Archive of aionprem.pl. Newest first.
[architecture]The europe-west4 outage exposed something worse than downtime: you cannot audit the dependencies your AI runs on. What you can actually verify on-prem, and what a hyperscaler will never show you.
[compliance]The sovereignty test in IT procurement does not check the vendor's country, it checks who controls the architecture and the model weights. That is why a local cloud does not pass it by default, while on-prem AI meets its core. Thresholds, five criteria and how to score an offer.
[vendor-evaluation]An AI TCO calculator answers one question: at what utilisation does on-prem beat cloud. Methodology, three formulas (per token, GPU rental, on-prem CAPEX), a full 3-year worked example and FAQ. Verdict: at moderate volume the API wins on price, on-prem earns its keep on control, not cost.
[compliance]Article 50 of the AI Act applies from 2 August 2026. When you self-host, you are often provider and deployer at once, which changes your transparency duties.
[compliance]Four regimes, but the requirements overlap heavily. Instead of running four separate compliance projects, build one control set and map it onto NIS2, AI Act, GDPR and ISO 27001. A cross-mapping table, plus the places where the regimes genuinely diverge.
[vendor-evaluation]A ready RFP framework for AI vendors in regulated manufacturing: 24 questions across four categories, security, regulatory, architecture and exit, each with its purpose and scoring guidance.
[architecture]Four telemetry layers for an on-prem LLM: infrastructure, serving, quality and audit. What to log, what not to store, and how observability feeds the audit trail NIS2 expects.
[vendor-evaluation]TCO is not decided by the GPU price tag, but by utilization and horizon. How to model on-prem AI vs cloud over three years: three different cost models, a full CAPEX and OPEX line-item list, the break-even point and an honest look at when cloud wins.
[compliance]A vendor's boilerplate DPA stays silent exactly where an auditor looks first. Eight clauses whose absence breaks an NIS2 or GDPR audit: from the sub-processors behind the model API and training use of your data, to logs, breach notice and data deletion.
[compliance]When a manufacturing AI system is high-risk under the AI Act and when it is not. Two routes to high-risk, step-by-step classification, and what the July 2026 Digital Omnibus changed. Plus the effect on the on-prem versus cloud choice.
[nis2]NIS2 does not prescribe a topology, but it does require isolation. A minimum three-zone model for on-prem AI, and how each network boundary maps to Article 21. A practical layout you can defend to an auditor.
[vendor-evaluation]Twelve questions to put to an AI vendor before you sign an MSA, in four blocks: data location, sub-processors, operational security, and exit terms.
[compliance]The ten Article 21 NIS2 areas mapped to an AI system. For each area, the question an auditor will ask and the single artefact you need to show.
[architecture]A reranker sharpens top-k ordering when queries are long and the corpus is dense. The numbers, the VRAM and latency cost, and five setups where it backfires.
[compliance]NIS2 does not ask for a standalone AI policy. It asks that your AI system sits inside seven documents you already produce. Here is the list, with a mapping table.
[architecture]How to build RAG outside the public cloud: the pipeline layers, the most common retrieval failures, the data boundary inside the prompt, and the questions an auditor will ask. A technical note for architects and CISOs.
[compliance]ISO 27001 has no concept of "AI," yet an AI vendor touches three of its controls at once: supplier relationships, information classification and flow, and logging. Which to map today – and how they tie into NIS2.
[nis2]The amended Polish cybersecurity act shifts responsibility for cybersecurity oversight onto the management board personally. What that means for choosing an AI vendor and architecture, and the decision trail you need to be able to show. A mapping of duties, not legal advice.
[nis2]Pillar. How to map an AI vendor onto NIS2 Article 21 (Polish transposition, 2026): supply chain, sub-processors, audit rights, management liability. A working guide for the CISO of an essential entity, with a risk-register skeleton and an audit-readiness checklist.
[vendor-evaluation]AI vendor lock-in is rarely one bad decision — it's the sum of reasonable steps across three layers (data, model, integrations). The worst traps sit not in the architecture but in the contract. How to spot them before you sign an MSA.
[on-prem]"On-prem AI" isn't one deployment model but at least three, with different cost, risk, and team-load profiles. We break them down so CISOs and CIOs know which conversation they're really having before the RFP.
[architecture]How many GPUs does it really take to run Llama 3.1 70B in-house? Concrete configs (A100, H100, H200), the impact of quantization (FP16 → FP8 → INT4), tokens/s, TTFT, and cost per 1M tokens. No marketing — numbers from vLLM and TensorRT-LLM benchmarks.
[on-prem]Bare-metal in your own server room, colocation with dedicated hardware, or a vendor's managed appliance. Three on-prem AI deployment models for European manufacturing in 2026: CAPEX and OPEX numbers, NIS2 risk profiles, when each makes sense — and when to skip on-prem entirely.
[nis2]A technical note: one NIS2 article, one scenario. Does a ChatGPT Enterprise or Claude contract meet Article 21(1)(d)? Three areas where a standard public-cloud LLM relationship starts to drift from supply-chain compliance.
[on-prem]Architecture, GPU sizing, security, integrations, TCO, build vs buy. A practical guide to deploying on-prem AI for CISOs and CIOs in European manufacturing in 2026.