Executive summary
- Open models are good, and still behind. The best models you can run on your own infrastructure trail the best closed models by three to four months, and the gap did not close in 2026.1
- The strongest open models are Chinese. Running their weights locally removes data transfers to China; bias trained into the model remains.3 Strong European and US alternatives exist one tier lower.
- "Open" no longer means unrestricted. Several leading models now carry revenue thresholds or regional limits that matter to large companies.
- Cost alone rarely justifies self-hosting. Hardware and GPU rental became more expensive in 2026 while API prices kept falling. The business case is control.
- Data law drives the regulatory case. High-risk AI Act duties start in December 2027. DORA, NIS2 and US data-access law are the more immediate drivers.
1. Capability and origin
Two independent trackers agree on the size of the gap. Epoch AI finds that since January 2026, the best open-weight models have trailed the best closed models by four months on average, slightly more than the three-month average of 2023 to 2025.1 On the Artificial Analysis Intelligence Index, the leading closed model scores 58 and the leading open model 46.2
Open models are good, and still behind
The best open-weight model scores 46 on the Artificial Analysis index, against 58 for the best closed model. All three leading open models come from Chinese labs.
The strongest model you can run yourself trails the frontier by 12 points.
Artificial Analysis Intelligence Index v4.3, score
Source: Artificial Analysis, index v4.3, September 2026. Scores are not comparable with earlier index versions.
Lindstead
For a board, the practical reading is this: the open model you can deploy today performs roughly like the closed frontier of a few months ago. For well-defined business tasks such as document processing, search and drafting, that is often sufficient. For the hardest reasoning work, it is not yet.
The second fact is less comfortable. Every open model near the top of the rankings comes from a Chinese lab. Government actions in Italy, the Netherlands, Germany and the Czech Republic have targeted the hosted DeepSeek app and its data transfers. None concerned weights run on an organisation's own servers. Running weights locally removes that transfer. It does not remove behaviour trained into the model: the US standards body NIST found that DeepSeek models echoed state narratives four times as often as US models.3
2. Licences
Open weights come with very different rights. Mistral Medium 3.5 grants no rights to companies with more than $20 million in monthly revenue unless they buy a commercial licence.4 Meta's Llama 4 policy withholds its multimodal rights from companies based in the EU.5 Alibaba moved its flagship Qwen model from Apache 2.0 to a custom licence.6 Permissive licences remain for, among others, Mistral Small and Large, DeepSeek, Gemma, gpt-oss and Granite.
Exhibit 2
Permissive licences remain available in every region, but not at the very top.
| Model | Licence | Minimum hardware |
|---|---|---|
| Europe | ||
| Mistral Small 4 Mistral AI (FR) | Apache 2.0 | 4× H100 or 2× H200 |
| Mistral Large 3 Mistral AI (FR) | Apache 2.0 | 8× H200 (FP8) |
| Mistral Medium 3.5 Mistral AI (FR) | Modified MIT | 2× H200 (FP8) |
| EuroLLM-22B EU research consortium | Apache 2.0 | 1 GPU |
| TildeOpen-30B Tilde (LV) | CC BY 4.0 | 1 GPU |
| United States | ||
| gpt-oss-120b OpenAI | Apache 2.0 | 1× 80 GB GPU |
| Gemma 4 Google | Apache 2.0 | 1 GPU |
| Nemotron 3 Ultra NVIDIA | NVIDIA open model licence | 2 to 4× B200 |
| Llama 4 Maverick Meta | Llama 4 Community | 8× H100 |
| Granite 4.2 IBM | Apache 2.0 | 1 GPU |
| China | ||
| MiMo-V2.6-Pro Xiaomi | MIT | 8× B200 |
| DeepSeek V4 Pro DeepSeek | MIT | 8× H200 or 8× B300 |
| Kimi K3 Moonshot AI | Kimi K3 License | 8× B200 minimum |
| Qwen3.8 (flagship) Alibaba | Qwen3.8-Max License | Multi-node |
| GLM-5.3 Z.ai | GLM-5.3 License | 8× H200 |
Source: model cards and licence texts, accessed 27 September 2026. Hardware is indicative for production inference. Full detail in the Model Index.
3. Economics
2026 moved the economics against self-hosting. Memory shortages pushed an NVIDIA RTX PRO 6000 from its launch price of $8,565 to about $16,000 on NVIDIA's own store.7 The median rental price of an H200 rose by about 25 percent in twelve months.8 Over the same period, the price of a given level of AI capability through an API kept falling steeply.9
Renting GPUs is getting more expensive
GPU rental prices are rising. Nebius, headquartered in Amsterdam, raises its on-demand prices by 17 to 21 percent on 1 October 2026.
European GPU rental prices are rising across every GPU generation.
On-demand price per GPU, $ per hour
Source: verda.com/pricing and nebius.com/prices, accessed 27 September 2026; on-demand list prices
Lindstead
Independent research from Carnegie Mellon finds that owning hardware pays back within months for small models, in about two years for medium models and in about five years for large ones. It is mainly viable at high, steady volumes or under strict data-residency requirements.10 Our own break-even analysis reaches the same conclusion: against a mid-priced closed model, an owned eight-GPU server breaks even only at several billion tokens per month, before staff costs.
4. Regulation and control
The AI Omnibus, in force since 27 July 2026, postponed high-risk obligations to 2 December 2027 for stand-alone systems and to 2 August 2028 for AI embedded in regulated products. Transparency duties under Article 50 apply from 2 August 2026.11 A company that simply deploys an open model is in most cases a deployer under the Act.
The more immediate pressure comes from elsewhere:
- US data access. Under the US CLOUD Act, US providers can be compelled to hand over data they control wherever it is stored. Microsoft France told the French Senate under oath that it could not guarantee this would never happen.12
- DORA. Financial entities must manage ICT third-party risk and plan exits. In November 2025 the European supervisors designated 19 critical ICT providers, including AWS, Google Cloud and Microsoft.13
- NIS2. The Dutch Cyberbeveiligingswet has been in force since 15 August 2026 and brings supply-chain security duties to more than 8,000 organisations.14
- Transfers. The EU-US Data Privacy Framework stands, but an appeal is pending at the Court of Justice. The accurate description is legal uncertainty.15
5. Security
Self-hosting removes third-party access to prompts and outputs, and gives you audit and exit control. It does not make a model safe. Prompt injection tops the OWASP list of LLM risks,16 and the UK National Cyber Security Centre warns it may never be fully mitigated.17 Research by Anthropic and the UK AI Security Institute showed that around 250 poisoned documents can plant a backdoor in models of very different sizes.18 When you run the model, these risks become yours to manage.
Demand for sovereign AI is broad, but rarely owned by the board
Demand for sovereign solutions is broad, and strongest in Germany and the Nordics. Yet only 16 percent of organisations treat it as a board-level issue.
Six in ten European organisations are looking for sovereign AI.
Organisations actively seeking sovereign solutions, %
1 Share of organisations actively seeking sovereign solutions; survey of 1,928 organisations in 28 countries, July to August 2025.
Source: Accenture, November 2025
Lindstead
6. What leaders should do
- Classify workloads by data sensitivity. Most AI use can stay on APIs. Reserve private deployment for the data you cannot afford to share.
- Set a model-origin and licence policy. Decide at board level which origins and licence types are acceptable, before engineering teams choose for you.
- Start in a European cloud. Rent capacity from an EU-owned provider to prove value before buying hardware at 2026 prices.
- Treat models as supply chain. Verify weights, prefer safe file formats, red-team before production, and plan for monthly model updates.
Organisations are moving in this direction: Accenture reports that 62 percent of European organisations are seeking sovereign AI solutions,19 and HSBC chose to run Mistral models on its own infrastructure.20
Sources
- Epoch AI, Open-closed ECI gap, 29 May 2026. epoch.ai/data-insights/open-closed-eci-gap
- Artificial Analysis, Intelligence Index v4.3 changelog and model pages, September 2026. artificialanalysis.ai/changelog
- NIST CAISI, Evaluation of DeepSeek AI models, 30 September 2025. www.nist.gov/news-events/news/2025/09/caisi-evaluation-deepseek-ai-models-finds-shortcomings-and-risks
- Hugging Face, Mistral-Medium-3.5-128B licence. huggingface.co/mistralai/Mistral-Medium-3.5-128B
- Meta, Llama 4 Acceptable Use Policy. www.llama.com/llama4/use-policy
- Qwen3.8-2.4T-A95B licence, Hugging Face. huggingface.co/Qwen/Qwen3.8-2.4T-A95B
- Thunder Compute, NVIDIA RTX PRO 6000 pricing, September 2026. www.thundercompute.com/blog/nvidia-rtx-pro-6000-pricing
- getdeploying.com, NVIDIA H200 rental prices, accessed 27 September 2026. getdeploying.com/gpus/nvidia-h200
- Epoch AI, LLM inference price trends, 12 March 2025. epoch.ai/data-insights/llm-inference-price-trends
- Carnegie Mellon University, cost-benefit analysis of on-premise LLM deployment, arXiv 2509.18101. arxiv.org/abs/2509.18101
- Lewis Silkin, The Digital Omnibus on AI enters into force, 27 July 2026. www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo
- The Register, Microsoft exec admits it cannot guarantee data sovereignty, 25 July 2025. www.theregister.com/off-prem/2025/07/25/microsoft-exec-admits-it-cannot-guarantee-data-sovereignty/458553
- EIOPA, ESAs designate critical ICT third-party providers under DORA, 18 November 2025. www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en
- Rijksoverheid, Cyberbeveiligingswet in force from 15 August 2026. www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht
- WilmerHale, Court of Justice to review challenge to EU-US Data Privacy Framework, 1 December 2025. www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework
- OWASP, Top 10 for LLM Applications 2025. genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
- UK NCSC, on prompt injection, December 2025. www.ncsc.gov.uk/news/mistaking-ai-vulnerability-could-lead-to-large-scale-breaches
- Anthropic, UK AI Security Institute and Alan Turing Institute, A small number of samples can poison LLMs of any size, October 2025. www.anthropic.com/research/small-samples-poison
- Accenture, Europe seeking greater AI sovereignty, November 2025. newsroom.accenture.com/news/2025/europe-seeking-greater-ai-sovereignty-accenture-report-finds
- HSBC and Mistral AI partnership, 1 December 2025. www.hsbc.com/news-and-views/news/media-releases/2025/hsbc-and-mistral-ai-join-forces-to-accelerate-ai-adoption-across-global-bank
Method: desk research of public sources, accessed 27 September 2026. Vendor-sponsored data is labelled as such. This briefing contains no paid content. Corrections: hello@lindstead.com.