Introduction

header_image

Machine-learning models and inference pipelines are increasingly embedded in everyday software: search, translation, photo libraries, voice assistants, and workplace tools. Product pages often label the whole category as so-called "Artificial Intelligence" ("AI"); this dossier uses that label sparingly and prefers concrete terms where possible. Most of this capability is delivered through centralized cloud services operated by a handful of corporations. Users gain convenience, but often surrender prompts, documents, images, and behavioural signals to infrastructure they neither own nor can inspect.

This dossier presents a different path: Self-sovereign AI — models and pipelines that can run on your own hardware, keep inference local, share compute through community infrastructure, and build on open, inspectable data foundations. NGI / NLnet funded parts of this stack; the pages below stay on what each project does. None of these projects alone replaces every proprietary assistant or API, but together they show that useful machine-learning work need not require permanent dependence on opaque remote systems.

Critical note: "Local" and "open" are not automatic guarantees of privacy or safety. Running a model on your own device still requires trusting the software stack, the model weights, and whoever maintains updates. Community infrastructure such as AI Horde shares compute rather than keeping everything on-device. Read each project's scope carefully before assuming your data stays private.

Risks of centralized cloud models

Understanding what centralized, vendor-hosted model stacks cost helps clarify why alternatives matter. The dominant pattern — API access to remote models trained on opaque corpora — creates interconnected risks:

Surveillance and data extraction. Cloud assistants such as ChatGPT, Gemini, Claude, Microsoft Copilot, Perplexity, and Grok, and other marketed "AI" features bundled into products, process prompts, uploads, and usage patterns on vendor infrastructure. Terms of service can change; data may be retained for training, compliance, or product improvement without meaningful user control.

Vendor lock-in and dependency. Models, fine-tunes, and integrations tied to one provider become expensive to migrate. Creators and organisations that build workflows around a proprietary API risk sudden price changes, deprecations, or regional unavailability.

Opacity and unaccountability. Closed weights, training data, and safety filters make it difficult to audit bias, hallucination rates, or environmental impact. When something goes wrong, users rarely have insight into why. Bajohr and Krajewski (2024) treat that opacity as a reading problem, not only a market one: source code is a text that has to be interpreted, and today’s language models often no longer offer a readable interior at all (see Sources). Zweig (2023) adds the accountability problem: blaming “the AI” is how institutions dodge the humans who designed, trained, and deployed the system. Bortzmeyer (2018) is even blunter about encoding rights: human rights can conflict with one another, so they cannot be turned into algorithms (see Sources). Wildenhain (2024) adds the older philosophical limit: strong AI is still missing, and a language model does not live in the world — talking of “the AI” as if it were one mind is, in his phrase, nonsense (see Sources). Carstensen et al. (2010, pp. 1–25) already treated language technology as engineering next to linguistics and AI: statistical models that must generalise rather than memorise, and machine translation as a technological compromise with no final solution (see Sources).

Energy and infrastructure concentration. Large-scale inference and training concentrate compute in a few datacentre regions, often far from the communities that consume the services. Engagement-driven recommendation and assistant features further increase demand for always-on processing.

Sovereignty and supply-chain risk. Relying on foreign hyperscalers for core cognitive infrastructure creates strategic dependency — especially for public sector, research, and civil-society use cases that handle sensitive material. The CCC (2026) rejects Palantir-style analytics and biometric dragnets as incompatible with fundamental rights — the same pattern when AI scoring meets state databases (see Sources). The EFF’s 2025 review of AI and copyright tracks the fight over training data and user rights when models ingest what people publish (see Sources). The FSFE asks whether LLM-generated “vibe code” can even be licensed into Free Software when authorship and copyrightability are unclear (see Sources).

Waiting for better regulation alone is insufficient. Practical, inspectable building blocks that communities and organisations can run themselves are needed alongside policy work.

How these projects address these risks

The projects below keep models close to the user — on-device, on local hardware such as FPGAs, or on infrastructure you choose to trust. They address surveillance, latency, and sovereignty risks from cloud-first model stacks, though each makes different trade-offs between convenience, hardware requirements, and complete data isolation.

SensifAI SensifAI applies on-device machine learning to tag and organise images without sending photos to a cloud vision API. That matters for personal archives, accessibility workflows, and any setting where visual data must stay on the user's hardware — libraries, clinics, newsrooms, or offline field kits.
LLM2FPGA LLM2FPGA explores running open LLMs on FPGAs rather than renting remote GPU clusters. The goal is predictable, locally controlled inference for labs, edge sites, and organisations that cannot or should not route prompts through commercial datacentres.
Open NPU drivers Open NPU drivers develops libre Linux drivers for Neural Processing Units, including Mesa Teflon support for Rockchip NPUs. The goal is inspectable, locally controlled inference on edge hardware — phones, boards, and laptops — without depending on proprietary firmware to schedule opaque workloads on accelerators you already own.
VersatAI VersatAI automates support for ML/AI algorithms on computational accelerators (iob-versat). Hardware that can run open models is of little use if every new operator still needs a closed vendor toolchain — VersatAI targets that compiler/accelerator gap.
OpenVoiceOS OpenVoiceOS is a self-hostable voice assistant stack built around open speech and language models. It offers an alternative to always-listening cloud assistants: operators can run, audit, and harden the full pipeline, and keep wake-word, transcription, and reasoning off third-party infrastructure when required.
Offline Translator Offline Translator performs on-device translation with open models, so text never has to leave the phone or laptop. Useful for travel, humanitarian field work, journalist source protection, and any workflow where intermittent connectivity or third-party translation APIs are ruled out.
RTranslator RTranslator is an Android app for on-device text and spoken-word translation, including a hands-free conversation mode between two phones. Version 3.0 replaces Google ML Kit with Mozilla Bergamot and MADLAD models so the stack is fully open, plus a self-hosted web front for text. Complements Offline Translator with live speech rather than only typed text.
AI Horde AI Horde provides collaborative, community-run generative model infrastructure: volunteers contribute GPU workers and users share capacity instead of relying on one corporate API. It decentralizes *who* operates inference, though prompts and outputs still cross the network — closer to mutual aid than to fully offline use.
AI-VPN AI-VPN applies machine learning locally to VPN traffic analysis for security monitoring. Network operators can detect anomalies and classify flows on their own machines instead of piping sensitive traffic metadata to a SaaS analytics vendor.
Video chat privacy Video chat privacy uses on-device models to edit video feeds in real time — removing or anonymising backgrounds during calls so webcams do not broadcast bookshelves, family members, or street views that recipients never needed to see.
Provability Fabric Provability Fabric adds verifiable evidence and run-time security around model stacks — including privacy-preserving logging for LLM workflows — so operators can audit what ran, what data was touched, and whether policy constraints held without trusting vendor dashboards alone.
Spacylize Spacylize distils knowledge from large language models into smaller, more efficient NLP models that teams can run with less compute. That lowers the hardware bar for local text classification, tagging, and extraction without routing every document through a remote API.

Critical note: Local inference often demands capable hardware, technical setup, and ongoing maintenance. Projects still vary in maturity — some are prototypes or research-oriented. Federation and shared compute (AI Horde) reduce per-user hardware needs but introduce trust in peer operators.

Open data and evaluation in this dossier

Machine learning depends on data as much as on models. Proprietary datasets, undocumented scraping, and siloed corporate stores make it hard to build reproducible, auditable machine-learning systems aligned with community needs. The projects below strengthen open data foundations: structured descriptions, self-hostable storage, and linked-data tooling that teams can use for training, evaluation, and knowledge-intensive applications without surrendering custody.

Data packages Data packages standardises how external datasets are described, validated, and packaged through the Frictionless Data ecosystem. Clear metadata and tooling make it easier to publish, discover, version, and reuse training and evaluation data across teams without each project inventing its own ad-hoc format.
Atomic Tables Atomic Tables offers a self-hostable tabular data layer for structured records with typed schemas and sync-friendly storage. Teams can keep feature stores, labelled tables, and operational datasets on infrastructure they control rather than defaulting to proprietary spreadsheets or opaque cloud warehouses.
Atomic Data Atomic Data provides typesafe handling of linked data and knowledge graphs with explicit schemas and permissions. Semantic, interlinked datasets can feed retrieval-augmented and graph-based ML pipelines while keeping provenance inspectable and hosting under community control.
SensifAI SensifAI also bridges vision and data organisation: on-device tagging turns private image collections into structured, searchable material. That creates labelled visual datasets for downstream workflows without exporting raw photos to a cloud indexer or training pipeline you do not control.
pgmpy pgmpy provides open-source infrastructure for causal machine learning: modelling cause-and-effect relationships with inspectable graphs and tooling rather than opaque correlation-only scores from proprietary analytics platforms.
PyCM PyCM evaluates machine-learning classifiers through inspectable confusion-matrix metrics instead of a vendor dashboard score. Teams can compare models locally, report in several formats, and audit performance without sending labelled results to a commercial MLOps platform.
PRESC PRESC (Predictor as Replica of a Scorer) builds copies of black-box classifiers so you can evaluate and remediate models you cannot open — ranking and recommendation systems included. That is the audit path when a vendor will not ship weights.
Vouivre Vouivre is a dependent type system for writing machine-learning programs in Lisp. Weak types in mainstream frameworks let shape and correctness bugs through to expensive runtime failures. Compile-time checks let pipelines fail in the compiler instead of on a rented GPU.

This is a first curated set of open-data foundations and on-device inference work in this dossier; the NLnet project list lists further related entries as the ecosystem grows.

Critical note: Open data tooling does not by itself prevent misuse of models or biased training corpora. It raises the floor for transparency and self-hosting, but governance, consent, and documentation of datasets remain human responsibilities.

Popular FLOSS local LLM tools

Alongside the projects above, three widely used FLOSS tools are a practical way to run LLMs on your own machine. Ollama, Jan, and OpenClaw are included because people actually run them as a local stack — not as NLnet-funded entries.

Ollama Ollama runs open LLMs on your hardware. Install it, ollama pull a model, chat in the terminal, or call the local API at localhost:11434.
Jan Jan is a local-first desktop chat app for local models. Point it at Ollama when you want a normal UI instead of the command line.
OpenClaw OpenClaw is a personal agent. Point it at your local Ollama server to run tasks, tools, and channel hooks — not just single chat sessions.

How they fit together. Ollama runs the model. Jan is the chat UI. OpenClaw handles automation on the same backend.

  1. Install Ollama, then ollama pull llama3.2
  2. Chat with ollama run llama3.2, or open Jan and select Ollama as the backend
  3. For agent work, set OpenClaw baseUrl to 127.0.0.1:11434

Example: a journalist keeps interview notes in a local folder, runs ollama pull mistral, drafts in Jan, and lets OpenClaw summarise transcripts overnight — nothing goes to ChatGPT or Gemini.

Models. Common picks include Llama 3.x, Mistral, Qwen 2.5, Phi, and Gemma. Small builds such as llama3.2:1b or phi3:mini suit weaker hardware. Community variants — Dolphin, Hermes uncensored, or abliterated builds — refuse less often because RLHF guardrails were removed. Useful when cloud bots block harmless prompts; also easier to misuse, and you decide what runs.

Cloud bias. ChatGPT, Gemini, and similar services apply filters and policies. Expect uneven refusals and answers shaped by business goals — not a neutral view. Local models drop vendor censorship; you keep the hardware cost, updates, hallucinations, and the choice of weights.

Note: Uncensored local models can output harmful or wrong text without warning. Cloud filters are flawed too. Check what you run, limit network access where it helps, and do not trust either side blindly.

Similar FLOSS Projects

Where to start

No single project in this dossier replaces proprietary cloud assistants such as ChatGPT, Gemini, Claude, Microsoft Copilot, Perplexity, and Grok. Choose based on which risk matters most to you.

Browse the projects in this dossier below.

Self-sovereign AI is a direction, not a product you can buy off the shelf. Local inference plus open data cuts several centralized risks, but takes more work than clicking through a terms-of-service popup. Start small: one local assistant, one offline tool, one dataset you document yourself.

Open weights and a local runtime still leave a text to be read. Bajohr and Krajewski (2024) call that work Quellcodekritik — source-code criticism as a philology of algorithms. Their introduction (“ReadMe1st.txt”) and Bajohr’s essay “Dumme Bedeutung” matter here because this dossier’s projects expose code, weights, or metrics that cloud APIs hide. After Kittler, they write, algorithms determine our situation: some run as trade secrets, others aim at open-source accountability (see Sources, p. 9). German originals below; English is ours.

Dabei ist es heute dringender denn je, auch außerhalb dieser Gruppen zeitgemäße Medienkompetenz in Form zuverlässiger coding literacy zu fördern.

It is more urgent than ever to foster contemporary media literacy as reliable coding literacy beyond specialist groups. (Bajohr and Krajewski 2024, p. 10)

That literacy is the gap local stacks in this dossier try to close in practice: inspectable tools instead of a compiled blob or a remote API. The editors also mark the limit of classical code-reading once models become connectionist rather than sequential:

Das klassische sequenzielle Paradigma […] wird heute durch das konnektionistische Paradigma – stochastische maschinelle Lernmodelle – zumindest erweitert, wenn nicht infrage gestellt. […] [Solche Modelle] sind aber nicht mehr in derselben Weise lesbar wie [klassischer Code].

The classical sequential paradigm is now at least extended, if not challenged, by the connectionist paradigm — stochastic machine-learning models. Such models are no longer readable in the same way as classical code. (ibid., p. 16)

Bajohr’s own chapter names what those models still produce without understanding:

Bedeutung ohne Geist – dumme Bedeutung.

Meaning without mind — dumb meaning. (Bajohr 2024, p. 199)

KI-Systeme sind dumm. Sie haben kein Bewusstsein. Dennoch produzieren sie eine komplexe artifizielle Semantik […]

AI systems are dumb. They have no consciousness. They still produce a complex artificial semantics […] (ibid., p. 213)

[…] wir lernen, die Dummheit des Systems in unsere Interaktion mit ihm einzupreisen […]

[…] we learn to price the system’s dumbness into our interaction with it […] (ibid., p. 215)

Local inference does not magically turn that dumb meaning into grounded knowledge. It does let you choose the weights, keep prompts off a vendor log, and treat the stack as something a community can comment, fork, or refuse — the philological gesture the volume asks for.

Katharina Zweig’s Die KI war’s! (2023) is the counterpart on decisions about people. The title names a dodge: when a hiring score, a credit line, or a welfare flag is wrong, vendors and agencies say the algorithm did it. Zweig asks under what conditions one can contest computer decisions, and what answers to expect (see Sources, p. 11). If neither operators nor the people affected get a satisfying explanation, contest the use of the system, not a single output — and ask who deployed it, because that is who customers will turn to, whether or not they own the decision logic (ibid., pp. 12, 21). Behind every algorithm sits first a model in the developers’ heads, then a statistical model the machine computes (ibid., p. 27). German originals below; English is ours.

Das Vorhandensein von Werturteilen in einem Entscheidungsprozess [weist] ganz grundsätzlich darauf hin, dass Maschinen diesen Prozess nicht übernehmen können.

The presence of value judgements in a decision process is a fundamental sign that machines cannot take that process over. (Zweig 2023, p. 217)

Widerspruch lohnt sich.

Contesting it is worth it. (chapter title, p. 269; closing plea for a broad debate on when automated decision systems may be used, p. 273)

Zweig’s point for this dossier: local and open tools help you inspect a stack, but they do not license handing value judgements to a model — and they do not let a deployer hide behind “the algorithm”.

Bortzmeyer, writing as a network engineer, reaches a matching limit from the other direction — rights, not models: human rights can conflict with one another, so they cannot be turned into algorithms (see Sources).

Michael Wildenhain’s Eine kurze Geschichte der Künstlichen Intelligenz (2024) is a short cultural and philosophical history, not a vendor brochure. The dream of serviceable artificial beings already carries the fear that they turn against us; the real question is how far systems measured by a human standard count as intelligent, and whether talk of machine consciousness makes sense (see Sources). The homunculus in the glass can perceive the world but is not in it (Wildenhain 2024, p. 16; see Sources). German originals below; English is ours.

Die Entwicklung einer starken KI steht hingegen nach wie vor aus.

The development of strong AI, by contrast, is still outstanding. (ibid., p. 25)

Das Gehirn ist hingegen kein logisch-kausales System.

The brain, by contrast, is not a logico-causal system. (ibid., p. 55)

Von der KI zu sprechen ist, alles in allem, unsinnig. […] Sie lebt, anders als der Mensch, nicht in der Welt.

To speak of “the AI” is, all in all, nonsense. […] Unlike the human being, it does not live in the world. (ibid., pp. 77–78)

Wildenhain’s point for this dossier: local inference still runs a model that is not in the world. Open weights let you inspect and refuse it; they do not turn next-token prediction into a mind.

Carstensen, Ebert, Ebert, Jekat, Klabunde and Langer (eds.), Computerlinguistik und Sprachtechnologie (3rd edn, 2010), is the standard German handbook that already put today’s language-model stack in older terms: natural-language processing, not a mind — practice-oriented language technology next to linguistics and AI. Chapter 1 already treats statistics and corpora as central, models that must generalise rather than memorise, and machine translation as a noisy-channel reconstruction — a technological compromise with no final solution (see Sources). We cite that chapter generically (pp. 1–25; authorised excerpt). German originals below; English is ours. All passages: Carstensen et al. 2010, pp. 1–25.

Computerlinguistik als praxisorientierte, ingenieursmäßig konzipierte Entwicklung von Sprachsoftware („Sprachtechnologie“).

Computational linguistics as the practice-oriented, engineering development of language software (“language technology”). (ibid.)

That framing already treats language tech as a compromise between claim and reality — no final solution expected (see Sources). Carstensen et al.’s point for this dossier: today’s assistants are still language technology — noisy-channel engineering plus generalisation, not a mind. Local open models let you inspect the engineering; they do not cancel the compromise.

Associated NGI0 Projects

Similar Closed-Source Projects

Sources

  • Bajohr, H. and Krajewski, M. (eds.) (2024) Quellcodekritik. Zur Philologie von Algorithmen. Berlin: August Verlag (imprint of Matthes & Seitz). Open access: PDF (publisher; doi:10.52438/avaa1004).
  • Zweig, K. (2023) Die KI war’s! Von absurd bis tödlich: Die Tücken der künstlichen Intelligenz. Munich: Heyne. ISBN 978-3-453-21856-7. The publisher PDF is not free, so we do not host it; publisher excerpt: Leseprobe (PDF).
  • Bortzmeyer, S. (2018) Cyberstructure. L’Internet, un espace politique. Caen: C&F éditions (collection Société numérique). ISBN 978-2-915825-87-9 (print); 978-2-915825-88-6 (epub). The full book is not free, so we do not host it; publisher specimen: PDF; companion site cyberstructure.fr.
  • Wildenhain, M. (2024) Eine kurze Geschichte der Künstlichen Intelligenz. Stuttgart: Cotta / Klett-Cotta. ISBN 978-3-7681-9824-0 (print); 978-3-7681-9826-4 (epub). The publisher PDF is not free, so we do not host it; publisher excerpt: Leseprobe (PDF).
  • Carstensen, K.-U., Ebert, C., Ebert, C., Jekat, S., Klabunde, R. and Langer, H. (eds.) (2010) Computerlinguistik und Sprachtechnologie: Eine Einführung. 3rd, revised and expanded edn. Heidelberg: Spektrum Akademischer Verlag. ISBN 978-3-8274-2023-7 (print); 978-3-8274-2224-8 (e-book). doi:10.1007/978-3-8274-2224-8. In-text we cite ch. 1 generically, pp. 1–25. The full book is not free, so we do not host it; chapter 1 (open excerpt, publisher permission): PDF (companion site).
  • Chaos Computer Club (2026) ‘CCC lehnt Palantir-Gesetze und biometrische Rasterfahnung ab’. Available at: ccc.de (Accessed: 13 September 2026).
  • Electronic Frontier Foundation (2025) ‘Artificial Intelligence, Copyright, and the Fight for User Rights: 2025 in Review’. Available at: eff.org (Accessed: 13 September 2026).
  • Free Software Foundation Europe (2026) ‘Copyrightability of LLM-generated code: Can we license “vibe code” into Free Software?’. Available at: fsfe.org (Accessed: 13 September 2026).