Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
8 min read · Updated: 23.04.2026
Ray Wang and Constellation Research have published the Enterprise Intelligence Monthly on April 22, 2026. The central message directly impacts boardroom discussions: AI is transitioning from promise to execution. Agentic scaling reveals architectural weaknesses. Cybersecurity is becoming the control layer for AI operations. Three observations are essential for board members to read, as they can shift the strategic tone for the next board meeting. Ignoring this update as a US-centric background noise overlooks the critical shift.
What is Agentic AI Scaling? Agentic AI scaling describes the transition from individual agentic applications in the pilot phase to multiple agents operating productively in business processes. It requires a comprehensive platform with shared identity, data, and compliance layers. Companies operating a single agent do not need a platform, but those running ten do. By 2026, many companies that have invested in individual use cases over the past 18 months will reach this threshold. Constellation identifies these scaling challenges as a central board-level issue.
In the April update, the observation focuses on agentic applications transitioning from pilot to scaling in 2026. This creates a different class of scaling challenges compared to individual pilots. Suddenly, interactions between agents emerge, and permission boundaries need to be redefined. Cost allocation per agent becomes a serious control challenge. Ray Wang argues that many companies underestimate this scaling challenge because the pilot phase gives a false impression of complexity.
A second observation changes the role of the CISO. Constellation argues that by 2026, cybersecurity will no longer be a risk layer alongside business layers but the control layer for AI operations. Companies running productive agentic applications need security mechanisms that provide audit trails, identity boundaries, and response pipelines. This elevation of the CISO role has direct implications for board structures. Boards that delegate cybersecurity to the audit committee must actively manage the integration with the tech mandate.
The third observation impacts vendor evaluation. Constellation notes that competitive advantage is shifting from models to infrastructure. By 2026, having the best model will be less critical than having the best data and compute infrastructure. This has strategic implications for vendor selection, platform investments, and contract architecture. The Meta Muse Spark Closed-Source Shift is a signal in this direction: vendors are now competing for platform dominance rather than model headlines.
The first observation focuses on strategic architecture discussions. Supervisory boards should explicitly ask in the next meeting how many agentic applications are currently running productively in the house, which platform layer they connect to, and how the scaling logic is planned. Those without a consolidated answer have a governance issue. The Merck-Google-Cloud Alliance is an example of how this architectural question is addressed in a regulated conglomerate.
The second observation changes the CISO mandate. Boards should clarify whether their CISO has the mandate and resources to oversee AI operations as a control layer. In many DACH houses, the CISO mandate is still traditionally limited to IT security without explicit AI responsibility. Those who do not update this risk shifting the responsibility to a position without a formal mandate. This can lead to avoidable friction during the first serious crisis.
The third observation requires a provider inventory. Which of our current AI and platform providers have genuine infrastructure depth, and which primarily sell models? Which contracts should be adjusted by 2026 or 2027 because the competitive logic has shifted? This inventory is worth a half-day strategy workshop with IT leadership, procurement, and compliance. The managed services discussion provides the operational template.
The Constellation note is not alone. Three additional April signals reinforce the strategic message. First, the Merck-Google-Cloud Alliance on April 22 with its commitment to Gemini Enterprise as a platform rather than individual KI tools. Second, the Cognizant-Fortune argumentation on outcome-based IT service models that cannot function without an agentic AI platform. Third, the ASP.NET Core patch wave from Microsoft, which shows how closely engineering and compliance must be intertwined by 2026.
For supervisory boards, this results in a consistent message. The KI discussion in 2026 is not a side-season tech initiative but an integrated strategy, security, and investment question. Those who treat it in isolation in any of these three areas build in friction losses. Those who integrate it gain strategic depth. This integration requires conscious board architecture where tech, risk, and strategy topics do not fall into separate committees.
A second connection deserves attention. The Constellation observation on cost governance directly links to the FinOps maturity discussion. Those who want to perceive KI as a quarterly burden need a consolidated cost allocation view that spans across departments and tools. Supervisory boards should request a consolidated cost report quarterly that details KI spending by business unit, provider, and use case class. Those who cannot provide such a report have a governance gap that will become visible in the next crisis.
Three months are sufficient for substantial preparation of the next board meeting with a clear stance on the three constellation observations.
Three strategic consequences deserve the attention of boards. First: Tech topics lose their niche position in the board calendar. AI will be a cross-cutting theme in every strategy, risk, and investment discussion by 2026. Anyone who relegates the AI discussion to an annual agenda item has a governance problem. A quarterly tech session with a clear topic architecture is the answer.
Second: The hybridity of mandates increases. CIO, CISO, and CFO work more closely together in the AI discussion than two years ago. Boards should actively shape the interfaces, otherwise friction losses will occur. A clear mandate clarification with documented responsibilities per AI axis is not bureaucracy but governance hygiene by 2026.
Third: The evaluation of external sources becomes more important. Constellation, Forrester, Gartner, and Bitkom provide different slices of the same reality. Boards should not favor one source but consciously shape the mix. Anyone who builds a quarterly synthesis from two US sources and two DACH sources has a better discussion foundation than a house that relies on a single provider report.
One final observation belongs in the strategic discussion. Constellation argues that the competitive landscape will shift faster in 2026 than board routines can keep up. Anyone as a board member who has a quarterly reporting that does not reflect the shift is flying blind. The adjustment of reporting logic belongs in the next meeting. Anyone who delays this will be in a discussion in 2027 that they could have prepared for in 2026.
Ray Wang is the founder and principal analyst at Constellation Research in Silicon Valley. His Constellation Enterprise Intelligence Monthly is recognized as one of the most important independent sources for enterprise technology topics. Supervisory boards appreciate the combination of quantitative observation and sharp analysis, which structures board discussions.
Constellation works leaner and more opinionated, while Gartner and Forrester bring greater research depth and quadrant evaluations. Constellation is ideal for strategic briefings, and Gartner and Forrester are better for vendor selection. A combined use covers the spectrum.
Bitkom studies for Germany, Lünendonk for vendor evaluations in the DACH market, and IfM Bonn for mid-sized company perspectives. Constellation and these sources complement each other well because DACH structures are not fully captured by US reports.
Quarterly as a mandatory program, monthly for tech-focused Supervisory Boards, or when making important architecture decisions. A quarterly internal synthesis on one page is the right cadence.
The CISO function will mandate AI operations by 2026, with identity boundaries for agents, audit trails for agent decisions, and a detection layer for unexpected AI behavior. Cybersecurity will become a cross-cutting theme, not a downstream risk block.
Once you reach five to ten productive agents, a true platform architecture becomes worthwhile. Below that, ad-hoc setups may suffice, but beyond that, complexity without a platform becomes uneconomical. Supervisory Boards should actively monitor this threshold.
Merck x Google Cloud as a Board Template for Agentic AI
MyBusinessFuture: Constellation April 2026 for Mid-sized Companies
Source Title Image: Pexels / Werner Pfennig (px:6949476)