My editorial verdict: I would not buy “AI hosting” as one undefined bundle. I would first split the system into five layers, then reject any proposal that cannot name who operates each layer and what crosses its boundary.
What are you actually hosting?
You are rarely hosting only a model. You are assigning an operating home to five connected layers. IBM describes AI infrastructure as the hardware and software needed to develop and deploy AI applications, including compute, data storage, networking, and software resources (IBM AI infrastructure, verified 18 August 2026). That broad scope is why a GPU-hosting page or model endpoint is not, by itself, a complete agent hosting plan.
The five-layer map below is a buying framework. It does not claim that every product uses these labels.
- Model endpoint. This is the service or runtime that receives an inference request. Hugging Face describes Inference Endpoints as a managed service that deploys models on fully managed infrastructure (Hugging Face Inference Endpoints, verified 18 August 2026).
- Agent or application runtime. This holds workflow logic and decides when to call a model or tool. n8n documents self-hosting on infrastructure you own, including on-premises or private-cloud infrastructure, with deployment methods for npm, Docker, and server platforms (n8n hosting, verified 18 August 2026).
- State and data. This includes the working records, files, retrieval stores, outputs, and other data the runtime uses. IBM includes data storage and management in its description of AI infrastructure (IBM AI infrastructure, verified 18 August 2026).
- Tools and actions. These are the external systems the runtime can query or change. n8n’s current security overview covers SSL, SSO and user controls, node and public API restrictions, security audits, and hardening for its own product (n8n security, verified 18 August 2026).
- Control and observability. This layer covers administrative access, logs, monitoring, configuration, and operating evidence. NIST’s zero-trust publication says zero trust focuses on protecting resources and grants no implicit trust based only on physical or network location (NIST SP 800-207). It is a general architecture reference, not proof that a hosting product is secure or compliant.
Boundary check: A dashboard can be local while its model call is external. A model can be on-premises while identity, updates, or telemetry remain external. Record each path instead of transferring one layer’s label to the whole system.
For adjacent ownership questions, use the box-versus-SaaS guide and the private AI boundary guide.
Who owns each AI hosting boundary?
Ownership means naming both the decision owner and the operator. The matrix is a worksheet, not a statement that every service behaves the same way. Fill each cell from current product documentation, configuration, contracts, and operating records.
| Layer | Boundary to record | Authority to assign | Evidence to request |
|---|---|---|---|
| Model endpoint | Where inference requests go and which endpoint is selected | Who can select or change the model and endpoint | Endpoint configuration and applicable vendor documentation (Hugging Face, verified 18 August 2026) |
| Agent/runtime | Where workflow logic executes | Who can deploy, stop, and update it | Runtime configuration and named maintenance owner (n8n hosting, verified 18 August 2026) |
| State/data | Where working records, files, and stores sit | Who grants access and defines the backup scope | Storage map, access roles, and backup configuration (IBM AI infrastructure, verified 18 August 2026) |
| Tools/actions | Which systems can receive queries or changes | Who approves credentials, scopes, and actions | Tool allowlist, credential owner, and approval record (n8n security, verified 18 August 2026) |
| Control/observability | Where configuration, logs, and administrative routes live | Who can inspect, administer, or support the system | Role list, logging configuration, and support-access route (NIST SP 800-207) |
The matrix makes split ownership visible. IBM describes a private cloud as a single-customer environment and says a managed private cloud outsources infrastructure management to a third party (IBM private cloud, verified 18 August 2026). Those statements support a tenancy and responsibility distinction. They do not locate every model call, tool connection, log, or administrator.
How do the four AI hosting categories compare?
The categories differ by the default operating boundary, not by a universal quality rank. A real deployment can combine them. Treat each category below as an equally weighted starting point and verify the actual service.
Managed model endpoint
A managed endpoint places model deployment on provider-operated infrastructure. Hugging Face describes its own Inference Endpoints as a managed service on fully managed infrastructure (Hugging Face Inference Endpoints, verified 18 August 2026). That source supports Hugging Face’s delivery model only; it does not establish the behavior of other vendors or settle the runtime, data, tool, and control layers around the endpoint.
Use this category when the endpoint is the boundary under review. Ask what request the runtime sends, who can change the endpoint, where endpoint-related logs sit, and how the endpoint is removed from the workflow.
Managed application or agent runtime
A managed runtime places application operation with a provider under that service’s stated responsibilities. This category describes a boundary to verify, not a general guarantee for managed agent platforms.
Use this category when you want to examine provider operation of the workflow layer. Still map external endpoints, connected tools, data stores, administrative roles, logs, backups, updates, and export scope separately.
BYOC or private cloud
A private cloud is dedicated to one customer under IBM’s definition, while a managed private cloud outsources infrastructure management to a third party (IBM private cloud, verified 18 August 2026). “Bring your own cloud” is not defined by the cited source, so treat BYOC as a proposal-specific term and request its precise responsibility split.
Use this category when the assigned cloud environment matters. Verify which control-plane services remain outside that environment, who holds operator access, which services are shared, and who owns updates and recovery. The AI agent platform guide expands that component-level review.
Self-hosted or on-premises
n8n documents self-hosting on infrastructure you own, including on-premises or private-cloud infrastructure, and lists deployment methods for npm, Docker, and server platforms (n8n hosting, verified 18 August 2026).
Use this category when direct infrastructure operation is part of the requirement. Do not infer that every dependency is local. Check model endpoints, identity, software sources, tool connections, logs, support routes, and backups as separate paths.
No category wins by label: Managed does not remove buyer responsibility, private cloud does not describe the entire data path, and self-hosted does not prove isolation. Those conclusions require evidence from the selected architecture and its operators.
What should an AI hosting buyer verify?
A buyer should leave the evaluation with seven written answers and evidence for each one. NIST says the AI Risk Management Framework is voluntary and intended to help organizations manage AI risks (NIST AI RMF). The checklist below is a procurement aid, not an AI RMF assessment, security certification, or legal conclusion.
- Data path: Draw the route from input through runtime, model endpoint, state store, tools, output, logs, and backups. Attach the current configuration or provider document that supports every crossing (IBM AI infrastructure, verified 18 August 2026).
- Authority: Name who can start, stop, change, or approve the runtime, endpoint, storage, credentials, and actions. NIST zero trust rejects implicit trust based only on network or physical location, but it does not certify a product or deployment (NIST SP 800-207).
- Logs: Record what the selected system logs, where those records go, who can read them, and which settings control them. Confirm the answer from the chosen service and configuration. n8n’s security page supports only its own guidance, not every vendor’s logging behavior (n8n security, verified 18 August 2026).
- Backups: State which components enter the backup scope, who runs the process, and who owns restoration. IBM includes storage in AI infrastructure, while the actual backup behavior remains deployment-specific (IBM AI infrastructure, verified 18 August 2026).
- Operator access: List customer, provider, support, automation, and emergency roles that can administer a resource. NIST SP 800-207 provides general zero-trust architecture guidance, not proof that those roles are correctly configured (NIST SP 800-207).
- Updates: Assign the host, runtime, model, connector, and configuration update duties.
- Exit: List the configurations, records, files, credentials, and evidence the buyer expects to retrieve or revoke. Confirm export and deletion behavior from current, service-specific terms. The NIST AI RMF is general risk guidance and does not prove a migration or exit outcome (NIST AI RMF).
Mark an answer “unknown” when the evidence is missing. That is more useful than turning a product label into an unsupported statement.
Is free or cheap AI hosting the right starting point?
No-not for this boundary decision. Start with the workload and operating map. A “free,” “cheap,” “GPU,” or “AI cloud hosting” label does not identify the five layers or allocate their duties. The cited sources describe infrastructure scope, specific vendor delivery models, private-cloud responsibility patterns, and risk frameworks; they do not support a cross-vendor price, performance, availability, confidentiality, migration, or total-cost comparison (IBM AI infrastructure; Hugging Face; n8n hosting, all vendor facts verified 18 August 2026).
Compare commercial terms only after candidates pass the same boundary worksheet. This guide deliberately makes no claim about profitability, value, or the lowest-cost provider.
How should a small firm choose?
Choose the smallest operating boundary that still gives the firm a named owner and acceptable evidence for every required layer. This is an editorial decision rule, not a technical fact. A solo operator who does not want server duties should not describe those duties as solved merely because a model endpoint is managed. A firm that requires an assigned cloud environment should not assume the surrounding control plane shares that boundary. A self-hosting team should not assume that installing software also assigns updates, recovery, or support.
Take the completed matrix into the vendor conversation. Require specific answers, record unknowns, and compare all four categories with the same questions. For one operating approach, not a ranked winner or proof of fit, see the AI Jungle OS cockpit.
Can you test the map with one real job?
Yes. Pick one small job and trace it on paper. Do not start with a product. Start with the work. A solo owner might choose a draft email. A small firm might choose a summary of a client file. Use a task that the team knows well.
Write the first input at the left edge. Name the person who sends it. Name the app that receives it. If a file is added, draw that path too. Stop when a location or owner is not known. Write “unknown” beside that step.
Now draw the model call. Name the endpoint. Do not write “cloud” alone. Add the service and the account owner. Then mark who can change that endpoint. If no one knows, keep the gap on the page.
Move back to the runtime. Ask who can start it. Ask who can stop it. Ask who can change its rules. Add one name or role for each answer. Avoid “the team.” It hides the owner.
Trace state next. Mark the prompt, file, working note, and final output. Some jobs will not use each item. Cross out what does not apply. For each item that remains, write its store and access owner.
Then trace the tool path. A draft may have no action. A send step does. Mark where approval sits before the action. Name the credential owner. Name the person who can revoke it. Keep the model call and the tool action as two separate paths.
Finish with the control layer. Mark the log destination. Mark the backup scope. Mark the admin route. Mark the update owner. Mark the exit item. Each mark should point to a setting, document, role, or record.
Run the same paper test for each hosting category. Keep the task fixed. Change only the proposed boundary. This gives each option the same questions. It also keeps the talk tied to the job.
Do not fill a blank with a guess. Ask the vendor or operator. Save the answer with its source. Add the check date. If the answer depends on a setting, name that setting. If it depends on a contract, name that document.
At the end, read the map from left to right. Then read it from right to left. The first pass follows the work. The second pass checks who can change, inspect, restore, or remove each part. A short map with clear gaps is useful. A neat map with guessed answers is not.
This exercise does not prove security, privacy, or compliance. It gives the buyer a clear set of questions. Use the NIST sources as general risk and architecture guidance only, within their stated scope (NIST AI RMF; NIST SP 800-207).
FAQ
What is AI hosting?
AI hosting is the operating arrangement for the model endpoint, agent runtime, state and data, tools and actions, and control and observability layers. This is the practical definition used in this guide.
Is AI model hosting the same as AI hosting?
No. Model hosting covers the endpoint or runtime that serves inference. A working AI application can also have an agent runtime, state stores, tools, logs, backups, and administrative access (IBM AI infrastructure, verified 18 August 2026).
Does private cloud mean every AI component is private?
No. IBM’s private-cloud definition establishes a single-customer environment, but the buyer must still locate external endpoints, tools, logs, support routes, and control-plane services (IBM private cloud, verified 18 August 2026).
Does self-hosted AI prove security or compliance?
No. Self-hosting does not itself prove a security or compliance outcome. NIST’s zero-trust and AI RMF publications remain general guidance, not product certification (NIST SP 800-207; NIST AI RMF).
Written by Tileo, who operates a portfolio of internet businesses on this same cockpit.

