Skip to content

Private AI

A European lab released a "sovereign" AI model you can run yourself. Here is what that word does and does not cover.

Aleph Alpha released an open-weight model called Kolibri on October 3, 2026, and describes it as sovereign. The direct answer for a business owner: a model you can download is one piece of a private AI setup, not the whole thing. The hardware, the people to run it, and the rules for your data still decide whether it helps you. Treat the word "sovereign" as a description of where a model came from, not a guarantee about how you will use it.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

Aleph Alpha, a German AI company, released Kolibri on October 3, 2026. According to its launch post and the model card on Hugging Face, Kolibri is an English-German mixture-of-experts model with about 78 billion parameters in total, of which about 3.5 billion are active for each piece of text it processes. The full weights are free to download under the Apache 2.0 license. Aleph Alpha says it built the model for regulated work such as public administration, industry, and aerospace, trained it in Germany and Finland, and designed it so customers can run it on their own infrastructure instead of sending data to an outside provider. The model card lists a minimum of two 80 GB A100 GPUs, or one H200, B200, or B300, with about 78 GB needed just to hold the model. The benchmark scores in the announcement are Aleph Alpha's own. We have not seen independent results.

Why it matters for business owners

Many owners have heard that private AI means your data never leaves your building. Kolibri is a clear, concrete example of what that path looks like when a vendor actually ships it. The model is free to obtain. The card is also specific about what it takes to run it, and that is the part worth reading. It also shows the "sovereign" idea moving from a policy argument into a product. For companies with strict data rules, a model whose origin, license, and hosting you can point to is easier to defend than a service whose back end you cannot see. That is a real benefit. But it is a benefit for a specific kind of buyer. Aleph Alpha itself frames Kolibri around regulated sectors, German and English, and organizations that already have infrastructure and technical staff.

What owners should not misunderstand

Do not read "open weights" as "free to run." The model costs nothing to download. The hardware to serve it, the engineering to keep it running, the security work around it, and the time to test it on your tasks are all yours. The model card says the full model has to sit in memory even though only part of it is active at once. Do not read "sovereign" as "compliant." Aleph Alpha says it designed Kolibri with the EU AI Act and data protection law in mind. Whether your use of it meets your own legal obligations depends on what you do with it, and that is a question for your counsel, not a property you inherit from the model. Do not read "open" as "fully open." The Apache 2.0 license covers the model files. Aleph Alpha says it keeps rights to its training code and methods. Do not take the benchmark table as your result. Vendor-published scores show how a model did on general tests. They say little about your contracts, your emails, or your customer questions. Aleph Alpha's own model card says the model is meant for work where a person reviews the output, not for unreviewed decisions. And do not forget scope. Kolibri covers German and English. If your work runs in other languages, it is not built for that.

The operational lesson

Owning the model and owning the outcome are different things. Private AI is a bundle: a model, the machines it runs on, the system that connects it to your documents, the people who maintain it, and the rules about who can ask it what. A free, well-built model removes one cost. It leaves the rest. That is why the first question is rarely which model. It is which data genuinely cannot leave your control, and what it would cost to keep that data in-house compared with a business-grade cloud plan with clear terms. For most small and mid-sized businesses, the honest answer is that only a small part of their work needs this level of control. That part may justify a private setup. The rest usually does not.

What a serious business should do next

Sort your AI use into three groups: work that can use a public business-grade tool, work that needs tighter data rules, and work that truly cannot leave your environment. Only the third group is a candidate for self-hosting. If you have something in that third group, price the whole setup before you compare models. Include the machines, the person who will run them, security, monitoring, and the time to test. Compare that to a private cloud option, which often covers the real concern for less. Then run a small test on your own documents and tasks, with a person reviewing every result, before you commit to hardware. If you do not have a data-handling rule for AI today, write that first. It is useful whichever route you choose.

The Atlacis view

Atlacis helps owners slow down before an AI decision, work out which data and workflows actually need private handling, and choose the simplest setup that covers the real risk. A new open model is good news for that conversation because it widens the options. It does not change the order of the questions. If you are weighing private AI and are not sure whether your data justifies it, start with the decision, not the download.

The short version

  • On October 3, 2026, Aleph Alpha released Kolibri, an English-German open-weight model under Apache 2.0, pitched for on-premise use in regulated work.
  • The model card lists about 78 GB of memory for the weights and a minimum of two 80 GB A100 GPUs or one H200, B200, or B300.
  • Free to download does not mean free to run. Hardware, staff, security, and testing are the real cost.
  • "Sovereign" describes where a model came from. It does not make your own use of it compliant.
  • Benchmark scores here are the vendor's own. Test on your tasks, with a person reviewing the output.
Tags:private AIopen-weight modelson-premise AIAI hardwareAI decision supportAleph Alpha
FAQ

Common questions

Does an open-weight model mean my data stays private?
Only if you run it on infrastructure you control and set up the access rules around it. The model being open does not protect your data by itself. How it is deployed and who can use it does.
Do small businesses need hardware like this?
Usually not. Most small and mid-sized businesses can cover real work with business-grade cloud tools and clear data rules. Self-hosting has to earn its cost with a specific data or control requirement.
Does a sovereign model make me compliant with EU rules?
No. The vendor says it designed the model with those rules in mind, but your obligations depend on how you use it. Ask your legal adviser about your own use case.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.