From the deeplit® team, on private AI.
Checkout our latest blog posts

BUILD VS BUY
AI token cost: why the bill outruns the budget
Token prices are falling while AI bills explode. The 2026 blow-ups, why per-token cost outruns every budget, and the flat-rate alternative: a GPU-hour you can forecast before you run anything.

ARCHITECTURE
Agentic workflows on internal infrastructure
An agentic workflow that runs the planner, the model, the tools, and the audit log behind the customer's firewall. The architecture, the EU AI Act Article 26 deployer frame, and the cases where it is overbuilt.

FINTECH
Financial services AI compliance under DORA
How the November 2025 Critical ICT Third-Party Provider designations changed the fintech-to-bank conversation under DORA. Why customer-environment AI deployment keeps your bank customer's third-party register short, and what to put in the data processing agreement.

COMPLIANCE
GDPR DPA template for AI: the seven clauses that matter
The seven clauses that decide whether a Data Processing Agreement fits AI infrastructure deployments. What each clause should say, where generic templates trip up, and how the GDPR Article 28 and EU AI Act Article 26 frames apply together.

LEGAL-TECH
Legal AI confidentiality and the EU AI Act: privilege in Europe
How the Council of Bars and Law Societies of Europe, three national bar positions, and the EU AI Act's deployer obligations converge on one architectural answer for legal-tech founders selling generative AI into European law firms.

COMPLIANCE
EU AI Act and GDPR Article 28: where AI vendor responsibility ends
Where your AI vendor responsibility ends, and your end-customer's begins. Three deployment shapes, three audit boundaries, and how the EU AI Act and GDPR Article 28 map onto each. The post most often forwarded into compliance review.

HEALTHCARE
Healthcare AI compliance: NEN 7510, GDPR Article 9, and deployment
The hospital security review is asking architectural questions, not certificational ones. NEN 7510, GDPR Article 9, and EU AI Act Article 26 each map onto customer-environment deployment without forcing a six-month vendor-certification path.

FROM THE FOUNDER
Private AI for startups: a founder-to-founder read
A founder-to-founder read on private AI for startups: the audit-boundary definition, the three 2026 shifts pushing your customer's compliance team away from the hosted-API answer, and what to do before the deal slips.

ARCHITECTURE
Private AI in your customer's GCP project
The architecture, the access pattern, and the audit-log defaults for shipping private AI into an end-customer's cloud account. Five phases. Time-bounded SSH during setup. Read-only or zero vendor access in steady state. Forward to your customer's compliance team.

PRIVATE AI
Private LLM vs public LLM: four ways to ship private AI
Private LLM vs public LLM: when your customer's compliance team rejects the hosted API, there are four real options. The Euro math behind each tells you which fits a 10- to 30-person startup.

BUILD VS BUY
The real cost of self-hosting an open-weight LLM
The honest math for a 10- to 30-person Dutch startup pricing the build path. Hardware is 20 percent of the cost. The 2.5 engineers are 80 percent. The opportunity cost of an engineering quarter is what tips the comparison.