ATAILA Newsroom · Budapest · 2026-08-03

Where AI sovereignty is really decided: the fourth layer

In a late-July analysis, the Hungarian science site qubit.hu — a piece by Dávid Takács — gives AI sovereignty structure instead of slogans: it breaks the question into four layers and shows, for each of them, where freedom of decision ends. As a company building a sovereign AI platform, we find little to argue with. On one point, though, we would go further: of the four layers, the one where mid-sized companies actually fail is not a theoretical question but an operational one.

What the Qubit analysis says

The piece’s core thesis is that full independence is not a cost problem but a structural impossibility: in globally interconnected systems there is no point from which every dependency can be eliminated. In the author’s words, “full sovereignty is not an attainable goal” — the real question is which dependencies we take on knowingly. To that end the article distinguishes four layers:

The numbers speak loudest on that fourth layer:

20%
of companies across OECD member countries use AI, per 2025 data — double the share of two years earlier (OECD)
42%
of organisations had halted the majority of their AI initiatives, up from 17% a year earlier (S&P Global, 2025)
≥ 50%
of generative-AI projects had been halted after proof of concept by the end of 2025 (Gartner)
65
structured interviews with data scientists and engineers: failures are typically organisational-integration issues, not technological ones (RAND, 2024)

The piece also cites S3NS, the joint venture Thales and Google Cloud founded in 2022: Google Cloud’s services run in data centres in France, while the encryption keys are held by the French Thales — so what emerges in practice is not independence but a carefully drawn compromise.

We agree with the layer model — not quite with the weighting

The layer model is correct, and the caution is warranted. We will not be manufacturing chips, and we do not claim that anyone buying private AI in Europe today has stepped out of the global supply chain. The point that control gained in one layer is no substitute for the others is exactly right.

What we would add is weighting. The article’s three strongest numbers — the 20%, the 42%, and the at-least-half of projects dying after proof of concept — are not about the infrastructure layer, nor about the models. All three are about integration. Companies fail to reach production not because they lack their own chip fab or their own base model. They fail because after the demo there is no one to run the system at seven on a Monday morning, no release process, no access control over the knowledge base, and no one who owns the backups.

From where we sit, this difference is not a nuance. For a 20–200-person company in a regulated or data-sensitive business — an accounting firm, a law practice, a clinic, a testing and certification body — sovereignty is not a geopolitical programme.

For a mid-sized company, sovereignty comes down to one very concrete sentence: this client data cannot go into ChatGPT.

The pragmatic answer to that sentence is not the illusion of full independence but a short, visible dependency chain that can be terminated at any time: private AI running on the operator’s own hardware, in an EU data centre, operated end to end by one party.

What ATAILA does: five layers instead of four

For us, sovereignty is not a principle but a product structure: we break the private AI platform into five layers — inference, knowledge base, applications, delivery, operations. Most offers on the market stop at the first: a rented GPU with a model runner, leaving the remaining four layers as the buyer’s problem. Exactly where the statistics Qubit cites say projects die.

Infrastructure: a full stack, not GPU rental

Our sovereign EU cloud runs on our own hardware in an EU data centre and arrives as a full stack: compute, networking, S3-compatible storage, secrets management, a private registry, monitoring and backups. Not VM rental: a sovereign environment sized for production, with a written 99.9% availability commitment and defined RTO/RPO. Where the iron itself has to be in your own hands, the single-tenant Enterprise edition is the answer.

Technology: open-weight models at a fixed monthly fee

We serve open-weight models privately, with an OpenAI-compatible API and a knowledge base built on the company’s own documents. Model choice and model switching thus remain a contractual matter, not a function of some provider’s price list — and the monthly fee is fixed, not assembled from tokens consumed.

Governance: the prompt is data processing too

A prompt is data processing. A contract pasted into a chat window is, in legal terms, the same as a contract sent out by email: a data transfer — even if all you see on screen is an input field. That is why there is no American data processor on the route, and why we document up front how every piece of data and code can be exported: the way out is documented as thoroughly as the way in.

Integration: delivery and operations in the same hands

The fourth layer is, for us, the pairing of delivery and operations. Four real environments (sandbox, dev, uat, prod), a versioned, audited release process — and we keep operating the system afterwards: not a project handover but a running system. And this is not theory: our open*.hu reference products run in production today, and the newest of them went live in hours precisely by reusing what was already built. The five layers are worth something together; none of them is enough on its own.

Our own limits

We do not claim ATAILA is sovereign on the first layer. The GPUs come from a handful of manufacturers, the open-weight models were trained by others, and we depend on suppliers too. We do not make chips and we do not train base models — nor will we. What we offer is not independence but a shorter, transparent, terminable dependency chain under a known jurisdiction.

Nor do we claim to be the right answer for everyone. If your inference needs outgrow this model by orders of magnitude — at the level of tens of thousands of euros a month — or you want to fine-tune your own base model, you should be talking to a GPU-rental provider, not to us. And AI does not fix a broken process: if the workflow itself is wrong, a private model will simply produce the wrong result faster. That assessment is better done at the start than at the end of year two.

If this is the layer you are missing

If you have a recurring, expensive workflow whose data cannot go into a public cloud, that is worth a confidential conversation — about a concrete process, concrete data and a concrete cost. We do not run demos: we walk through the layers and tell you which ones you already have and which one is missing.

Get started →