← All articles

AI trends Published 2026-07-22 · 7 min read

The shift from cloud-first to data-residency-first enterprise AI buying

Enterprise AI procurement in 2024 had a default: cloud-first. By mid-2026 the default has flipped. Deployer obligations under the EU AI Act, NIST's critical-infrastructure direction, and the OECD's policy toolkit have moved the architectural decision before the vendor decision. Residency-first — keep the inference content where the deployer already manages everything else — is the new default. The shift took 24 months.

This article traces the signals and what they mean for an enterprise that is buying AI in 2026.

The cloud-first era and what worked about it

Through 2023 and into early 2024, enterprise AI buying tracked the broader cloud-software pattern. A vendor offered a managed LLM API, the deployer integrated against it, the inference happened on the vendor's infrastructure, and the deployer's compliance team accepted the vendor's certifications (SOC 2, ISO 27001, GDPR-aligned DPA) as sufficient evidence. This was simple to procure, fast to evaluate, and well-matched to how enterprises had bought SaaS for the previous decade.

a16z's enterprise survey from March 2024 captured the late-cloud-first moment: 72% of enterprises used an API to access their model, over half used the model hosted by their cloud-service provider, and "deals that used to take over a year to close are being pushed through in 2 or 3 months" for products that fit the new requirements [3]. Even mid-2024 the new requirements were already starting to bend the deal curve.

What broke

The EU AI Act came into force in August 2024. Prohibited AI practices became effective 2 February 2025, governance and GPAI obligations on 2 August 2025, transparency obligations are due August 2026, and the high-risk deployer obligations that re-shape procurement architecture apply from 2 December 2027 [1]. The 7 May 2026 omnibus political agreement re-confirmed that 2 December 2027 milestone and added new prohibitions [2], removing any procurement team's hope that the deadline would slip.

The Act distinguishes between the provider and the deployer of an AI system. Deployer obligations include human oversight, monitoring, log retention, and demonstrating these capabilities on request [1]. Crucially, the obligation is on the deployer — the bank, the hospital, the agency — not on the LLM vendor.

That single legal fact is what flipped the architecture. A deployer obligation cannot be satisfied by a vendor certification. Cloud-first procurement assumed the vendor's certifications were proxy for the deployer's compliance posture. Residency-first procurement is what the deployer does when that assumption no longer holds.

The signals that confirmed it

Three signals in 2026 confirmed residency-first as a cross-jurisdiction direction, not a European peculiarity.

NIST AI RMF Critical Infrastructure profile, 7 April 2026. [4] The first US federal scoping of AI RMF deployer obligations for critical-infrastructure operators. Concept-note stage, not finalised, but the direction is unambiguous: US federal procurement is heading toward the same deployer-obligation framing the EU has codified.

OECD AI Policy Toolkit, 3 June 2026. [5] OECD-speak for "the principles are settled; the bottleneck is implementation". The Toolkit's framing matches the EU and US trajectory closely enough that a multinational enterprise designing once for the strictest jurisdiction now satisfies the rest.

a16z deal-cycle compression continuing. The 2024 survey [3] caught the early shape; by 2026 the products that fit deployer-obligation requirements clear procurement in weeks, while products that don't still take a year or more. The market signal is the speed of the procurement decision itself.

What residency-first looks like architecturally

The architecture the signals converge on has four properties:

  1. Inference local to the deployer. Either on the user's device or on a server the deployer operates. Prompts and responses never leave the deployer's perimeter.
  2. Content-free audit logs the deployer owns. Every administrative action logged with timestamp and actor, in the deployer's SIEM. No prompts or responses in the audit row; the row is the evidence, the content is the deployer's to retain.
  3. Identity through the deployer's IdP. OIDC against Microsoft Entra ID or Google Workspace; existing access controls apply unchanged.
  4. No vendor-side tenant. The vendor doesn't operate the runtime, doesn't see the data, isn't a point of failure for compliance posture.

Cloud LLM APIs can implement properties 1–3 with effort. Property 4 they structurally cannot — operating the runtime is what makes them a cloud LLM API. Residency-first treats that as the architectural constraint, not a vendor selection criterion.

What this means for an enterprise buying AI in 2026

Three concrete implications.

First, vendor questionnaires need re-shaping. The questions a deployer asked in 2024 were about the vendor's certifications. The questions a deployer asks in 2026 are about the deployment-architecture properties above. Procurement teams that haven't yet rewritten their template are the ones reporting stalled buying cycles — see Why on-prem AI deployments stall in procurement for the full pattern.

Second, the strictest jurisdiction sets the architecture. A multinational deployer designing against the EU AI Act's 2 December 2027 obligations [1] won't fail US, UK, Japanese, or Singaporean requirements — see the EU AI Act compliance article for the per-obligation mapping. The cross-jurisdiction convergence the OECD Toolkit [5] documents is what makes one architecture viable.

Third, the procurement-cycle math has changed. Products that fit residency-first close in 2–3 months; products that don't take 12+ [3]. Enterprises buying AI in 2026 should price the architectural fit before the per-seat cost — a 9-month procurement delay is more expensive than any per-seat differential.

References

  1. European Commission. "AI Act — Regulatory framework on AI." digital-strategy.ec.europa.eu. Accessed 2026-07-22.
  2. European Commission. "AI Act omnibus political agreement, 7 May 2026." digital-strategy.ec.europa.eu. Accessed 2026-07-22.
  3. Andreessen Horowitz. "State of Generative AI in the Enterprise." a16z.com/generative-ai-enterprise-2024. Published 21 March 2024. Accessed 2026-07-22.
  4. NIST. "AI Risk Management Framework." nist.gov/itl/ai-risk-management-framework. Accessed 2026-07-22. Critical Infrastructure concept note released 7 April 2026.
  5. OECD AI Policy Observatory. "AI Policy Toolkit." oecd.ai/en/wonk. Accessed 2026-07-22. Released 3 June 2026.

Related articles

Walk the architectural shift through a real workload.

A free 1-week pilot puts the four residency-first properties — inference, audit, identity, no vendor tenant — into the customer's environment, with the compliance team writing the deployer-obligation memo against their own logs.

Get release updates

New free AI products, major updates, and a few releases available only via this site. No spam.