The objection isn't a reason to skip AI. It's a constraint on which kind to buy. There are two questions to put to any AI-for-ERP vendor, and they're different questions: where does the data live, and what happens if you leave.
Where does your data go when you add AI to your ERP?
With most cloud AI tools, it leaves the building, and that should end the conversation. The standard architecture sends your queries and your data to the vendor's cloud, where it's processed by models you don't control under terms you'll never fully audit.
Annora's answer is architectural, and there are exactly three claims behind it. It's self-hosted: the system runs on your own servers or private cloud, so the data stays in your building. It never trains on your data; your data never reaches OpenAI, Anthropic, or any outside AI company. And your IP can't leak to competitors, because it's private AI, deployed for you alone.
That architecture isn't a premium tier. It's the design decision everything else rests on, and it's also what makes adoption possible, because boards and IT teams that would veto a cloud tool can say yes when the data never moves and the credentials stay theirs.
What happens if the vendor walks away, or you do?
That's the second question, and it gets asked less because companies have been trained not to ask it. One CTO put the fear plainly: his parent company's experience was hiring consultants you then pay forever, because every future change runs through them. Most software ownership works the same way: cancel the subscription and the capability vanishes, because it never lived in your environment to begin with.
A self-hosted deployment inverts that. The system runs in your environment, on your infrastructure, under your credentials. If the relationship ends, the deployment doesn't evaporate; what was built for you is running on machines you control. You're not renting access to your own operating knowledge.
Why does ownership matter as much as privacy?
Because dependency is a cost that compounds quietly. Privacy is about what can leak out; ownership is about what you can be charged to keep. A manufacturer that's put its quoting logic, knowledge base, and daily workflow into a tool it doesn't control has handed its vendor pricing power over its own operations; every renewal is negotiated against the cost of losing the capability.
Running in your environment, under your credentials, caps that exposure. The vendor keeps earning the relationship through value delivered, not through the pain of leaving. It keeps both sides honest.
What should you ask any AI vendor before connecting your ERP?
Five questions, in order. Where, physically, does our data get processed? Does any of it reach an outside AI company, for any purpose? Is it ever used to train models (yours or anyone's)? What runs in our environment versus yours? And if we part ways in two years, what do we still have?
A vendor with good answers will give them quickly and in writing. Vague answers to the first three are a no. A "nothing" on the last one is a dependency you're choosing with your eyes open, or, better, not choosing.
