NetApp
/
What’s in Private AI Certified — Expert
/
Where Should Your AI Actually Run? (Deep Dive)
NetApp Iterate.ai
NetApp Sellers & Partners
Joint Educational Series
Field Brief  ·  The Deployment Decision

Where Should Your AI Actually Run?

Public, private, and sovereign AI all promise control. Most enterprises are already running more than one — the question is whether that’s by design or by accident.

A joint educational white paper by NetApp® and Iterate.ai.

What You’ll Learn
Why the average enterprise already runs 4.2 AI models in production — not one deployment decision, but dozens.
The real difference between renting AI capacity and owning it — and what each actually costs you.
Why “sovereign AI” often still depends on foreign infrastructure, and what that means for enterprise control.
A framework for deciding which workloads belong where — public cloud, your own walls, or somewhere in between.
Written by Jon Nordmark (Iterate.ai CEO) with support from
Brian Sathianathan (Iterate.ai President, CAIO)
and the NetApp AI Solutions Team
Version 1.1
Aug 11, 2026  ·  01 / 12
The Hidden Decision

The Decision Nobody Makes Once

As of early 2026, 67% of enterprise AI workloads run in public cloud, 22% run hybrid, and 11% run entirely on-premises (industry surveys, 2026). That split isn’t a snapshot of one decision. It’s the average across dozens of them — the typical enterprise now runs 4.2 AI models in production, more than double the 1.9 it ran in 2023 (Gartner).

67%
Public Cloud
22%
Hybrid
11%
On-Premises

Every one of those models had to be deployed somewhere: rented from a public provider, built on infrastructure the company owns, or — increasingly — built by a government treating AI compute the way it treats highways and power grids. Renting, owning, and building your own city are three different bets. Most enterprises are placing all three at once, often without a framework for which workload belongs where.

That’s the real question this paper answers: not “which AI model is best,” but which of these three ownership structures each of your workloads actually belongs in — and why the answer changes by workload, not by company.
NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  02 / 12
The First Model

Public AI: Renting the Penthouse

Public AI is a model and a service, developed and hosted by a third party, made available to any organization willing to pay for access — usually through an API. It’s the fastest way to get from “we want AI” to “we have AI,” and for a huge share of use cases, that speed is exactly the right trade.

OpenAI GPT-4 / ChatGPTAnthropic ClaudeGoogle GeminiAmazon Bedrock
1
Shared infrastructure
Many organizations use the same underlying models and compute, separated only logically — not physically.
2
Provider-managed
The provider handles training, updates, scaling, and maintenance. You never touch the infrastructure.
3
Consumption-based pricing
You pay for what you use — API calls, tokens, or compute time — with no upfront infrastructure cost.
4
Rapid deployment
Teams can be using production-grade AI within minutes, with zero infrastructure setup.

Like renting a furnished penthouse: you move in today, someone else handles the plumbing, and you get the building’s amenities on day one. But the lease is the landlord’s, the rules are the landlord’s, and you own nothing when you move out.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  03 / 12
The Fine Print

The Rules Aren’t Yours to Set

Every advantage of renting comes with a matching trade-off. None of these are hypothetical — they’re the standard terms of the lease.

1
Data privacy
Sensitive data sent to a third party may be subject to its access, retention policies, or accidental exposure — you don’t control the terms.
2
Limited customization
You can shape prompts and fine-tune at the margins. You cannot change the model’s core architecture or what it was trained on.
3
Vendor lock-in
Applications built deep into one provider’s API are expensive to migrate — the switching cost is the point.
4
Compliance exposure
Regulated industries (healthcare, finance, government) may be restricted or barred from sending data to third-party AI at all.
5
Unpredictable costs
Usage-based pricing scales with adoption — the more your teams rely on it, the less predictable the bill gets.

This is the same asymmetry The Oohs, Awes, and Dangers of AI Memory (elsewhere in this series) covers in depth: on shared infrastructure, the value of what you reveal doesn’t stay yours. It flows to whoever owns the model.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  04 / 12
The Second Model

Private AI: Buying the House

Private AI runs entirely within infrastructure an organization owns or exclusively controls — on-premises, in a dedicated private cloud, or both. The enterprise decides the model, the training data, the deployment, and the lifecycle. Nothing leaves the building unless the organization chooses to send it.

1
Maximum data control
Sensitive data never leaves organizational boundaries — the direct answer to public AI’s biggest liability.
2
Real customization
Models can be fine-tuned or trained from scratch on proprietary data, terminology, and workflows.
3
Predictable costs
Infrastructure cost is fixed and known in advance, not a variable bill that grows with adoption.
4
Regulatory fit
Meets data-residency, audit-trail, and processing-control requirements that public AI often can’t.
The Honest Trade-Off

None of this is free. Building Private AI yourself typically means:

Significant upfront GPU & storage costDedicated AI & MLOps expertiseOngoing operational complexitySlower access to frontier updates
NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  05 / 12
Owning Without the Build

The House, Pre-Built

Every challenge on the previous page is a challenge of building Private AI from scratch — not of owning it. That distinction is the entire premise of the AIPod Mini: NetApp storage and Iterate’s Generate reasoning layer, pre-integrated, so a customer gets the ownership of Private AI without first becoming an infrastructure company.

1
No GPU buildout
Turnkey hardware, sized to the workload — deploys in under 20 minutes, not a multi-month procurement cycle.
2
No dedicated MLOps team
Generate’s Super Agent handles agent building, prompts, and workflows — the operational complexity is engineered away, not staffed around.
3
Predictable, not proportional, cost
Infrastructure you own, not a bill that scales with how often employees use it. A full AIPod Mini deployment runs roughly $250,000 — and far less if the workload only needs a single RTX Pro–class GPU.
The NetApp AIPod Mini appliance
The AIPod Mini — private AI, pre-built.

For the deployment mechanics in detail, see From Empty Infrastructure to Working AI in 20 Minutes; for the cost case, see The Rest of the Invoice — both elsewhere in this series.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  06 / 12
The Third Model

Sovereign AI: Building a City From Scratch

Sovereign AI takes the same ownership logic to the scale of a nation: compute, models, and data infrastructure built and controlled within a country’s own borders. In 2024 it was an aspiration. By 2026, it’s a budget line in most of the G20.

$100B+
Global sovereign AI spend, 2026 (projected)
€109B
France’s AI infrastructure pledge, Feb 2025
5 GW
UAE’s planned AI campus capacity

France’s commitment funds Mistral Compute — 18,000 NVIDIA Grace Blackwell chips in a single facility. The UAE’s Mubadala fund alone deployed $12.9B in 2025. Singapore, India, and the EU (via the AI Act and domestic-model initiatives) are running comparable, if smaller, programs. The logic is the same one driving enterprise Private AI: don’t rent your intelligence from someone else’s infrastructure.

The Twist
Even at nation-state budgets, full independence is hard to buy.
The CNAS Sovereign AI Index finds the UAE and Japan alone account for over two-thirds of disclosed sovereign AI investment — and roughly 70% of tracked “sovereign” projects still involve at least one foreign technology partner, most often American.

The lesson isn’t about geopolitics. It’s that ownership isn’t a function of budget size — it’s a function of what you actually control in the stack. A nation can spend $100 billion and still depend on foreign chips and foreign partners. An enterprise can own its AIPod Mini outright for a fraction of that and control the entire stack end to end.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  07 / 12
Side by Side

Public, Private, and Sovereign AI, Compared

The three models trade off against each other on nearly every dimension that matters to a buyer. None is universally “better” — each is the right answer for a different workload.

Public AI
One unit in a shared building — and data can leak to the tenant next door.*
Private AI
A house you own outright — smaller than the building, but every wall is yours.
Sovereign AI
A nation building its own civic infrastructure — the largest scale, and the slowest to build.
Same ownership logic, three very different scales.
* This is the mechanism Satya Nadella describes in his own account of shared AI: you pay for intelligence twice — once with money, once with the institutional knowledge you reveal to make it useful. Read: “The Reverse Information Paradox”, Satya Nadella, CEO, Microsoft — snscratchpad.com (Jul 12, 2026).
Dimension
Public AI
Private AI
Sovereign AI
Control
Provider-managed
Organization-controlled
Nation-controlled
Data location
Provider infrastructure
Your premises
National borders
Customization
Prompts, light fine-tuning
Full — architecture & training
National priorities
Initial cost
Low (pay-per-use)
High (infrastructure)
Very high (national scale)
Deployment speed
Immediate
Weeks (AIPod Mini: ~20 min)
Years
IP protection
Limited
Maximum
National asset

Note the deployment-speed row: Private AI’s traditional weakness — weeks to months of build time — is exactly what a turnkey appliance like the AIPod Mini is built to close.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  08 / 12
The Framework

Which Workloads Go Where

Don’t choose a deployment model for the company. Choose one for each workload. Six questions do most of the work.

1
How sensitive is the data?
Regulated or highly sensitive data (health records, financials, trade secrets) points toward Private AI by default.
2
How much customization does it need?
Domain-specific terminology or proprietary workflows favor a model you can actually shape.
3
What’s the budget and in-house expertise?
Limited AI expertise or budget is a reason to start with Public AI — or a turnkey Private AI appliance that removes the expertise requirement.
4
What does the regulatory environment demand?
Healthcare, finance, and government workloads often have the decision made for them.
5
How large or latency-sensitive is it?
High-volume, low-latency applications increasingly favor dedicated infrastructure over shared API calls.
6
How strategic is this capability?
If it’s a source of competitive advantage, it deserves the investment Private AI requires.
NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  09 / 12
The Real-World Pattern

Hybrid Isn’t Indecision — It’s the Default

22% of enterprise AI workloads already run hybrid, and IDC finds 64% of infrastructure-maturity leaders describe their overall environment the same way (Feb 2026). Hybrid isn’t a failure to choose. For most enterprises, it’s the correct architecture.

1
Tiered deployment
Public AI for non-sensitive work, Private AI for regulated or proprietary workloads — sorted by the framework on the previous page.
2
Prototype-to-production pipeline
Build fast on Public AI, then migrate the workloads that prove out to owned infrastructure.
3
Edge-and-cloud combination
Run inference on private, on-prem hardware while using public cloud for training and periodic updates.
NetApp + Iterate’s Role

The hardest part of hybrid isn’t deciding — it’s avoiding data silos once workloads are split across three architectures. NetApp’s unified data layer moves data across on-premises, private cloud, and public cloud without duplication or lock-in; Iterate’s Generate runs consistently on top of it, wherever a given workload lives.

NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  10 / 12
Three answers, three questions

Ownership Is a Workload Decision, Not a Company-Wide One

Public, Private, and Sovereign AI aren’t competing answers to the same question — they’re the right answer to three different ones. The mistake isn’t picking the wrong model. It’s picking one model for every workload, when the workloads themselves are telling you which one they need.

The AIPod Mini removes the excuse for defaulting to public.
When the barrier to Private AI was building it yourself, renting made sense by default. A turnkey appliance changes the default — ownership is now the fast option too, not just the safe one.
More in This Series
From Empty Infrastructure to Working AI in 20 Minutes. The deployment mechanics behind the AIPod Mini’s speed.
The Rest of the Invoice. The wider cost case for owning infrastructure instead of renting it.
The Oohs, Awes, and Dangers of AI Memory. Why the data you send a shared model doesn’t stay only yours.
About This Series

A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

NetAppIterate.ai
v1.1 · Aug 11, 2026
NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  11 / 12
Appendix

A Quick Glossary of AI Deployment

Plain-language definitions for the deployment terms in this paper — enough to hold the conversation with a technical or procurement team.

Public AI
A model hosted and operated by a third-party provider, accessed by many organizations through a shared API — e.g. GPT-4, Claude, Gemini.
E.g. a support team using ChatGPT to draft responses — fast, but every prompt leaves the building.
Private AI
AI deployed entirely within infrastructure an organization owns or exclusively controls — on-premises or in a dedicated private cloud.
E.g. the AIPod Mini, running Generate entirely on NetApp storage a company already owns.
Sovereign AI
AI infrastructure, models, and data controlled at the national level, built to reduce a country’s dependence on foreign providers.
E.g. France’s Mistral Compute — national infrastructure, not a single company’s.
Hybrid AI
Splitting AI workloads across more than one deployment model by design — sensitive work stays private, other work runs public.
Fine-Tuning
Adapting a pre-trained model to a specific task or domain using additional, targeted training data.
Inference
Using an already-trained model to generate outputs on new data — the “running it” phase, as opposed to training.
Large Language Model (LLM)
A model trained on very large amounts of text to understand and generate human language.
MLOps
The practices and tooling for deploying, monitoring, and maintaining machine-learning models in production.
Data Residency
Legal or regulatory requirements specifying the physical location where data must be stored and processed.
E.g. a hospital required to keep patient records on servers physically located in-country.
Data Sovereignty
The principle that data is subject to the laws of the country in which it is collected or stored.
Vendor Lock-In
Dependence on one provider’s proprietary API deep enough that switching providers becomes costly or impractical.
Total Cost of Ownership (TCO)
The full cost of a deployment model over its lifetime — infrastructure or fees, plus integration, staffing, and maintenance.
NetApp | Iterate.aiWhere Should Your AI Actually Run?  ·  12 / 12