A PBX vendor recently told me something I did not expect to hear: customers are asking for on-premise systems again.
Looking broader into the entire market, I can see how this makes a lot of sense. Companies are becoming increasingly uneasy about where critical infrastructure and sensitive data live. AI fraud is getting better. Voice cloning is becoming more convincing. Vibe coding is allowing less experienced developers to build faster, but not always more securely. Quantum computing is still over the horizon, but serious companies are already thinking about what it may mean for encryption and long-term data protection.
For the past decade, cloud migration was treated as the obvious strategy. It gave companies speed, scale and lower upfront costs. Startups could launch without buying servers. Enterprises could modernize without rebuilding their own infrastructure.
That logic still holds. But we are witnessing an interesting shift where progress is happening so fast, security cannot keep up, thus creating an uneasy feeling causing decision-makers to revert back to older, and perhaps safer perceived strategies.
Here are three trends that I believe are pushing on-prem back into the limelight.
AI fraud is changing the security conversation
In many cases, cloud providers are more secure than what a company could build internally. The issue is that thanks to AI, attackers are becoming more sophisticated, and quick. AI makes phishing more polished, fake invoices more believable, and voice impersonation harder to detect. A call that sounds like the CFO or CEO asking for a payment approval is no longer far-fetched.
That changes how companies think about exposure. The attack surface is not only servers. It is identity systems, SaaS tools, APIs, employee workflows, permissions, contractors and support portals.
For sensitive systems such as communications, payments, identity and customer data, control becomes more valuable. On-prem does not guarantee security. But it can reduce dependency on outside platforms and give companies clearer ownership over the systems they cannot afford to compromise.
Enterprise AI may favor private infrastructure
Cloud AI APIs are excellent for testing. A company can launch a pilot quickly without buying GPUs, managing models, or hiring a large infrastructure team.
But enterprise AI is moving into production. That changes both the economics and the risk.
The most useful enterprise AI applications require proprietary data: contracts, source code, customer records, financial reports, support tickets, security logs, medical files and internal communications. This is the data that gives AI business value. It is also the data companies are most careful with.
For these use cases, on-prem or private AI infrastructure becomes more attractive. The model can run closer to the data. Access can be controlled more tightly. Retention, compliance and audit requirements become easier to manage.
There is also a cost angle. Token pricing is convenient in a pilot, but expensive at scale. When thousands of employees or customers use AI every day, paying per query can become a serious recurring cost. For stable, high-volume workloads, owning or controlling the infrastructure may be cheaper than renting every interaction forever.
Quantum risk is making long-term data protection more strategic
Quantum computing is not breaking enterprise encryption today. But the risk is already part of serious security planning.
The concern is that the minute quantum becomes commercial, all encrypted data sitting in the cloud will be transparent. No existing encryption will hold against a quantum computer. That matters most for companies holding long-life sensitive data: banks, healthcare providers, telecom companies, governments, defense-related organizations and infrastructure providers.
Regardless of whether or not on-prem is the best solution for all this, it is perceived as such. Hence, I believe it will drive higher demand for the legacy on-prem strategy. This early shift is also an opportunity, but that’s for another article.
Itay Sagie is a strategic adviser to tech companies, investors, CEOs and boards, specializing in strategy, growth and M&A. He is a guest contributor to Crunchbase News and a university lecturer on strategy, finance and entrepreneurship. Learn more at SagieCapital.com and connect with him on LinkedIn.
Photo by Kevin Ache on Unsplash.
Stay up to date with recent funding rounds, acquisitions, and more with the Crunchbase Daily.
67.1K Followers
Facts Only
* Customers are asking for on-premise systems again.
* Increased customer unease exists regarding the location of critical infrastructure and sensitive data.
* AI fraud is becoming more sophisticated, affecting phishing, fake invoices, and voice impersonation.
* The attack surface includes identity systems, SaaS tools, APIs, employee workflows, permissions, contractors, and support portals, not just servers.
* Control over sensitive systems like communications, payments, identity, and customer data is valued.
* On-premise systems reduce dependency on outside platforms and provide clearer ownership over compromised systems.
* Enterprise AI applications requiring proprietary data favor private infrastructure because it allows the model to run closer to the data with tighter access controls.
* Token pricing for cloud AI can become a serious recurring cost at scale, making infrastructure ownership potentially cheaper for high-volume workloads.
* Quantum computing poses a future risk, as existing encryption may not hold against quantum computers once commercialized.
Executive Summary
Customers are requesting on-premise systems again, driven by growing unease regarding where critical infrastructure and sensitive data reside. This shift is fueled by advancements in AI fraud and voice cloning, which increase the sophistication of threats, and the potential future risk of quantum computing to current encryption standards. While cloud migration offered initial benefits in speed and cost, rapid technological progress has created a security lag, prompting decision-makers to favor perceived safer strategies like on-premise systems.
The trend is supported by several specific drivers: AI fraud necessitates greater control over identity systems, as the attack surface expands beyond servers to include workflows and permissions. For enterprise AI applications that rely on proprietary data—such as source code or customer records—on-premise or private infrastructure offers advantages in controlling access, ensuring compliance, and managing costs associated with high-volume queries compared to token-based cloud APIs at scale. Furthermore, the looming threat of quantum computing elevates long-term data protection concerns, making legacy strategies more strategically appealing for highly sensitive assets.
Full Take
The narrative highlights a tension between the speed of technological advancement and the pace of security adaptation, suggesting that perceived safety drives strategic decision-making. The shift back toward on-premise infrastructure is not purely technical but stems from a desire for increased sovereignty—control over data in the face of evolving threats (AI fraud) and existential risks (quantum computing). The concept that proprietary data ownership directly correlates with security control is a critical pivot; as AI becomes the primary economic driver, the friction introduced by external, black-box cloud services becomes an unacceptable risk for handling core assets.
This pattern suggests a feedback loop where novel threats (AI) exacerbate existing anxieties about external dependency, pushing organizations toward self-contained solutions. The attractiveness of on-premise systems in the context of AI and quantum shifts implies that security is moving from a compliance checklist to a fundamental determinant of business viability. The question for observers is whether this reversion represents a genuine strategic realignment or an overreaction driven by fear. What mechanisms exist for building trust in self-managed systems when the very entities that pose the greatest risk (e.g., sophisticated AI adversaries) are constantly evolving? Does prioritizing control over access inadvertently create new, centralized points of failure that become even more attractive targets?
Sentinel — Human
The text functions as an opinion-based analysis synthesizing current technological anxieties into a strategic argument for revisiting on-premise infrastructure, strongly suggesting human authorial intent.
