You now know what an AI model is, how generative AI and retrieval work, why humans stay in the loop, and what sovereignty and the EU AI Act demand. This final module turns all of that into a decision: how do you actually get a governed AI assistant running in your business — without becoming a software company?
The real question is build vs buy
Every SME considering AI eventually hits the same fork: do you build the capability in-house, or buy it as a finished service?
On paper, building looks cheap. The model is free to download. There are open-source tools for everything. So why pay anyone?
Because a working, governed AI assistant is not one thing — it is a stack of things that all have to work together, securely, every day:
- A language model running on hardware you maintain
- A retrieval system that finds the right passages in your documents
- An ingestion pipeline that keeps the knowledge base current as files change
- Access control so the right people see the right answers — and outsiders never see internal material
- Logging, backups, monitoring, and updates for all of the above
Each piece is a genuine engineering project. Wiring them together — and keeping them running after the consultant who set it up has moved on — is a job for a team most SMEs simply do not have on staff.
The model is the easy part. The hard part is the plumbing around it: retrieval, permissions, governance, and the discipline to keep it all running. That plumbing is the product.
We call this the complexity wall. It is the point where a promising weekend prototype meets the reality of security patches, employee turnover, and a regulator who expects you to explain how your system works. Most SMEs hit the wall before they reach production — which is exactly the trap this blog post is about.
Three deployment shapes
Assuming you decide to buy the capability rather than build it, sovereign AI still comes in three shapes. They differ in where the system physically lives — which is the question that actually matters for data residency and control.
Appliance — a local box
A pre-configured device sits in your office or server room. The model, your documents, and every answer stay inside the building. Nothing reaches the public internet to function. This is the strongest form of sovereignty and the simplest to reason about for a regulator: the data never left. It suits firms with sensitive material — legal, medical, engineering, public sector.
Self-managed — your own servers
The same software runs on infrastructure your IT team already controls: your own servers, or a private cloud you administer. You get full control and can fit it into existing security policy, but you take on more of the operational responsibility — updates, capacity, uptime.
Managed — EU-region hosting
A provider runs the system for you in a high-availability EU region, under EU data-protection law. You give up physically holding the box, but you gain resilience, automatic updates, and no hardware to babysit — while keeping data inside European jurisdiction. For many SMEs this is the pragmatic middle ground.
All three run the same governed architecture. The choice is about who keeps the lights on, not about what the system does. You can see the platform behind all three shapes.
The easiest interface is a person
Here is the part the technology brochures miss. For a non-technical owner — say, somewhere between 40 and 60, running a real business with no spare engineers — the most usable "interface" to AI is not a dashboard. It is a trusted local advisor.
A consultant who already understands your industry can handle the setup, configure the compliance settings, curate the first knowledge base, and train your staff. You describe the problem in plain language; they translate it into a running, governed system. You never touch a config file.
This is why Wegenty is delivered through consultants rather than sold as a download. If you are an advisor, the consultant path explains how that works.
Recap: internal superset, public projection
Before you plan a rollout, hold on to the one boundary that makes the whole thing safe.
Your internal knowledge base is the superset — everything the business knows, including confidential material. The public-facing agent is a governed projection of that superset: a deliberately narrowed, filtered view safe for customers and the public to query. Information flows one way. The public agent never reaches back into the internal store, and nothing private leaks outward by accident.
When a human corrects an answer, that correction is captured back into the knowledge base through the correction loop — so the system gets more accurate over time without ever weakening the boundary. One local model can serve many such knowledge bases at once, each with its own projection.
A sensible first step
You do not need a company-wide AI strategy to begin. The opposite, in fact — ambition is where these projects die. Start small and governed:
- One curated knowledge base. Pick a single, well-bounded domain — your product manual, your policies, your most common support questions.
- One public agent. A single governed projection that answers a defined set of questions reliably.
- Delivered by a consultant. Someone who handles the hardware, the compliance posture, and the training so you can judge results, not plumbing.
Prove value in that one slice, with a human reviewing the early answers. Then widen. This is how you cross the complexity wall — by going around it, not over it.
Remember that ~53% of German SMEs name legal uncertainty as their single biggest AI barrier. A small, sovereign, consultant-delivered start is the most direct way to act despite that uncertainty: the data stays put, the governance is built in, and someone accountable is standing beside you.
Don't boil the ocean. One curated knowledge base, one governed public agent, one trusted consultant — that is a complete, defensible AI deployment. Everything else is just more of the same.
That is the whole course in one sentence: sovereign AI is not about owning the cleverest model. It is about keeping control of your data, governing what the system can say, and starting small enough to actually finish. When you're ready to see it working, try the live demo — or book a demo to talk through your own first knowledge base.