracks headcount, not the value produced.
  • The regulatory timeline has tightened: Regulation (EU) 2024/1689 (the EU AI Act) has applied generally since August 2, 2026, with the obligations for the high-risk systems of Annex III arriving on December 2, 2027 (source: European Commission).
  • The real cost of self-hosted AI is not the GPU: it is MLOps, model updates, monitoring and in-house expertise. That line item, not the hardware, determines success.
  • The safest path for a manufacturing SME is gradual: start with sovereignty over data (the scope that is yours alone), then over the model, and only then over the infrastructure if volume justifies it.

What "sovereign AI" really means

The term is used to sell very different things. Before any trade-off, it needs to be broken down, because these three dimensions are handled separately and cost separately.

Three levels to distinguish: data, model, infrastructure

Sovereignty over data is the ability to know where your information goes, what is retained, and whether it is used to train a third-party model. It is the most accessible level: it is often obtained through contracts and configuration, without changing technology.

Sovereignty over the model is the ability to hold the model weights: you can download it, run it, adapt it to your business, and no one can deprecate it or change its behavior without your consent. This is the level that protects against forced obsolescence — the scenario where a provider withdraws the version your processes were calibrated on.

Sovereignty over the infrastructure is the ability to choose the machine where the computation runs: your server, a device on the shop floor, or a hosting provider subject to European law alone. In France, the technical benchmark is the SecNumCloud qualification issued by ANSSI (the French national cybersecurity agency); the current list of qualified offerings is published in the agency's catalog, updated at least once a month (source: cyber.gouv.fr).

These three levels are independent. An open-weight model running on a non-European cloud gives you sovereignty over the model, not over the infrastructure. A service hosted in France but closed gives you the opposite. Naming the level you actually need keeps you from buying all three when only one is at stake.

"No recurring license" does not mean "no license"

This is the most expensive confusion, and it deserves to be stated plainly. A so-called "open" model is not a model without a contract: its weights are published under a license, and those licenses are not equivalent.

Some are genuine permissive open source licenses — Apache 2.0, under which many models from the Mistral and Qwen families are published: free commercial use, no royalties, no threshold. Others are proprietary licenses. Meta's Llama Community License is not OSI-approved and contains restrictions absent from standard open source licenses, including a threshold of 700 million monthly active users beyond which a license must be requested from Meta (source: llama.com/llama4/license).

For a manufacturing SME, that threshold is obviously never reached. But the methodological lesson stands: read the license sheet of the specific model you deploy, not the reputation of the family it belongs to. Terms vary from one version to the next at the same vendor. What disappears with self-hosting is the per-user subscription — not the contractual obligation.

Why the question is now landing on executives' desks

Per-user cost does not track the value produced

The dominant pricing model for office AI is the seat: a price per user per month. Microsoft lists Copilot Business at €18.20 excl. VAT per user per month at standard pricing, with a promotional price of €15.60 excl. VAT from July 1st to December 31, 2026, and the Business Premium plan including Copilot at €27.73 excl. VAT per user per month with annual billing (source: official Microsoft 365 Copilot pricing page, accessed 09/17/2026).

Run the arithmetic on your own headcount; it is the most illuminating exercise there is: at €18.20 excl. VAT, fifty users represent €910 excl. VAT per month, or €10,920 excl. VAT per year — and that amount renews every year, rises with every hire, and produces no asset on the balance sheet. The point is not that it is expensive in absolute terms: for many office uses, it is perfectly profitable and far simpler to deploy than an alternative. The point is that this spend is indexed to headcount while the value is concentrated in a few processes. In a manufacturing SME, it is rarely all sixty employees who need a general-purpose assistant: it is the three technical sales engineers who prepare quotes, the methods engineer searching two thousand pages of technical documentation, and the executive who wants a consolidated view of the business.

The regulatory timeline has tightened

Regulation (EU) 2024/1689, known as the EU AI Act, entered into force on August 1st, 2024 with phased application: prohibition of certain practices and AI literacy obligations since February 2, 2025, governance rules and obligations for general-purpose models since August 2, 2025, general application since August 2, 2026. The obligations for the high-risk systems listed in Annex III will apply on December 2, 2027, and those concerning high-risk systems embedded in already-regulated products benefit from an extended transition until August 2, 2028 (source: European Commission, "Regulatory framework on AI" page). This timeline was adjusted in 2026: check the version in force on the Commission's website before any compliance decision.

The practical effect is simple: you will need to be able to document which AI systems are used in the company, on which data, and with what level of human oversight. An architecture whose components you control is structurally easier to document than a stack of subscriptions signed service by service. We cover this point in detail in our article on the legal framework for AI integrators.

Your industrial data is the asset you cannot buy back

A manufacturing SME owns something rare: a production history, routings, non-conformances, customer returns, technical documentation built up over twenty years. That material is what makes an assistant useful rather than anecdotal — a general-purpose model does not know your internal part numbers.

This asset has one peculiarity: it cannot be bought back. If an architecture leads you to expose your complete technical documentation without a clear contractual guarantee on its retention and reuse, the trade-off is no longer an IT matter but an executive-level one.

The four possible architectures

In practice, a manufacturing SME chooses among four configurations, from least to most sovereign — and the right choice depends on the use case, not on an ideological preference.

  • Public consumer SaaS. You use a standard online service. Immediate deployment, per-seat cost, no sovereignty over the model or the infrastructure. Relevant for non-sensitive office work; to be avoided for uploading confidential documents without an appropriate contractual framework.
  • Commercial API under an enterprise contract. You consume a proprietary model on a usage basis, with contractual commitments on non-reuse of data and on location. Cost indexed to actual consumption rather than headcount — often the best entry point. Sovereignty over data by contract, not over the model.
  • Open-weight model on a European cloud. You deploy a model whose weights you hold with a hosting provider subject to European law, SecNumCloud-qualified where appropriate. Sovereignty over the model and the data, with rented infrastructure that is nonetheless legally under control. This is the most common balance point for an SME.
  • On-premise or edge. The model runs on your machines, possibly on the shop floor, with no network dependency. Full sovereignty, and the only option when data must physically not leave the premises or when latency is constrained. The trade-off: hardware investment and, above all, a lasting expertise requirement.

These four options can be combined. The most common architecture among our clients pairs a commercial API for general-purpose uses with a self-hosted model for the sensitive scope — typically a RAG system over technical documentation, whose real production cost we have detailed.

What an AI you own really costs

The cost items people forget

The public debate focuses on the price of graphics cards. It is the most visible line item and rarely the most decisive. A sovereign AI project actually carries five costs:

  • compute — hardware bought or rented, and its power consumption;
  • initial engineering — connecting to data, preparing sources, setting up the RAG, guardrails;
  • MLOps — monitoring, measuring answer quality, incident management, logging;
  • model maintenance — open models evolve fast; staying on a version frozen for three years is a default choice rarely owned as such;
  • expertise — someone has to know how, in-house or at a partner, over the long term.

The last three items are the ones that determine success, and they are the ones left out of comparisons. An unmonitored self-hosted AI becomes an AI nobody dares use anymore, because nobody knows whether its answers are still correct. We have detailed the structure of these costs in our analysis of the costs of industrial AI, from hardware to tokens.

Where the tipping point lies

The economic tipping point toward self-hosting depends on two variables: usage volume and number of users. A per-seat subscription becomes penalizing when many people need to be equipped; usage-based billing becomes penalizing when an automated process consumes massively, continuously, with no human in front of the screen.

The most reliable signal is therefore not a universal threshold — be wary of savings percentages announced without assumptions — but a calculation run on your own numbers: actual monthly volume, number of users to equip, data sensitivity, and available expertise. Our field experience shows that a high-volume automated process tips over much earlier than human conversational use, simply because it runs without interruption.

Where to start: a four-step path

The progression that fails least often is incremental, and it starts with the problem, not with the model.

  • Step 1 — scope a use case with measurable value. A single process, with a before/after indicator: response time to a tender, time spent searching technical documentation, re-keying rate. Without an indicator, no later trade-off is possible.
  • Step 2 — take sovereignty over data first. Map what leaves the company today and under which contract. This step costs little and often settles most of the real risk.
  • Step 3 — validate the value before investing in hardware. Prove the use case with an API under contract, on a usage basis. Buying GPUs for an unvalidated use case is the most frequent mistake and the hardest to undo.
  • Step 4 — bring in-house what deserves it. Once volume is known and value is proven, move to an open-weight model the scope that justifies it economically or legally. The decision then rests on measured figures, not on assumptions.

Five pitfalls observed in the field

  • Confusing sovereignty with self-hosting. Self-hosting a model whose license you have not read, on infrastructure you do not control, produces no real sovereignty.
  • Buying the hardware first. GPUs can be rented by the hour for validation. The investment is decided after volume has been measured, never before.
  • Neglecting data quality. A sovereign model connected to outdated technical documentation produces outdated answers, with the authority of the machine as a bonus.
  • Forgetting access rights. An assistant that reads the entire file server makes accessible to everyone what was not before. Permission management must come before go-live — the topic is covered in our AI security framework for industry.
  • Freezing the model and forgetting it. Without continuous measurement of answer quality, drift goes unnoticed until users' trust is lost — and it does not come back easily.

Frequently asked questions

What is sovereign AI?

Sovereign AI is an artificial intelligence system whose three dimensions the organization controls: the data it entrusts to it, the model it uses, and the infrastructure it runs on. These three levels are independent and can be acquired separately. In practice, an SME almost always starts with sovereignty over data, which settles most of the risk at low cost.

Is self-hosted AI really license-free?

No. It is free of a recurring per-user subscription, which is different. The weights of an open model are published under a license: Apache 2.0 for many Mistral and Qwen models, but a proprietary license at other vendors. Meta's Llama Community License, for example, requires requesting a license beyond 700 million monthly active users (source: llama.com/llama4/license). You need to read the license of the specific model deployed.

Do you need GPUs to do sovereign AI in an SME?

Not necessarily at the start. An open-weight model can run at a European hosting provider without buying hardware, which already provides sovereignty over the model and the data. Buying GPUs is justified when usage volume is measured and stable, or when the data physically cannot leave the company.

What is the SecNumCloud qualification?

SecNumCloud is the qualification issued by ANSSI to cloud service providers that meet its security and sovereignty framework, including criteria for immunity from extraterritorial legislation. The current list of qualified offerings appears in the catalog of qualified products and services published by the agency on cyber.gouv.fr, updated at least once a month.

Does the EU AI Act require hosting your AI in Europe?

No. Regulation (EU) 2024/1689 governs AI uses according to their risk level and imposes transparency and documentation obligations; it does not in itself impose a hosting location. Location constraints come from other texts, notably the GDPR and sector-specific requirements. However, a controlled architecture is simpler to document under the EU AI Act.

How long does it take to deploy a first sovereign use case?

The limiting factor is rarely the technology: it is the quality and accessibility of internal data. A well-scoped document use case, on an already clean corpus, can be prototyped in a few weeks. If the technical documentation is scattered across a file server, mailboxes and spreadsheets, data preparation will account for most of the timeline.

BCUB3's role

BCUB3 is an AI integrator for industry: we build agentic systems, RAG architectures and applied models on top of our clients' existing data — ERP, MES, technical documentation, production histories. On the question of sovereignty, our role is to help frame the trade-off with numbers: what level of sovereignty is really needed, at what cost, and over what scope. We work with partner automation engineers for the instrumentation layer, which we consume without designing it.

If you are asking yourself the question for your company, we can review your situation and tell you straight whether it is worth it for your scope — including when the answer is that your current subscription is the right choice. Let's talk, or see our solutions comparator to position the tools on the market.

Sources

  • Microsoft — Microsoft 365 Copilot plans and pricing, official pricing page (microsoft.com/fr-fr/microsoft-365-copilot/pricing), accessed 09/17/2026.
  • European Commission — Regulatory framework on AI (digital-strategy.ec.europa.eu), application timeline of Regulation (EU) 2024/1689.
  • ANSSI — Catalog of certified, qualified and approved products, services, protection profiles and sites (cyber.gouv.fr), reference for the SecNumCloud qualification.
  • Meta — Llama Community License Agreement (llama.com/llama4/license), 700 million monthly active users threshold clause.