AI Orchestration · Data Stays In-House · n8n, Open-Weights, DLP

AI in production. Data stays in-house.

Sovereign, model-independent, DMZ-capable. Cloud API is an option, not the default.

AI orchestrated in B2B industrial operations — with an architecture that works without sending data to US or China cloud: n8n as workflow engine, open-weights models like Llama or Mistral with local inference, OpenCode as development agent, DLP filter at the egress. On-prem, DMZ, or at a sovereign DACH hosting provider (AD IT Systems, IONOS, Hetzner, Open Telekom Cloud, StackIT). Cloud models (Anthropic, OpenAI, Google) are an option, not the default.

Architecture Stack

Three layers.
One stays in-house.

AI without cloud lock is no longer a research question in 2026 — it is an architecture choice. Bitkom Cloud Monitor 2024 shows: 65 % of DACH companies prefer German cloud or multi-cloud with a DE anchor, 41 % explicitly for sovereignty reasons. The US CLOUD Act and uncertain EU-US data adequacy make the frame doubly sharp. Three layers underpin every sovereign AI operation — combinable with cloud APIs as an option, but without requiring them.

Open-Weights Llama · Mistral · Qwen · Mixtral

Inference models with commercial usage licenses, runnable on your own GPU hardware or at sovereign DACH hosting providers. Llama 3.3 70B and Mistral Mixtral 8x22B (Apache 2.0) as the default choice for DACH B2B mid-market. Qwen and DeepSeek as reasoning options, but with a compliance caveat for KRITIS and defense applications due to China origin. Quantization (int8 / int4) makes 70B models runnable on a single H100 or two A100s. Swap models without rebuilding skills.

Source: Meta Llama 3.3 (12/2024) · Mixtral 8x22B (Apache 2.0) · Mistral Research License
n8n + OpenCode Workflow and Engineering Layer

n8n as a self-hosted workflow engine with AI nodes for local models and cloud APIs alike — mail triage, document routing, RFQ automation, ERP sync all run as executable workflows. OpenCode as a terminal-based engineering agent, model-agnostic, capable of addressing local inference or cloud APIs. Both on-prem-capable, GDPR-compliant without third-country transfer.

Source: n8n.io · sst/opencode · self-hosted Sustainable License
DLP Egress Data sovereignty at the call level

When a cloud API does make sense (frontier reasoning, specialized OCR workloads), a DLP egress layer checks every call: customer IDs, internal endpoints, sensitive strings are masked or blocked before transmission. Audit log per call, Annex III documentation-capable. Sovereignty is the architecture default; cloud egress is the controlled exception.

Source: NIS2 + KRITIS + EU AI Act Art. 10 data governance obligations
Four Specializations

One architecture.
Four entry triggers.

Which specialization fits you depends not on a marketing wish but on the trigger in your operations. The matrix below shows the entry occasion, the Phase 1 output, and the sovereignty path for each row.

Specialization Trigger in operations Phase 1 output Sovereignty default
AI Readiness Audit Board demands strategy, shadow AI in-house, no neutral vendor assessment, KRITIS or NIS2 pressure. Written decision basis with use case list, sovereignty mapping, AI Act filter, roadmap. Vendor-neutral assessment of cloud vs. on-prem per use case, without reseller bias.
AI in Engineering Operations Codebase conventions are ignored, senior review bottleneck, sending code to US cloud is blocked. Codebase skill map, OpenCode setup with local model, first productive skills in pilot team. OpenCode plus open-weights model on your own hardware, cloud API as optional boost for frontier reasoning.
AI Content Operations Content output pressure is rising, brand voice at risk of dilution, voice data should not go to external providers. Voice extraction as an executable Voice-Lock, n8n pipeline with local inference, drift metric documented. n8n on-prem, open-weights inference for voice review, cloud only optional for non-sensitive outputs.
Spryker plus AI Spryker stable in production, ACP apps purchased but unused, customer data should not go to Vertex AI. Stack audit with ACP activation status, use case map, sovereignty options per use case. Spryker Glue as model-agnostic connector, local reorder models as alternative to Vertex AI.
Architecture in practice

Three patterns that cost you sovereignty.

Three patterns from active engagements — what surfaces regularly in discovery workshops and the first pilot weeks when AI setups run into their data privacy reality.

  1. Pattern 01 · Cloud Default Bias

    "We'll just use OpenAI" — until Legal shows up.

    Pilots start with a cloud frontier API because it is fast. Three weeks later comes the data protection impact assessment, third-country transfer question, KRITIS auditor. What was meant as a quick start turns into re-architecture with open-weights inference and a DLP egress layer. Planning sovereignty as default from day 1 avoids the loop without losing cloud options.

    Consequence
    Pilot pause for re-architecture under compliance pressure
    Frame-Reset
    On-prem default, cloud as a controlled option
  2. Pattern 02 · Model Lock

    Skills are stapled to a vendor's feature set.

    Building skills only against a vendor-specific skill mechanism means you cannot switch later without a full rebuild. We build workflows as n8n graphs with tool-calling specifications that work equally with Llama, Mistral, Qwen, Anthropic, and OpenAI. Switching models is a configuration task, not a reimplementation. Open-source frameworks (LangChain, LangGraph, CrewAI) are the portable building blocks.

    Risk
    Vendor skill lock forces a complete rebuild
    Frame-Reset
    Workflows as portable graphs, not vendor features
  3. Pattern 03 · Governance Afterthought

    DLP, audit logs, and approval gates only arrive at the works council.

    Pilots run freely and get pushed to production. Only then comes compliance review, the works council, GDPR impact assessment. Pilot pause, rework, frustration all around. We build governance hooks in from day 1: DLP egress filter per workflow, n8n execution logs as audit trail, approval gates for sensitive actions. Compliance is not a brake — it is a platform requirement.

    Consequence
    Pilot pause for compliance rework
    Frame-Reset
    Governance hooks from workflow day one

Sovereignty, model portability, and governance can be built as one architecture, not three separate workshops. That is the difference between workbench and whitepaper.

Before you call

Five questions, five straight answers.

"What does sovereign AI architecture mean in practice?"
Data sovereignty across the full inference path: your prompt, your business data, and the model output never leave your network. We build workflows with n8n and an open-weights model (Llama, Mistral, Qwen, or Mixtral) on your own GPU hardware or at a sovereign DACH hosting provider. Cloud frontier APIs stay optional per use case, with a DLP egress layer in front — but not as the default.
"Do we have to commit to a model?"
No. Skill architecture, n8n workflows, and governance patterns are model-agnostic. On-prem default is typically Llama 3.x or Mistral; cloud frontier (Anthropic, OpenAI, Vertex) stays as an option per use case. Swap models without rebuilding skills.
"Which specialization fits our setup?"
No plan? Audit. Engineering team with code sovereignty needs? AI in Engineering Operations (OpenCode plus local model). Marketing output with voice data control? Content Operations. Spryker with on-prem AI extension? Spryker plus AI. The matrix above is the honest routing logic.
"How does this fit with the EU AI Act, GDPR, and KRITIS?"
Sovereignty is the simplest answer to third-country transfer and high-risk obligations. If the data never leaves the network, many compliance discussions simply disappear. Audit logs per workflow call are generated automatically, Annex III documentation-capable. KRITIS and NIS2 operators get an architecture without cloud egress.
"How does an engagement start?"
Phase 1 is always scoped: audit, OpenCode skill onboarding, voice extraction workshop, or Spryker stack audit. Terms are mandate-specific. Extensions are decided phase by phase — no lock-in, no retainer pressure.
Architecture depth

Five architecture principles that outlive the model.

For the deeper read on the layer architecture: data class separation, MCP tool contract, vendor abstraction. With verified sources — Bitkom 09/2025, EU AI Act Annex III, Cohere/Aleph Alpha announcement 04/2026. Read the architecture principles →

Experience & contact

Deep platform expertise.

25 years in IT, 14 of them in B2B commerce. Architecture mandates with large enterprises, building and steering distributed expert teams, vendor-neutral project rescue. Focus areas: platform architecture, project rescue, team operations.

Chris Zepernick

Senior consultant · Hamburg

What we have learned

Sovereignty is default, not premium.

When you bring AI into operations, you face two architecture choices: data leaves the network or stays in it. Both are legitimate, but only one is the honest default for DACH B2B industry under NIS2, KRITIS, and the AI Act. We build the default architecture — n8n, open-weights, OpenCode, DLP egress. Cloud APIs stay open where they fit. But they are an option, not a prerequisite.

How we work

Which specialization hits your bottleneck?

Audit, engineering, content operations, or Spryker plus AI — a few minutes on the phone and we sort out honestly which of the four specializations holds your first lever.