A series of recent incidents involving some of the world’s leading AI providers has brought the risks of relying on externally hosted AI into sharper focus. Google Gemini went offline temporarily, bringing dependent production processes to a standstill.
Shortly afterwards, access to Anthropic’s latest models, “Fable 5” and “Mythos 5”, was restricted following a last-minute US export decision affecting non-US users. OpenAI’s “GPT-5.6” faced similar constraints, with access limited to select US customers before the model was ultimately withdrawn.
While the circumstances differed, the underlying issue is the same: organizations using AI through public APIs are dependent on availability they cannot fully control. Outages, access restrictions and regulatory decisions can quickly become operational risks, making private AI less a luxury and increasingly a matter of risk management.
Technology isn’t the problem
There’s no debate over whether public LLMs work. They’ve proven themselves and consistently get the job done. The real problem is corporate resilience. Using a public model means inheriting someone else’s geopolitical exposure, their outages and their opaque product and pricing changes. Assuming these challenges won’t affect your organization is the real risk.
Cost is also a big driver of AI headaches, simply because it’s so hard to control. While variable pricing models mean the benefits of AI grow with adoption, costs will rise just as sharply – especially with agent-based AI systems. This becomes especially pronounced once AI shifts from being an experiment to a fully integrated part of the value chain. GitHub Copilot’s shift to token-based billing blindsided developers with bills that evaporated budgets on normal usage rates. Uber burnt through its entire 2026 AI budget in just four months as employees embraced GenAI and AI coding tools.
This is happening across all industries. When usage scales unpredictably as adoption shifts, workflows consume more and more tokens. It’s also a metric that organizations can’t prepare for. Few organizations have visibility into ‘tokens burned’ until they get the invoice.
The problem here is that public API pricing is set by the provider, adjusted on the provider’s schedule and priced according to the provider’s own financial priorities – not the customer’s budget cycle. That’s why organizations that are serious about their AI strategy are pushing for greater control over their own infrastructure. Owning it reduces exposure to repricing risk, when costs shift unexpectedly, or when an outage takes place and AI-dependent processes go offline.
Data needs to stay at home
The issue of using publicly hosted models is also fueling debates around data protection. According to the Stanford AI Index Report 2025, the number of documented incidents related to AI privacy and security increased by 56.4% from 2023 to 2024. At the same time, public APIs make it difficult to prove the kind of traceability that the EU AI Act now demands for high-risk systems.
This is where the premise of “well, we have a contract” is often overestimated. A contract can define certain obligations, but it can’t stop an export ban or reverse an outage. AI providers might sit in different jurisdictions and regulatory perimeters than their customers. That makes continuity and security as much of a policy risk as a technical one.
This is why data sovereignty is increasingly a continuity issue rather than just a compliance one. Organizations who rely on externally hosted models are essentially outsourcing their infrastructure and control. They lose visibility over who can access their data and where it resides, and even the certainty over service availability. An export control, a licensing restriction, an outage or a sudden change to data rules can change model access requirements overnight – it doesn’t matter what the contract says.
Private AI: A risk mitigator, not a luxury
These factors are driving the need for Private AI, and understanding what that means is important. Private AI doesn’t mean the wholesale rejection of public models, it means deciding where the core foundation of AI strategy should sit.
With Private AI, models, applications and data all live within a sovereign domain. These can be located within any cloud environment – public, private, hybrid or multi-cloud – but the key is that nothing is leaving an organization’s control. That brings security, IP protection and the traceability that regulators are increasingly asking for. Above all, organizations retain control over availability, governance and cost.
Running AI in an environment controlled by the organization itself also means that you can build use cases tailored specifically to business needs. Automating repetitive work, speeding up decisions and scaling productivity can all be done without gambling on compliance or risking security issues on another company’s infrastructure.
Although private AI often requires higher initial investments than public services, adopting it pays off in the long run. Dependence on third-party providers decreases, ongoing costs for storage, processing and licenses fall and become more predictable. Private AI isn’t just a good look; it’s the key to operating AI in a stable and financially sound way.
Public is an option but not the foundation
Public models are certainly an option and have their place in AI strategy, but they shouldn’t be the foundation. Organizations should be building their AI around digital sovereignty. Recent outages or politically enforced restrictions on models are just the tip of the iceberg and are likely to become a common occurrence rather than isolated incidents or early teething problems. AI shouldn’t be an external risk factor, one that creates dependencies on others. It needs to become a robust, compliant platform on which companies can scale effectively and be used to spearhead innovation, without being affected or even incapacitated by outside factors. Only those organizations using Private AI can rid themselves of risk, reliance and potential repercussions.