Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
Every AI roadmap at major corporations currently hits the same blind spot. They plan models, data centres, and talent—but they fail to plan for the very materials that hardware is made from. Gallium, germanium, rare earths, ultra-pure copper: without secure access to these inputs, every semiconductor and AI strategy remains an equation with an unknown variable. By 2026, raw-material policy will no longer be an afterthought for procurement. It will be tech policy—and belong on the board agenda.
Key Takeaways
Related:Compute Capacity Becomes the Supply Chain / Sovereignty Trumps Price
What is the Critical Raw Materials Act? The Critical Raw Materials Act is an EU regulation that entered into force in 2024. It defines a list of critical and strategic raw materials and sets target benchmarks for what share of these materials should be mined, processed, and recycled in the EU by 2030. The goal is to reduce dependence on individual supplier countries.
For a long time, raw material procurement was seen as a topic decided two levels below the board. That is no longer the case. The very materials underpinning AI infrastructure are the same ones at the center of geopolitical tug-of-war. When a supplier country ties export licenses for gallium to conditions, that is not a purchasing bulletin—it is strategic intelligence that belongs in the same meeting as the cloud strategy.
I have reviewed enough corporate roadmaps to recognize the pattern. The AI strategy is meticulously calculated down to the GPU generation. The question of where the components of that GPU come from and how vulnerable that path is appears nowhere. It is tacitly delegated to a hardware supplier, who in turn silently passes the buck further down the chain. At the end of the line stands a single country. No one in the corporation knows exactly which one.
It is precisely this gap that elevates the raw materials question to the executive level. Not because the CIO should start mining operations, but because otherwise no one owns the risk. A dependency without an owner in the org chart becomes a surprise in a crisis. And surprises in the supply chain are expensive.
Source: International Energy Agency, Critical Minerals Reviews
This concentration is the real issue. The bottleneck is not extraction from the ground, but processing. A material can be mined in many places around the world yet refined almost exclusively in one location. Anyone who talks diversification while only considering the mine—and not the refinery—has not grasped the problem.
The EU has set binding targets for the first time with the Critical Raw Materials Act, rather than merely issuing declarations of intent. Three of these targets are crucial for the tech sector and all share the same deadline year.
For senior management, the final line is the most important. The 65 percent threshold is not an abstract foreign-trade figure; it is a requirement that cascades downward. Suppliers shipping into the EU will increasingly have to prove that their own supply chains comply with this logic. A hardware-procurement contract lacking transparency on origin will therefore become a liability over time.
For proper context: the Critical Raw Materials Act is a target-driven framework with levers, not an automatic switch. It accelerates permits for strategic projects, mandates risk analyses from large companies, and creates a framework for joint procurement. What it cannot do is build a refinery overnight. The timeline is the second half of this decade. That is precisely why decisions must be made now.
Vulnerabilities rarely lie where the board suspects them. They rarely reside with the well-known chipmaker whose name everyone recognizes. The weak point is usually one layer down: a specialized supplier providing a single material in the required purity.
Three failure points recur in risk analyses. The first is the processing stage. A material may be mined in several places, yet refining to semiconductor-grade quality is concentrated in a handful of plants. If one goes offline—due to export controls, an accident, or a political decision—there is no quick replacement.
The second failure point is lack of visibility. Most corporations know their direct supplier and perhaps their supplier’s supplier. Anything below that is a black box. When the critical dependency sits on the fourth tier, even the strongest contractual relationship at the first tier offers no protection.
The third failure point is the assumption that a high price solves the problem. During genuine scarcity, allocation—not price—becomes the issue. Whoever lacks a contractually secured volume will be at the back of the queue, no matter how much they are willing to pay. Money cannot substitute for a delivery contract.
Analysis yields a concise list of concrete steps. None are exotic, yet each requires a decision at a level that is often not involved today.
First: Contractually demand transparency of origin. Hardware framework agreements need a clause obliging suppliers to disclose the origin of critical materials, at minimum down to the processing stage. Without this visibility, no risk assessment is possible.
Second: Multi-source strategy, not the illusion of multiple suppliers. Two suppliers sourcing from the same refinery are one source, not two. A true second source must be separated down to the processing stage. This is more expensive and slower, but it is the difference between resilience and its simulation.
Third: Take recycling seriously as a procurement pathway. Decommissioned servers, networking hardware, and end devices contain precisely the materials in question. Treating old hardware merely as disposal items forfeits a raw material source explicitly prioritized by the Critical Raw Materials Act.
A raw materials strategy can look complete on paper yet fail in practice. The patterns below typically decide the difference.
The gap between the columns is not a knowledge gap. Most procurement organizations know the theory. What is missing is the mandate to enforce the more expensive, slower option against short-term cost pressure. That mandate can only come from the top.
The above assessment assumes the Critical Raw Materials Act will take effect. That is not guaranteed. Three objections deserve honest answers.
The first objection concerns the timeline. Permitting, building, and ramping up a refinery takes years. The 2030 target is ambitious. Some capacity will not be online by then. That is true. It is still not an argument against the regulation, but an argument to start now.
The second objection is price. Within the EU, processed raw materials will remain more expensive than world-market prices for the foreseeable future. Pure cost optimizers will avoid this. The calculation changes, however, once supply security is treated as its own value in the equation. Geopolitics is forcing that shift right now.
The third objection is enforcement. A regulation with targets is only as strong as its reporting obligations. Here lies a real weakness: as long as disclosure requirements remain vague, the 65-percent threshold can become a formality. Management should therefore not wait for perfect regulation, but secure its own supply chain regardless.
Treating raw-material policy as tech policy doesn’t mean launching a new mega-project. It means putting three items on an agenda where they’ve been missing so far.
First, assign raw-material risk to an owner. One C-level executive who reports where critical dependencies lie and how resilient the counter-measures are. Without that assignment, the risk remains a no-man’s-land.
Second, embed provenance transparency in every new hardware contract—not as an appendix, but as a condition. Suppliers unable to disclose the origin of their critical materials represent a risk that must appear in the contract.
Third, fold the materials dimension into every AI and infrastructure roadmap. A compute plan that maps models and data centers but omits the stuff hardware is made of is incomplete. The raw-material question isn’t the end of the tech strategy; it’s its foundation.
Because the materials underpinning AI and semiconductor hardware are the same ones fueling geopolitical rivalries. An export restriction on gallium or rare earths directly impacts compute availability. That makes the materials layer a risk factor that belongs in the same planning tier as cloud and AI strategy—not two levels down.
Strategic raw materials are those essential to key technologies such as semiconductors, batteries, and renewable energy while also carrying high supply risk. They include rare earths, gallium, germanium, lithium, and high-purity copper. The Critical Raw Materials Act lists them separately and sets binding targets for each.
The rule that no single third-country can supply more than 65 percent of any strategic raw material cascades down the chain. Companies shipping hardware into or operating it within the EU will increasingly need to prove provenance. Procurement contracts lacking that transparency will, over time, become compliance and supply hazards.
Not necessarily. Two suppliers drawing from the same refinery are effectively one source. A robust second source must diverge at the refining stage. True diversification is measured at the refinery, not the number of contract partners.
The binding targets run to 2030, yet lead times are long. Building contract structures, second sources, and recycling pathways takes years. Waiting for an actual shortage means missing the window. These decisions therefore belong in the annual planning cycle, not a later strategy round.
Read more on Digital Chiefs
Digital ChiefsSaaS Portfolios Need an Exit Strategy, Not Another ToolDigital ChiefsSovereignty beats price: the new procurement signalDigital ChiefsWhich IT Budget Survives the Cuts RoundMore from the MBF Media Network
Image source: AI-generated (May 2026), C2PA certificate embedded in image