Workloads Companies May Want To Keep Off The Public Cloud

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Workload placement is less a one-time migration decision and more an ongoing architectural question as technology, business requirements and operating conditions change.

gettyThe public cloud has become the default home for many business workloads, offering flexibility, scalability and access to powerful new technologies. But as companies juggle cloud services, private infrastructure and increasingly demanding AI systems, deciding where a workload belongs is becoming less straightforward—and simply moving everything to the cloud can create new trade-offs around cost, control, performance and risk.

Workload placement is less a one-time migration decision and more an ongoing architectural question as technology, business requirements and operating conditions change. Below, members of Forbes Technology Council identify workloads companies may want to reconsider moving—or keeping—in the public cloud and explain why another environment may sometimes make more sense.

Companies should think twice about putting AI workloads involving sensitive consumer or biometric data entirely in the public cloud. These workloads can raise added concerns around privacy, data residency, access controls and governance, making hybrid or private infrastructure a better fit when organizations need tighter oversight. - Anastasia Georgievskaya, Haut.AI

Enterprises have spent a decade deciding where data is allowed to rest; AI agents change the question. Once an agent is acting, what matters is where the interactions flow: what it retrieved, what it was permitted to see, what it decided and on whose authority. That trail is what an auditor asks for, and it’s harder to reconstruct when the loop spans three providers. Keep that loop where you can account for it, and burst everything else. - Louis Landry, Teradata

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Question the legacy application kept running solely to retrieve old records. Before moving it to cloud servers, test whether a searchable archive can meet access and retention needs, including legal holds. A rarely used application can still demand patching and support. Preserving the records need not mean operating the entire system indefinitely. - Mani Padisetti, Almost Magic Tech Lab

Real-time transaction processing is worth keeping close to where it happens rather than moving it wholesale to the public cloud. A network hiccup shouldn’t be able to take a device down mid-transaction. Keep the core logic local and use the cloud for monitoring, software updates and any analysis that can run on its own schedule. - Andy Zosel, Diebold Nixdorf

Workloads governed by consent withdrawal or a legal right to erasure deserve close scrutiny. In the public cloud, one patient or customer record can spread into replicas, logs, embeddings, feature stores, caches and model checkpoints. Deleting the source is not deletion. Leaders should map each derivative, set provable expiry controls and test one end-to-end erasure request before migration. If deletion cannot be evidenced, elasticity has created permanent data debt. - Jagadish Gokavarapu, Wissen Infotech

Chaos tests, load tests and AI experiments are designed to create spikes, crashes, retries and huge logs. In the public cloud, that can turn good testing into unpredictable cost. From a QA perspective, some workloads are valuable precisely because they behave badly. - Margarita Simonova, ILoveMyQA

One workload companies should reconsider keeping in the public cloud is cryptographic key and root-of-trust infrastructure. Encryption keys, certificate authorities and signing systems form the foundation of digital trust. If compromised, the impact can spread across many applications and systems. Leaders should assess whether cloud convenience justifies concentrating these critical trust functions with the same infrastructure provider. - Salice Thomas, Wipro Limited

Real-time network telemetry and anomaly detection is one workload to think twice about keeping in the public cloud. Streaming every sensor signal to the cloud is slow and costly and creates compliance risk when data crosses public networks. That workload belongs at the edge—where processing locally keeps more data on-site, lowering costs—with refined insights sent to the cloud for analytics. - Juho Sarvikas, Inseego

Core identity and authentication workloads deserve scrutiny before moving them fully to the public cloud. These systems sit at the center of every other security decision an organization makes, and depending on a third-party provider for availability means an outage outside your control can cascade across every system that relies on it. The cloud convenience argument is weakest exactly where the blast radius of a failure is largest. - Dan Haiem, AppMakers USA

Think twice about leaving yesterday’s experimental AI workload in tomorrow’s production architecture. A workload that needed public-cloud elasticity during experimentation may eventually run continuously at predictable scale. At that point, leaders should revisit placement using utilization, data gravity, latency and total cost as criteria rather than assuming the original architecture is permanent. - Prajkta Waditwar, Box Inc.

Think twice before putting operational decision-making in the public cloud. That means anything that must keep working when the link doesn’t: plant floors, vehicles, remote sites and data that can’t legally or competitively leave the premises. The cloud is the right home for training and aggregation; decisions increasingly belong at the edge, where latency and sovereignty are physics, not preferences. - Charles Yeomans, Atombeam

One workload worth reconsidering is corporate meeting minutes and board records. They capture strategic decisions, sensitive negotiations and legal exposure. Keeping them in public cloud AI pipelines risks leaks or unauthorized training use, so private infrastructure with strict access controls often makes more sense. - Nino Letteriello, FIT Group

Think twice about keeping critical incident evidence solely in the same public cloud as production. Logs, traces, audit records and recovery evidence may be needed when that cloud account is compromised or unavailable. Keeping an independent copy outside the production blast radius can make investigation and recovery much more reliable. - Sibasis Padhi, Walmart Inc.

Think twice about moving steady-state, high-volume workloads that run 24/7 at predictable scale, like large databases or constant AI inference. Public cloud rewards bursty, variable demand, but for always-on workloads, pay-as-you-go premium and data egress fees compound fast. Once usage is steady and predictable, owned or private infrastructure often costs far less. - Srinivas Chippagiri, Salesforce Inc.

Think twice about workloads that constantly move large datasets between systems or regions. Compute may look cheap while data egress and transfer costs quietly dominate the economics. Sometimes the right architecture is to move compute to the data rather than data to the compute. - Benedetto Biondi, Folks Finance

Keep the systems needed to recover production outside the same failure domain as production itself. If one stolen credential, bad configuration or provider outage can disable both the workload and the tools or backups needed to restore it, a company doesn’t really have an independent recovery path. - Nicholas Domnisch, EE Solutions

Tightly coupled, monolithic legacy applications are a strong candidate to keep off the public cloud. These systems often depend on specific hardware or low-latency local resources that don’t translate well to cloud environments. Migrating them can require costly re-architecture with limited performance. If modernization isn’t feasible soon, running such workloads on-premises may be more stable and economical than forcing a cloud lift-and-shift. - Harsh Jangid, Coozmoo Digital Solutions

Think twice about running core contract and revenue operations data pipelines exclusively in the public cloud. High-volume CPQ workflows, proprietary transaction logs and real-time LLM inference on enterprise contract metadata incur significant data egress and token-routing costs. Keeping sensitive revenue data in a hybrid environment protects margins while securing your core business logic. - Eshaan Jain, Mphasis Silverline

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/24/workloads-companies-may-want-to-keep-off-the-public-cloud/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business