SAP AI Core consultant: plans, resource groups, deployments and cost
As of 2026-10-09
A SAP AI Core consultant sets up and runs the BTP runtime that executes AI workloads: the service plan, the tenant and its resource groups, the templates, configurations, executions and deployments, the credentials, and the capacity-unit reporting that shows what each use case costs. The generative AI hub sits on top of the same tenant and has its own guide; this page covers the runtime underneath it. In the corpus generated on 8 October 2026, 29 of 1,698 live postings carry an SAP AI Core skill tag: 24 permanent, 3 freelance and 2 contract, 18 of them in Germany.
Where the AI Core role stops and the hub role starts
AI Core runs Kubernetes underneath, with Argo Workflows for training and batch runs and KServe for model serving; templates are synced from a Git repository, images are pulled from the customer's Docker registry and artefacts are read from and written to the customer's object store. The generative AI hub is not a separate product: SAP describes it as a capability that extends AI Core and AI Launchpad, available only on the extended plan.
The practical split for a client is therefore one of layers. The AI Core consultant owns the tenant, its isolation, its credentials and its bill. The hub consultant owns orchestration, grounding, masking and filtering. On a small programme one person does both; on a large one the AI Core work is a platform role and is staffed first, because every later decision runs inside the structure it sets.
Plan and tenant: the decisions that cannot be undone
Two production plans remain. Standard covers custom predictive AI without generative AI; extended adds the generative AI hub. Standard can be upgraded to extended while keeping data and models, but extended can never be downgraded, and once a standard or extended instance is deleted no new standard instance can be created. Deleting an instance to start clean is therefore the most expensive mistake on the list. The free plan was discontinued on 22 May 2026 (SAP Note 3735945); a 30-day trial that includes the hub replaces it for exploration.
The tenant is the subaccount. Creating several service instances in the same subaccount does not create several tenants: they all point to the same one. A consultant who hears that a second team will get its own instance should check whether it is getting its own subaccount, because isolation is decided there, not by the instance.
Resource groups and the six objects
SAP's vocabulary has six objects. A scenario groups the executables of one use case; an executable is a reusable template; a configuration binds parameter values and artefact versions to an executable; a non-deployable executable becomes an execution, a single run that produces a model or a result set; a deployable executable becomes a deployment, a model server with an inference URL; and artefacts are the data that flow between them.
Resource groups are the isolation unit. A default group exists from onboarding and the documented ceiling is 50 per tenant, raisable by ticket. Configurations, executions, deployments and artefacts are isolated per group; scenarios, executables and Docker registry secrets are shared across the whole tenant. Runtime objects cannot be moved between groups afterwards, so the map of use case by environment is drawn before the first deployment. SAP's security guidance warns against reusing one object-store bucket with the same IAM credentials across groups, and deleting a group that holds scenario-consumer tenants deprovisions them outright.
Training and serving your own models
For a custom model the sequence is: push workflow and serving templates to Git, register the repository and an ArgoCD application, register a Docker registry secret and an object-store secret, then create configurations and start executions or deployments. Compute is chosen through resource plans, with documented minimums of 2.5 GB and one core for Starter, 10 GB and three cores for Basic, 115 GB and 31 cores for Basic.8x, standard GPUs on Infer-S, M and L, and an advanced GPU on Train-L. Deployment and replica quotas are set per tenant; increases are requested on component CA-ML-AIC.
The decision that precedes all of this is whether a custom model is needed at all. A hosted model, including SAP's tabular models for structured prediction, is billed on tokens with no baseline; a custom model pays node hours and baseline for as long as it runs.
Credentials, audit and compliance
The service key carries the client credentials, the authentication URL and the base URL of the AI API. An x.509 variant exists; its default certificate is 2048-bit and valid seven days. SAP states that credential rotation is the customer's responsibility, so a client secret sitting unchanged in a pipeline since go-live is a finding, not a detail.
The audit log records management events such as secrets, resource groups, deployments and executions. It does not record prompts or payloads; capturing those requires inference observability, switched on per request. Data in AI Core is encrypted with tenant-specific keys, and customer-managed root keys are supported through SAP Data Custodian. SAP's ISO/IEC 42001 certification covers Joule, AI Core and AI Launchpad: it certifies SAP's AI management system, not the system the client builds, whose AI Act obligations stay with its provider or deployer.
Cost: capacity units, and a worked example
Billing is in BTP capacity units. For custom AI, SAP meters node hours per resource plan, gigabyte hours of storage, and a baseline in tenant hours that runs every hour compute or storage is in use, capped at 730 hours a month. For generative AI, compute, storage and baseline are waived and tokens are converted into GenAI tokens at model-specific rates published in SAP Note 3437766.
As an illustration of the baseline rule: one idle custom deployment left running for a 30-day month accrues 720 baseline hours, just under the cap, plus its node hours, although nobody calls it. Parallel nodes add node hours but no extra baseline hours. We hold no published capacity-unit list price, so the illustration stops at hours; the rate is in the customer's BTP contract. Consumption per model, orchestration line and resource group appears in the global-account usage export, which is why resource-group design is also the cost-allocation design.
Decision table: what to settle in the first week
Service plan — Standard: custom predictive models only · Extended: any hub, orchestration or tabular-model use on the roadmap · Risk: no downgrade, no new standard instance after deletion.
Model access — Foundation-models scenario: one deployment per model and version · Orchestration scenario: one deployment, model switch by configuration, masking and filtering available · Risk: provider-shaped calls tie code to one model.
Custom or hosted model — Custom: proprietary model or latency a hosted model cannot meet, paid in node hours and baseline · Hosted: in-context or foundation model suffices, paid in tokens.
Credentials — Client secret: trial and tooling · x.509: production with enforced rotation.
Resource groups — One per use case and environment from day one · Risk: everything in the default group, with no way to split cost or access later.
Inherited code — Check whether calls still use the orchestration v1 completion endpoint, decommissioned on 31 October 2026, and migrate to v2.
Who writes this guide
Cédric Mary, editor of Analytics Legends, is a freelance SAP AI & Analytics architect whose delivery focus is the data layer these services run on (Datasphere, Business Data Cloud, Databricks). This guide is written from that vantage point and from the corpus cards listed below, not from a SAP AI Core project of his own.
What we cannot assert
No source we hold publishes a list price for capacity units or a day rate for this role. Resource-plan minimums and quotas are SAP's documented defaults as at the September 2026 service guide and change by release. The posting count depends on how skills are tagged: the AI Core tag was applied more widely from 8 October 2026, so it is not comparable with lower counts quoted on earlier pages.
Frequently asked
Is there a SAP AI Core certification?
There is no standalone AI Core exam. C_AIG_2604, SAP Certified Associate for the Generative AI Developer, covers AI Core with the hub; it replaced C_AIG_2412 in April 2026.
Is the generative AI hub a separate product from AI Core?
No. SAP describes it as a capability of AI Core and AI Launchpad, available only on the extended plan.
Does the BTP audit log show what a model was asked?
No. It records management events. Prompts and answers are kept only if inference observability is enabled per request, with an object store registered.
Engage the editor
This guide is written by Cédric Mary, SAP AI & Analytics Architect & Team Lead. 27 years of SAP — Datasphere, Business Data Cloud, SAC Planning, Joule. Freelance or permanent · Hybrid / remote · Anywhere in EMEA. Available from 19 October 2026.
What this page is built on
- SAP AI Core
- SAP AI Core resource groups, scenarios and executables
- SAP-RPT (RPT-1 → 1.5 → 1.6) — Using SAP's Tabular Foundation Model
- Analytics Legends live contract corpus, 8 October 2026
External sources
- SAP AI Core service guide (PDF, 4 Sep 2026)
- SAP AI Core — Resource Groups (SAP-docs)
- SAP AI Core — Service Plans (SAP-docs)
- SAP AI Core — Metering and Pricing for Generative AI (SAP-docs)
- SAP AI Core — Multitenancy (SAP-docs)
- SAP AI Core — What's New (SAP-docs)
Read next
- SAP AI Core
- SAP AI Core resource groups, scenarios and executables
- SAP generative AI hub consultant: what they configure, deliver and cost
- SAP AI Core pricing — the units the bill is actually built from
- Cédric Mary — SAP AI & Analytics — Data Platform Architect and team lead — Generative AI · AI agents · SAP Joule · Business Data Cloud · Datasphere · Databricks · SAC · BW/4HANA
Guides that answer with this page
These guides cite this page as one of the sources their answer rests on.