41 minutesPrivate AI vs. Cloud: How Enterprise Leaders Can Make Smarter Build-or-Buy Decisions
Make AI build-vs-buy decisions around outcome, data control, workload economics, infrastructure readiness and operational ownership.
MSP GLOBAL. Carme Artigas chaired the Council negotiations that produced the AI Act, and here she explains it to managed service providers through which many SMEs buy AI systems. She walks the timeline understood at the time, from the August 2025 GPAI code of practice to an August 2026 conformity-assessment milestone, and discusses vendor documentation. The [AI Omnibus, Regulation (EU) 2026/1744](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202601744), later moved the relevant Chapter III high-risk requirements to 2 December 2027 for Annex III systems and 2 August 2028 for systems covered by Annex I. The inventory, vendor-evidence and ownership work remains useful, but the video's dates are historical.
A negotiator's keynote provides context, not legal advice. The current dates above come from the amending regulation; verify the classification and obligations for your system against current EU law and relevant Estonian guidance before changing policy.
Compare the video's historical timeline with current EU law, then map the current deadlines to the vendor-evidence and ownership tasks an SME must schedule.
Basic awareness of which AI systems your business runs or buys and of the Act's risk-based approach.
Last reviewed: Aug 11, 2026
Continue through the same learning path with the next curated companion videos.
41 minutesMake AI build-vs-buy decisions around outcome, data control, workload economics, infrastructure readiness and operational ownership.
56 minutesBuild an ROI case for one AI workflow with a baseline, direct and indirect benefits, quality gates and an explicit stop decision.
37 minutesEvaluate private AI as an infrastructure and governance decision instead of defaulting to either SaaS or self-hosting by instinct.
Hand-picked external courses that go deeper on this topic.
AWS Training and Certification
A cloud-vendor-specific complement to the Macquarie specialization: AWS's own Generative AI Security Scoping Matrix, OWASP Top 10 for LLMs, and MITRE ATLAS, walked through governance, legal, and compliance controls for five different AI deployment scopes — from consumer apps to self-trained models. Not GDPR-specific, but a genuinely practical advanced pick for teams whose AI workloads actually run on AWS and need concrete data-governance and compliance controls, not just theory.
Macquarie University Cyber Security Hub faculty
An advanced pick for professionals responsible for both GDPR compliance and AI security: a three-course specialization from Macquarie University's Cyber Security Hub that goes from GDPR/CCPA fundamentals and privacy-by-design, through privacy impact assessments, to a dedicated third course on securing AI systems against adversarial attacks and model leakage. It genuinely bridges the two rather than treating them as separate topics.
CyberSuite
The rare AI Act course written for the companies the Act actually reaches: SMEs adopting AI, not the labs building it. Hosted on the European Commission's own skills platform, it pairs the legal side — roles, obligations, risk classification — with the security side (prompt injection, data leakage, supplier due diligence) that most compliance courses skip. For an Estonian SME deploying AI, this is the practical starting point.