Where the intelligence sits


· 13 min read
There is an infrastructure decision facing telcos in the next capex cycle that almost never gets called by its name. It sits beneath the routine business of care, customer experience, and service assurance, and it amounts to a question of where intelligence is allowed to live in the network. Operators that recognise the question and answer it correctly will own a position in the digital economy that nobody else can credibly assemble. Operators that miss it will be outflanked on cost, trust, and access to whatever comes next in the value-added services stack.
The modern carrier gateway stopped being a router some time ago. What sits on the wall today is a multi-core ARM computer with several gigabytes of memory, with packet-processing offload preserving routing throughput and, on newer platforms, dedicated AI acceleration available alongside the application CPU, planted inside a household with stable power, a regulated commercial relationship with the operator and continuous network presence. The model classes this hardware can host are the ones household intelligence depends on. Small classifiers for traffic, device and application identification. Embedding models for similarity and clustering. Distilled task-specific models for QoE scoring, anomaly detection and intent recognition. And, increasingly, compact language models in the one to three billion parameters range that recent Phi, Gemma and Llama families have made genuinely capable for local diagnostics, natural-language interfaces and structured summarisation. Models in these classes fit in modest memory budgets, run usefully on spare application CPU capacity and, where present, dedicated AI acceleration, while packet-processing offload preserves the gateway's core routing function. Within the next refresh cycle, the capability set will be standard across the premium estate.
That changes the data-sovereignty calculation significantly. The data classes that can be processed or protected at the household edge are bounded by what the gateway can see. Most application content is encrypted within TLS sessions and is not legible to a broadband gateway. What the gateway can see, and what useful household intelligence can be built on, includes network and device telemetry, DNS or destination metadata where available, application-category behaviour, gaming and streaming QoE signals, Wi-Fi performance, device health, security events and, where the customer has authorised specific integrations, smart-home, energy, voice, health or appliance data through those authorised endpoints. These behavioural and metadata signals, plus what authorised integrations bring in, sit adjacent to the data classes the dominant platforms have built their business models around: household behaviour, device usage, service engagement, attention, identity and intent. The operator has historically provided the pipe and captured none of the upside. Gateway-resident processing changes that balance. The household keeps its data inside the perimeter the customer consented to, the operator holds the consent fabric, and the platform partners come in through a permissioned interface on terms the operator governs. What was free becomes priced. What was extracted becomes licensed.
What leaves the gateway is the derivative output the customer has authorised, scoped to the purpose for which the partner has been granted access, and data-minimised, purpose-limited, and pseudonymised or aggregated where appropriate, so that only what the partner needs and is permitted to see leaves the gateway. Pseudonymised data can still be personal data under UK GDPR where re-identification is reasonably possible and is governed accordingly.
The privacy posture this enables looks fundamentally different from the prevailing hyperscaler model, which depends on the continuous extraction of identifiable data to a centralised cloud and rebuilds trust afterwards through pseudonymisation, retention policies, access controls, and disclosure controls. The on-gateway model establishes trust at the architecture layer. The customer can, in principle and increasingly in practice, see what is being processed locally, shared, retained, and deleted.
Legal and regulatory direction of travel is moving towards this configuration faster than most operators have noticed. The UK Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, establishes a framework to support Smart Data schemes across sectors, including energy, transport and telecoms, subject to scheme design and secondary legislation. The EU AI Act is being phased in: prohibited practices and AI literacy obligations applied from February 2025, general-purpose AI obligations from August 2025, general applicability from August 2026, high-risk systems in specified areas (such as biometrics, critical infrastructure, education, employment, migration and border control) from December 2027, and high-risk AI embedded in regulated products from August 2028 following the AI omnibus political agreement. Adequacy decisions between the UK and EU remain sensitive to the perceived rigour of data protection enforcement at home. US state-level privacy legislation is converging on similar consent-and-purpose architectures.
Operators that build the on-gateway architecture end up positioned to satisfy these frameworks by design, with audit trails that map cleanly onto what regulators are increasingly asking to see. Operators that do not are accumulating compliance risk on a data architecture that is moving out of regulatory favour year by year.
The telco position in this configuration is structurally unique. Operators are already the entity in the value chain with the physical connectivity, the billing relationship, the consumer trust, the regulatory permissions, and the installed-device footprint. Adding sovereign on-device processing to that stack produces a configuration that no other actor in the digital economy can credibly assemble. Hyperscalers have compute and, in some cases, consumer devices, but they generally do not hold the regulated broadband access network, the managed CPE estate, the connectivity billing relationship, and the operator consent fabric in one place. Device manufacturers have hardware presence and customer accounts, but not the regulated access-network position or managed broadband relationship. Content and service providers have the demand but not the underlying infrastructure. AI-native platforms have the model capability but no presence in the home and no established consent architecture. Only the telco sits at the intersection of all of these.

Figure 1: Five pieces are required simultaneously to host useful household intelligence. Only telcos combine all five inside the regulated broadband stack at network scale.
The commercial expression of this is an ecosystem of knowledge rather than a pipe. Telcos that build the gateway as a local inference and consent platform become the broker of derivative insight to partners across health, energy, insurance, mobility and content, on terms that those partners cannot replicate by going around them. A federated query architecture lets specialist vertical operators ask questions of the installed base without seeing the underlying data, with the telco governing what is asked, what is answered, what compensates the household for the contribution and what is logged for regulatory audit. A new revenue layer emerges above connectivity: governed insight per query, with the underlying access network becoming the moat rather than the only product being sold.
The investment is justified before the platform value is even considered. Customer-recognised issues are where operating costs concentrate, and the prevailing cloud-centric telemetry architecture spends heavily to detect them slowly. Streaming raw data from millions of gateways into a centralised analytics platform consumes backhaul, ingest, storage and compute on a scale that has become disproportionate to the value extracted. By the time the cloud-side analytics flag a degradation, the customer is normally already on hold with care.
Pushing the inference into the gateway collapses telemetry volumes by orders of magnitude. Cloud cost falls. Resolution speed improves from minutes or hours to seconds. The gateway closes the loop locally, renegotiating Wi-Fi channels, restarting a misbehaving radio, throttling a runaway device or prompting the customer through an app before the call to care is ever made. The incremental energy and compute costs on the gateway itself are negligible, ranging from low single-digit pence to low pounds per household per year, depending on workload, against a unit that is already provisioned, powered, and running. The customer captures the experience benefit. The operator avoids the backhaul, storage, and cloud compute that it would otherwise have to provision. The economics scale linearly with the installed base.

Figure 2: Bars show cumulative incident cost as the issue escalates. Local resolution avoids the care event entirely. Inbound call cost: ContactBabel UK Contact Centre Decision-Makers' Guide. Engineer visit: UK blended field service on a per-visit basis.
The capability built for care-cost reduction is reusable across a whole portfolio of value-added services. The same inference fabric that detects Wi-Fi degradation can also detect a streaming session falling below the QoE threshold of a premium entertainment tier, monitor the health of a connected security camera estate, detect anomalous behaviour in a smart energy device fleet, and verify that a telehealth consultation meets clinical-grade reliability standards. The classifier changes. The architecture does not.
The approach's capital efficiency is substantial. A single investment in on-gateway inference, justified solely by care-cost returns, becomes the substrate for entertainment QoE, home security, energy management, and telehealth assurance, with marginal cost dominated by model development rather than infrastructure. Each new service amortises across the same gateway fleet, telemetry pipeline, model deployment pipeline, and operational governance. By the time a fifth service is layered onto the same fabric, the unit economics approach pure software margins.
The architecture is not theoretical. Production-grade gateway-resident inference capability now spans real-time network performance management, application-layer QoE for video conferencing and streaming, digital threat detection and content filtering, home security and safety monitoring, and household energy disaggregation. The breadth of the capability set is the point. Each new service draws on the same telemetry pipeline, the same consent framework, the same compute footprint and the same governance model. Operators integrating this capability into their gateway estate are demonstrating in production what the structural argument predicts in theory.
Recent engineering work by Silpion and Presciense has benchmarked this configuration on a representative MediaTek MT7988-class platform, as found in current premium carrier CPE. A quantised Qwen 2.5 0.5B runtime, configured for short household diagnostic interactions, sits alongside a compact Seq2Seq non-intrusive load monitoring model for household energy disaggregation, with combined memory consumption below 600 megabytes. Sustained throughput in the region of ten tokens per second is sufficient for the household-facing workload, which is event-driven rather than conversational. The MediaTek Network Processing Unit on the chipset preserves packet-processing performance and handles QoS and tunnelling offload, which is its actual function. The application CPU runs the inference and manages orchestration, with a true neural accelerator available for additional offload on platforms that include one. In the tested configuration, routing performance was preserved under event-driven inference load. The resource envelope for useful household intelligence has become small enough to sit on current premium gateway platforms and the next refresh cycle of managed CPE, with the specific figures workload- and configuration-dependent.

Figure 3: Two qualitatively different workloads, both gateway-resident. Indicative figures, representative MT7988-class configuration.
The customer authorised the operator's relationship. They signed a contract. The relationship is regulated. When the operator installs a vendor agent on the gateway that streams household data to the vendor's cloud, the lawful basis for that processing does not automatically extend. A vendor-controlled data path, especially one used for the vendor's own commercial purposes, needs a fresh controller/processor or controller/controller analysis. If the vendor is acting as a processor, Article 28 UK GDPR terms are required. If it is acting as an independent or joint controller, the operator needs an appropriate data-sharing basis, transparency, purpose limitation, security guarantees and an audit trail. What looked like a single regulated relationship becomes a chain of relationships, with the vendor inserted between the operator and the customer who originally consented to the operator. That is disintermediation, dressed up as consolidation.

Figure 4: Two questions decide the answer. Where the inference runs, and who controls it. The customer relationship and lawful basis do not extend to vendor-controlled paths.
There is a version of this argument now being made by a handful of well-funded vendors that gets the diagnosis right and the prescription wrong. ISPs are indeed running a dozen or more point tools in the home experience stack. Consolidation is indeed the answer. But consolidating onto a single vendor's cloud, with the data extracted to the vendor's platform and the intelligence running on the vendor's infrastructure, replaces a multi-vendor integration problem with a single-vendor concentration problem that is far harder to unwind. The alternative is to build the ecosystem under operator control. Keep the data inside the consented perimeter. Run the inference on the gateway estate the operator already owns. Open the consent fabric to specialist partners on terms set by the operator, not by the vendor. What was being extracted for free becomes licensed at scale. The right consolidation move is architectural rather than commercial. Consolidate the data fabric, the consent architecture and the inference layer onto the operator's own gateway estate. Keep vendor relationships at the model and application layer, where they can be swapped, multi-sourced and competed. Whoever holds the data architecture eventually holds the customer, and an operator that has spent two decades watching that play out at the OTT layer should not repeat the mistake at the home experience layer.
A further capability the architecture enables deserves separate mention. The gateway is best positioned to assess its own health. Local telemetry on memory pressure, CPU thermals, power supply stability, Wi-Fi radio performance, port error rates and reboot frequency is exactly what a failure-prediction model needs, and exactly the data that gets lost or arrives too late through cloud-side ingestion. On-gateway inference can flag a unit as a maintenance candidate, schedule a proactive intervention trigger within the customer's window of convenience, and trigger a replacement before the failure produces an inbound call, a churn moment, or an emergency truck roll. The same approach extends to the wider home device estate the gateway sees, from smart meters to set-top boxes to connected security and energy hardware. In well-designed pilots, gateway-resident predictive maintenance should be capable of meaningful field-operations cost reductions on a similar order of magnitude to the care-cost gains, with the two effects compounding when both are deployed together. The specific figures depend on baseline reactive-dispatch volumes, current repeat-visit rates and fleet composition.
The architecture has real execution constraints that shape the deployment plan. Inference cannot run continuously on hardware that already routes line-rate Wi-Fi 7 traffic. Event-driven duty cycling keeps the gateway within its thermal envelope and protects the warranty from exposure that would otherwise undermine the entire system. The installed base is mixed, and legacy CPE units cannot host the new architecture, so the transition must be phased rather than instantaneous. Cloud telemetry continues to serve brownfield devices on a sunsetting basis, with the inference fabric deployed on premium and mid-tier replacements as the refresh cycle catches up. The organisational problem is harder than the technical one. Network and procurement own the CPE budget, care owns the call-centre cost, and the architecture only delivers if the savings on the care line are explicitly authorised to subsidise the more expensive gateway hardware. A unified Total Cost of Ownership model, mandated by the executive committee, is the prerequisite for execution. Operators that cannot make that organisational change cannot deploy this strategy, regardless of how sound the technical architecture is. Security widens with the data classes the gateway holds, and cryptographic isolation between the routing functions, the inference containers and the third-party applications running on the gateway is the necessary engineering response.
The cleanest way to think about the next telco capex cycle is as a competition for where intelligence is allowed to live. The cloud-centric model will keep paying for backhaul, storage, compute and the latency-induced churn that comes with detecting problems after the customer has already noticed them. The gateway-centric model pays for none of those at any meaningful scale, sees care-operation costs fall as a direct consequence, builds a service assurance fabric that is reusable across several revenue lines, and holds a sovereign data position that the wider digital economy can neither replicate nor route around.
Cost makes the decision urgent on its own. Platform value makes it strategic. The combined sovereignty and ecosystem position is what elevates it to a generational question.
The next telco capex cycle is not just a gateway refresh. It is a decision about where household intelligence lives, who controls the consent fabric, and who captures the value of the data generated inside the home. Operators that treat the gateway as a cheap router will become tenants in someone else's platform. Operators that treat it as a sovereign inference layer can rebuild the economics of care, assurance and household services around an asset they already own.
illuminem Voices is a democratic space presenting the thoughts and opinions of leading Sustainability & Energy writers, their opinions do not necessarily represent those of illuminem.
Interested in the companies shaping our sustainable future? See on illuminem’s Data Hub™ the transparent sustainability performance, emissions, and climate targets of thousands of businesses worldwide.
Georg Kell

Corporate Sustainability · Corporate Governance
Yury Erofeev

AI · Green Tech
Andrea Bonime-Blanc

Corporate Sustainability · AI
The Wall Street Journal

AI · Green Tech
Eco Business

Electric Vehicles · Consumers Green Tech
The Wall Street Journal

AI · Consumers Green Tech