MICKAI®ArticlesThe Future of AI Infrastructure, …
Article · 22 July 2026

The Future of AI Infrastructure, 2026 to 2035

Infrastructure control migrates from vendor to operator across the decade, driven by regulation, not preference.

Author
Micky Irons
Published
22 July 2026
Follow Micky Irons
LinkedInX
sovereign aiai infrastructurefuture of aieu ai actpost-quantum cryptography

AI infrastructure between 2026 and 2035 moves in one broad direction: control over the model, the data and the audit trail migrates from the vendor back to the organisation running the workload. The cloud API remains the default for experimentation, but for anything regulated, safety critical or nationally sensitive, the winning pattern becomes infrastructure the operator owns, can inspect, and can prove the behaviour of, offline, without calling home to a vendor. Regulation is the forcing function: the EU AI Act, the proposed EU Cloud and AI Development Act, DORA, NIS2 and a widening set of national rules all converge on the same demand, that an organisation using AI for anything consequential must be able to show what the system did and why, on request, years after the fact.

Why this matters now: the infrastructure decisions boards make in 2026 and 2027 set the shape of their AI estate for the rest of the decade. Migrating a fleet of agents off a cloud platform, or retrofitting an audit trail onto three years of undocumented AI decisions, is materially harder than building the evidentiary layer in from day one. The organisations that treat infrastructure as a compliance afterthought in 2026 are the ones scrambling in 2029.

What will change in AI infrastructure between 2026 and 2035, in one paragraph?

Five shifts compound over the period: infrastructure ownership moves from rented to owned for regulated workloads; audit and provenance move from optional logging to cryptographically sealed record as a design requirement; cryptography migrates from classical to post-quantum signing ahead of the "harvest now, decrypt later" threat window; compute moves from a single hyperscaler default to a deliberately multi-tier stack (public cloud, sovereign or regional cloud, and fully on-premise); and governance moves from a written policy to a continuously enforced control, because regulators increasingly want evidence, not a statement of intent. None of these are speculative. Each is already visible in a live regulation, a published standard, or a procurement pattern in 2026.

Why is infrastructure ownership becoming a board-level question rather than an IT decision?

Three pressures are pushing the "where does this run" question up the organisation chart. First, regulatory exposure: under the EU AI Act, a deployer of a high-risk system carries duties, human oversight, monitoring, record keeping, that do not disappear because the underlying model is rented from a third party. The deploying organisation, not the vendor, answers to the regulator. Second, third-party risk: DORA, in force since 17 January 2025, requires financial entities to manage concentration risk in critical ICT third parties, including AI vendors, and to hold exit strategies for each one. A single foundation-model dependency that cannot be exited on reasonable notice is precisely the concentration risk DORA was written to surface. Third, vendor continuity: an AI vendor can be acquired, deprecated, or have its terms changed unilaterally, and when a workload sits entirely inside someone else's infrastructure, the deploying organisation has limited leverage to prevent that from becoming its own outage.

None of this means every organisation needs to own a data centre. It means the ownership question, who controls the infrastructure this workload depends on, has become a board-level risk decision rather than a procurement default.

What does the AI infrastructure stack look like by the early 2030s?

The single-tier "everything runs on one hyperscaler API" model is giving way to a three-tier stack, and most organisations will run a deliberate mix rather than picking one tier exclusively.

TierWhat it isFits
Public cloud APIRented inference against a hyperscaler or frontier lab's hosted model, data leaves the organisation's boundaryLow-sensitivity, high-velocity experimentation and consumer-facing workloads
Sovereign or regional cloudInfrastructure located, owned or controlled within a defined jurisdiction, addressing residency and supply-chain transparency without full on-premise operationRegulated data that must stay in-region but does not warrant a fully air-gapped estate
On-premise or air-gappedInfrastructure the operator physically controls, with inference running on hardware it owns, disconnected from the public internet by defaultClassified, ITAR-adjacent, critical national infrastructure, and any workload where a connected estate is itself the unacceptable risk

The proposed EU Cloud and AI Development Act, adopted by the European Commission on 3 June 2026, formalises something close to this stack in policy: a four-tier cloud sovereignty ladder running from EU data location, through demonstrated independence from non-EU control and EU ownership, up to a Strategic Autonomy Cloud with full software supply-chain transparency. It remains a legislative proposal working through the EU process, not law in force, but the direction of travel, treating infrastructure sovereignty as a graded, procurable attribute rather than a binary, is unlikely to reverse regardless of the final text.

How will regulation reshape AI infrastructure architecture through the early 2030s?

Regulation is the single biggest architectural input over this period, and four strands matter most for infrastructure planning.

The EU AI Act's deferred but real high-risk timeline

The Act's prohibited-practice and AI-literacy duties have applied since 2 February 2025, and general-purpose AI model obligations since 2 August 2025. The originally planned 2 August 2026 date for stand-alone high-risk systems (Annex III) has been superseded: the Digital Omnibus on AI deferred it to 2 December 2027, with product-embedded high-risk systems (Annex I) deferred further, to 2 August 2028. Article 50 transparency duties, telling people they are dealing with AI or AI-generated content, stayed largely on the original near-term schedule. The deferral buys build time, it does not remove the underlying requirement for risk management, technical documentation, logging and human oversight, and infrastructure decisions made now should assume those duties arrive on schedule in 2027 and 2028.

Financial and critical-infrastructure resilience rules

DORA already requires regulated financial entities to test operational resilience against ICT disruption, including AI dependencies, and to hold documented exit strategies for critical providers. NIS2 extends security and incident-reporting obligations to a wide band of "essential and important entities" across critical sectors, a broader category than the "critical entities" language sometimes mistakenly used for it (that narrower term belongs to the separate CER Directive). The UK sits outside NIS2's scope but is building its own regime; the Data (Use and Access) Act 2025, given royal assent in June 2025 and commencing in stages, reworks the UK's automated-decision-making rules and is one part of that picture.

A widening, non-EU regulatory front

2026 has produced signals that AI infrastructure regulation is not a European-only story. China's Implementation Opinions on intelligent agents, reported to become enforceable from 15 July 2026, are reported to introduce authorisation tiers and filing requirements for higher-risk agents. A US state, Illinois, has reportedly enacted the first state-level law requiring annual independent safety-plan audits for large frontier-model developers, ahead of any comparable US federal requirement. The transferable lesson for infrastructure planners outside either jurisdiction is not the specific statute, it is the shape: every jurisdiction converging on a mandate, an identity and a reviewable record for consequential AI use, whether the AI is a model, an agent, or an embedded system.

Sector guidance filling the gaps

Alongside binding law, the UK's AI Growth Lab, announced 8 June 2026, brings regulators including the ICO, the SRA and the Legal Services Board together to give sector-specific steer, starting with lawtech and conveyancing. Guidance channels like this do not replace the underlying legal duties, but they signal where enforcement attention concentrates first, and infrastructure investment tends to follow enforcement attention by twelve to eighteen months.

What happens to the hardware and energy layer?

Two hardware trends run through the whole period. The first is the continued split between training-scale compute, still overwhelmingly a hyperscaler and frontier-lab game because of the capital involved, and inference-scale compute, which is increasingly viable on operator-owned hardware as model efficiency improves and quantisation techniques mature. An organisation that could not plausibly have trained a competitive model in 2023 can, by the late 2020s, run a capable model entirely on its own premises for day-to-day inference, selecting CPU or GPU execution based on its own latency, cost and availability constraints rather than a vendor's default. The second trend is energy: AI compute's power draw has become a visible constraint on data-centre siting and grid capacity in multiple markets, and organisations planning multi-year on-premise or sovereign-cloud infrastructure increasingly treat power availability as a first-order design input alongside chip supply, not an afterthought.

How does post-quantum cryptography change AI infrastructure by 2030?

Cryptographic migration is one of the few infrastructure shifts on a fixed, non-negotiable clock, set by the maturity of quantum computing rather than by any AI-specific regulator. The US National Institute of Standards and Technology has finalised its post-quantum standards: FIPS 204 (ML-DSA) is the primary post-quantum digital signature standard, with FIPS 205 (SLH-DSA) as a second, hash-based signature standard for diversity of approach, and FIPS 203 (ML-KEM) covering key encapsulation, not signing. Any AI infrastructure that seals an audit record, a model provenance chain, or a software update pipeline with a digital signature has a migration decision to make well before a cryptographically relevant quantum computer exists, because the "harvest now, decrypt later" threat model means data or records signed today with classical cryptography alone can be broken retroactively once that capability arrives. For infrastructure being specified now, choosing a post-quantum or hybrid signature scheme for anything expected to hold evidentiary weight for years, an audit ledger, a compliance record, a long-lived software supply chain, is a design decision worth making at the outset rather than as a later retrofit.

What does "sovereign AI" mean by 2035, and who actually needs it?

The term has been used loosely enough to mean almost anything, from "hosted in the same country" to "fully air-gapped." By the early 2030s the useful definition converges on three testable properties, not a marketing label: the operator can run the system with the network cable removed and it still functions; the operator holds the cryptographic keys and audit chain, not the vendor; and the operator can prove, offline and without vendor cooperation, what the system did on any given date. Judged against that test, most of what is sold as "private AI" today, a dedicated instance inside a hyperscaler's cloud, a single-tenant deployment still dependent on the vendor's infrastructure, does not qualify, and does not need to for most use cases. The organisations that genuinely need the full sovereign test are a defined, not universal, set: defence and national security, critical national infrastructure operators, regulated financial services handling systemically important functions, healthcare bodies holding population-scale special-category data, and any organisation whose regulator explicitly prohibits data leaving a defined boundary. For everyone else, a well-governed private or regional-cloud deployment, with a genuine, contractually enforceable exit path, remains a proportionate choice. The infrastructure planning task for the 2026 to 2035 period is matching the tier to the actual risk, not defaulting to the most extreme option, or the cheapest, without doing that mapping first.

Will agentic AI change infrastructure requirements?

Yes, and it is one of the least settled parts of the decade ahead. An agent that can take actions, not just generate text, needs infrastructure that answers a different question than a chatbot does: not only "what did the model say," but "what did the system do, under whose authorisation, and can that be proven after the fact." China's 2026 agent rules are an early, concrete signal that regulators are moving in this direction, requiring an authorisation tier and a filing for higher-risk agents rather than treating an agent as just another model call. The infrastructure implication is that agent-capable systems need an identity for every agent, a scoped mandate defining what it is authorised to do, and a reviewable, tamper-evident record of every action it took, sealed at the point of action rather than reconstructed afterwards from application logs that were never designed as evidence. Organisations building or buying agentic capability over this period should expect that record-keeping requirement to arrive as regulation, in some jurisdictions before 2030, whether or not it exists yet in the market they operate in today.

The infrastructure decision that matters most for the 2026 to 2035 period is not cloud versus on-premise as a single binary choice, it is whether the organisation can prove what its AI did, offline, years after the fact, regardless of which tier it runs on.

Where does this leave build, buy and rent decisions?

Cohere, Mistral, IBM with its Granite models on-premise, and Microsoft's own on-premise stack all already offer private deployment options where the vendor cannot see the operator's data, and each is a genuine, capable route for organisations whose primary requirement is confidentiality. Private and on-premise availability is table stakes across serious enterprise AI vendors by 2026, not a differentiator on its own. Where the market is still thin, and where infrastructure planning through the 2030s needs to pay closest attention, is the layer above confidentiality: cryptographic, offline-verifiable, action-level audit that a regulator or a court can check without calling the vendor, and the software an organisation actually runs its operations on, not a model it has to integrate into somebody else's platform. Mickai is a Sovereign Intelligence Operating System built specifically on that layer, running offline on operator-owned hardware, with every action sealed into a post-quantum signed audit ledger, backed by 104 filed UK patent applications covering 2,340 claims, owned by Mickai LTD. It is one credible route through this decade for organisations that need the full sovereign test, alongside in-house build programmes and the on-premise offerings of the vendors named above; which route fits depends on the organisation's regulatory exposure, its engineering capacity, and how much of its own infrastructure it is prepared to own outright. How the fuller architecture fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Will every organisation need on-premise or air-gapped AI by 2035?

No. The organisations that need the full sovereign test, offline function, operator-held keys, offline-provable audit, are a defined set: defence, critical national infrastructure, systemically important financial functions, population-scale health data holders, and organisations whose regulator bars data from leaving a defined boundary. Most organisations are better served by a well-governed private or regional-cloud deployment with a genuine, contractually enforceable exit path.

Is the EU AI Act's high-risk deadline still 2 August 2026?

No. The Digital Omnibus on AI deferred stand-alone high-risk (Annex III) obligations to 2 December 2027, and product-embedded high-risk (Annex I) obligations to 2 August 2028. Article 50 transparency duties largely stayed on the original near-term schedule. The deferral extends the build window, it does not remove the underlying requirement.

Is the EU Cloud and AI Development Act already law?

No. It is a European Commission legislative proposal, adopted 3 June 2026, setting out a four-tier cloud sovereignty ladder and a target to reduce reliance on non-EU cloud providers. It remains in the EU legislative process and is not yet in force, though the direction it signals, sovereignty as a gradeable procurement attribute, is already shaping buyer expectations ahead of any final text.

Why does post-quantum cryptography matter for AI infrastructure being built today?

Because of the "harvest now, decrypt later" threat: data or signed records captured today under classical cryptography alone can potentially be broken retroactively once a sufficiently capable quantum computer exists. Any AI infrastructure sealing an audit record or software supply chain with a long expected evidentiary life should use a post-quantum or hybrid signature scheme, such as FIPS 204 (ML-DSA), from the outset rather than retrofitting it later.

Does agentic AI need different infrastructure from a chatbot?

Yes. An agent takes actions, not just generates text, so its infrastructure needs to answer what the system did and under whose authorisation, not only what it said. That requires an identity and a scoped mandate per agent, and a tamper-evident record sealed at the point of action, which most application logging was never designed to provide.

What is the single most important infrastructure decision to get right before 2027?

Building the audit and provenance layer in from the start, rather than treating it as a later addition. Migrating agent fleets or retrofitting a cryptographically sound audit trail onto years of undocumented AI activity is materially harder and slower than designing the evidentiary layer alongside the AI capability itself.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/future-of-ai-infrastructure-2026-2035. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles