Summary
- CTI Digital has opened Croft externally after developing the private AI platform for its own operations.
- The stack supports self-hosted models, retrieval, agents, workflows, on-premises deployment, and a managed private-cloud option.
- The product illustrates how sovereign-AI procurement increasingly depends on architecture, data control, access, and external dependencies rather than nationality alone.
Manchester technology company CTI Digital has opened its Croft private AI platform to external customers after developing the stack for its own operations, extending the market for enterprise systems designed to keep models, data, retrieval, and automated workflows under tighter organisational control.
Croft supports self-hosted language models, retrieval-augmented generation, agents, and workflow automation, with deployments available on premises or through a managed private-cloud environment. CTI Digital presents the platform as an alternative to sending sensitive organisational data through public AI services whose infrastructure and model-training arrangements may sit outside the customer’s direct control.
The product arrives as more organisations move beyond isolated chatbot trials towards AI systems connected to internal documents, databases, and business processes. That shift increases the amount of sensitive information exposed to models while also giving automated systems greater ability to retrieve data and take actions across enterprise environments.
Private infrastructure can reduce some of those dependencies, although the label “sovereign AI” describes an architecture and control model rather than a guarantee. Customers still have to understand where models come from, how they are updated, which external components remain in the stack, and who can access the underlying infrastructure.
Private AI moves beyond the chatbot
Early enterprise generative-AI deployments often centred on standalone assistants used for drafting, summarisation, and search. Croft’s broader design reflects the next phase of adoption, where retrieval systems connect models to proprietary information and agents are given permission to carry out multi-step tasks rather than simply return text.
Those capabilities can make AI more useful because they ground responses in organisational data and allow systems to participate directly in workflows. They also make governance harder, since an agent with access to customer records, internal documents, or operational systems can expose or alter information if permissions are too broad or its instructions are poorly constrained.
Self-hosting gives technical teams more control over model choice, data movement, logging, and access policies. Yet it also transfers responsibility for infrastructure, security, updates, capacity planning, and model operations back towards the organisation or its managed-service provider, replacing one form of dependency with a different operational burden.
Sovereignty becomes an architectural claim
The European market has attached growing importance to sovereign AI as organisations assess data jurisdiction, public-cloud concentration, regulatory exposure, and dependence on a small number of global providers. In practice, sovereignty is rarely binary because an apparently private deployment can still depend on overseas chips, open-source model developers, external software libraries, support services, or remote administration.
Croft’s architecture gives customers the option to keep the core platform within infrastructure they control, which can be useful in regulated or data-sensitive environments. The stronger procurement question is therefore not whether a vendor uses the word sovereign, but which parts of the system can operate independently, which data leaves the environment, and which external services remain necessary.
That makes technical documentation and contractual controls as important as model performance. Organisations need to know how prompts are logged, whether retrieval data is retained, who can administer the platform, how vulnerabilities are patched, and what happens if a particular model or infrastructure supplier changes its terms.
Control becomes harder as agents gain authority
Agentic systems raise the stakes because access decisions become operational decisions. A chatbot that produces a poor answer can inconvenience a user; an agent connected to business applications can send information, change records, initiate workflows, or trigger downstream systems before a person notices the mistake.
Private deployment can make those actions easier to observe and constrain, although it does not replace careful permissions, approval gates, testing, and audit. The more authority an AI system receives, the more its surrounding identity and access controls resemble those used for human employees and conventional software services.
Croft therefore sits in a market moving away from simple model procurement towards questions about the entire AI operating environment. Enterprises deciding between public AI services, private cloud, and on-premises systems will increasingly be comparing control, integration, staffing, and external dependencies alongside model quality and price.












