We're one well-publicised security pop from locally hosted being a non-negotiable for some large set of buyers.
They've convinced every company in the country, including in previously security or compliance-centric environments (finance, medical, government), to hand them hyper-sensitive data.
We've already seen the leakage scenario, with the academics who found the labs scooping them on the research they were using the LLMs to assist. What's to say they-- or someone who infiltrated their infrastructure-- won't do the same thing with your propriatery business details?
I'm not sure open LLMs are a great play for commodity vendors. A lot of "lowest bidder commodity services" work because they can wildly oversell. That VPS hosting a small-biz website or 1000-messages-a-week internal email can run on a Raspberry Pi 1B, so you can pretty easily sublet a $1000 server to 50 customers at $10 per month each. Current LLM hardware plays tend to need more expensive gear and seem to be running at higher utilization rates, so the price that actually fits the underlying business might not look as appealing.