
For more than a decade, the arc of enterprise technology strategy bent in one direction: away from company-owned infrastructure and into the public cloud. Artificial intelligence was supposed to accelerate that migration. Instead, it is forcing a rethink.
The path forward is no longer a straight line. Executives aren’t ripping up their AWS contracts or shuttering Azure tenants, but they are paying closer attention to what data lives outside their walls. Across financial services, healthcare, manufacturing, and the public sector, a growing number of companies are pulling their most sensitive AI workloads out of the hyperscaler cloud and running them on infrastructure they control. A 2025 global survey of 1,800 senior IT decision-makers found that 53 percent now rank private cloud as their top priority for new workloads over the next three years, and 69 percent are actively evaluating workload repatriation from public to private cloud.(Broadcom Private Cloud Outlook 2025) One-third of that group has already made the move.
The drivers are not hard to find. They cluster around three boardroom-level concerns that are converging simultaneously: uncontrollable costs, regulatory exposure, and the question of who actually owns the data once an AI system touches it.
Traditional cloud workloads like a CRM instance, a payroll system, or an analytics dashboard operate within well-understood security and contractual boundaries. AI systems are different. They introduce compounding layers of data interaction: continuous prompts, vector embeddings, inference logs, retrieval-augmented generation pipelines, and increasingly autonomous agentic workflows. Each layer multiplies the points at which sensitive proprietary data may be processed, stored, or inadvertently recycled by a third-party model provider.
The governance question has shifted accordingly. It is no longer whether the cloud is secure in principle. It is whether organizations can maintain clear, demonstrable accountability over how proprietary data is handled once pervasive AI systems enter the picture.
That question now carries board-level weight. An EY analysis of Fortune 100 proxy disclosures found that in 2025, nearly half of public companies specifically cited AI risk as part of the board’s oversight of enterprise risk, triple the 16 percent that did so one year earlier. Around 40 percent of boards have formally assigned AI oversight to a committee, nearly four times the share in 2024. (Harvard Law School Forum on Corporate Governance) These are not cosmetic disclosures. They reflect a material shift in how fiduciary responsibility intersects with technology architecture decisions.
If the governance gap is what keeps general counsel up at night, cost volatility is what haunts the CFO.
Unlike traditional enterprise applications with predictable licensing or consumption-based billing, AI inference costs fluctuate with usage, model size, and token consumption. As AI moves beyond pilot projects into core workflows, the bills become both larger and less predictable. Average monthly enterprise AI costs reached $85,521 in 2025, a 36 percent increase from the prior year, and nearly half of organizations still cannot confidently measure AI’s return on investment.(CloudZero, The State of AI Costs) (Note, that figure represents an average across company sizes, including smaller organizations still in early-stage deployment. For enterprises running AI in production workflows, the number is meaningfully higher.) Variable hyperscaler billing is creating monthly cost swings that make financial planning and budget governance extraordinarily difficult for finance teams.
The tipping point is becoming easier to quantify. Deloitte’s Tech Trends 2026 report identifies a cost inflection at roughly 60 to 70 percent of equivalent on-premises system costs. This is the type of threshold where capital investment becomes more attractive than operational expenditure for predictable, high-volume AI workloads.(Deloitte Insights, Tech Trends 2026) Lenovo’s own TCO analysis of GPU server configurations against equivalent cloud instances found breakeven points as short as twelve months on an on-demand basis, and under two years even against discounted reserved pricing.(Lenovo Press, Generative AI TCO 2025)
The strategic logic is straightforward: match infrastructure to the workload’s economic and risk profile, rather than defaulting to the cloud as a universal answer. Analysts describe this as “cloud rebalancing” rather than wholesale repatriation—a selective migration of certain AI workloads toward owned or dedicated infrastructure, while maintaining public cloud for burst capacity, model training, and rapid experimentation.
There is another driver that rarely appears in vendor pitch decks but shapes architecture decisions more than most executives realize: data gravity.
In many organizations, the most sensitive or operationally critical data never fully migrated to the cloud. Core transaction systems, medical imaging repositories, voice recordings, industrial telemetry, and regulated financial records frequently remain on premises (by design or by inertia). Running AI models far from these data sources introduces latency, transfer costs, and operational complexity that can undermine the business case for AI entirely.
For use cases that require response times below ten milliseconds (real-time fraud detection, predictive maintenance on factory floors, clinical decision support) the inherent delays of cloud-based processing are simply unacceptable.(Deloitte Insights, Tech Trends 2026) Enterprises increasingly find it more efficient to bring AI computation to the data rather than moving massive datasets into the cloud. This dynamic is strategic, not merely technical. It preserves intellectual property, satisfies compliance requirements, and eliminates the risk of proprietary data being incorporated into third-party model training.
Regulation is hardening this shift into a structural reality.
The General-Purpose AI Model obligations under the European Union’s AI Act took effect in August 2025, alongside DORA and the NIS2 directive. Collectively, these requirements have transformed data sovereignty from a preference into a hard obligation for financial services, critical infrastructure, and healthcare organizations operating in Europe.(EU AI Act Articles 51–52; DORA; NIS2) And the pressure is not limited to regulatory text. Geopolitics is accelerating the trend: a November 2025 Gartner survey of 241 Western European CIOs found that 61 percent expect geopolitical factors to increase their reliance on local or regional cloud providers, and 53 percent said geopolitics will restrict their future use of global hyperscalers.(Gartner, November 2025) Gartner projects that by 2030, more than 75 percent of all enterprises outside the United States will have a formal digital sovereignty strategy.
The implications extend well beyond Europe. U.S. state-level AI legislation is proliferating.(NCSL, AI 2025 Legislation) The regulatory floor is rising globally, and most enterprise architectures are not yet built for where this is heading. The organizations that have navigated this terrain the longest (defense agencies, large financial institutions, critical infrastructure operators) have generally solved it by building and controlling their own infrastructure stacks. That model is now being studied by a much broader set of industries.
In response, major cloud providers are rolling out sovereign and disconnected deployment options, including dedicated tenancy, customer-managed encryption keys, and confidential computing enclaves designed to process data without exposing it to the provider. These offerings narrow the gap meaningfully for some workloads. The simple fact that the hyperscalers now acknowledge that centralized, multi-tenant cloud models are not suitable for all AI workloads tells you everything about where the market has moved.
A reminder before the pendulum swings too far, simply being on-premises does not mean data is inherently safe.
Many organizations have access to far more mature security controls, continuous monitoring, and identity management in the public cloud than in their own legacy data centers. Without strong governance, on-premises AI deployments can introduce new blind spots, particularly around model lifecycle management, access control, and auditability of AI decision-making. And the risk isn’t isolated to where the data sits. It extends to whether the organization has the internal capability to manage AI infrastructure responsibly. For most, that capability is thinner than they think.
Successful organizations treat infrastructure decisions as one component of a broader risk and governance strategy, not as a purely technical or cost-driven choice. Repatriating workloads without building the internal infrastructure to govern them is just trading one set of risks for another.
For non-technical leaders, the shift toward hybrid AI architectures reflects a fundamental change in how technology decisions intersect with risk, regulation, and corporate economics. The companies moving AI workloads closer to home are responding to four questions, each of which now carries board-level weight.
The future of enterprise AI is not going to be entirely cloud-based or entirely on-premises. It will be selective, hybrid, and governance-driven. The real risk for executives is not choosing the wrong architecture. It is assuming that the cloud strategies of the past decade apply unchanged in a world where AI touches everything.
The organizations that get this right will be the ones that treat infrastructure as a strategic lever that determines competitive position, regulatory exposure, and the economics of every AI workload they run.