
Sovereign AI
When the data cannot leave.
If a regulator, a residency rule, a classification or a contract means your data cannot move into a hosted service, most of the market's default answer is already unavailable to you. That is usually discovered late, and expensively.

Why it keeps disappointing
Five failure patterns, and they are all architectural.
The diminished edition
A cloud product, ported. It trails the hosted version by a release cycle or three, and the roadmap belongs to the cloud product.
The AI is still somewhere else
The application runs locally; the intelligence does not. The deployment diagram is sovereign and the data flow is not.
The managed-service dependency
It assumes one cloud provider's managed database, queue and identity. Lift it out and half of it does not run.
Governance follows the data
The audit trail and policy engine live in the vendor's control plane. You can see your data but you cannot prove what happened to it.
Nothing is actually disconnected
"Air-gapped" turns out to mean a periodic sync, a licence check, or a telemetry channel somebody assumed was fine.
The useful question
Not "can this be deployed on premises?" — every vendor says yes. It is: is the on-premises version the same product, and does the AI still work when nothing can leave?
Five topologies
From one codebase, so none of them is a special edition.
Open-weights models
Model choice is a configuration, not an architecture.
A sovereign deployment runs inference against models you hold. We are deliberately not loyal to any of them: the right model is the smallest one that passes your evaluation, on a licence your legal function has read, measured on your data rather than on a leaderboard.
The four shapes worth holding
| Shape | Typical role | What to watch |
|---|---|---|
| General instruction-tuned, mid-size | The workhorse for grounded question answering and summarisation. Runs on a single modern accelerator. | Instruction-following under your own prompts, not benchmark scores. |
| Long-context | Document extraction, contract and case work, anything where the passage is long. | Real performance at the far end of the window, which is often much worse than the headline. |
| Larger reasoning-capable | Agent planning and multi-step tool use, where a wrong plan costs more than a slow one. | Tool-calling reliability. Test it; do not assume it. |
| Small and code-specialised | On-device work, classification, routing and coding assistance where latency and privacy dominate. | Whether a rule would do the job better and cheaper. Very often it would. |
How we choose, in order
- Your evaluation set, built from your own questions during discovery. Nothing else decides it.
- Latency and throughput. Two points better and four times slower is usually the wrong model.
- Your hardware — including where the honest answer is that a smaller model is the right call.
- The licence, read by someone who will have to defend it.
- Cost per answered question, not per token, because per-token is not a number anyone can act on.
Grounding, policy, evidence and cost control live in the platform, not the model. Replacing a model is a configuration change and a re-run of your evaluation — not a migration.
Federation
One view, without one location.
The hardest sovereign requirement is not "keep it in country". It is "keep it in country and let the group see the picture".
Diligence
Eight questions worth putting to any vendor — including us.
- Is the on-premises version the same product and the same release as the hosted one?
- Where is content embedded, and does anything leave the boundary to be indexed?
- Where does inference run, and can it run against a model we host?
- Does the audit trail live in our deployment or in your control plane?
- In an air-gapped deployment, which capabilities stop working?
- What does the system depend on from one specific cloud provider?
- Can policy be evaluated per user at query time, or only at the front door?
- Can you reconstruct a decision from the data as it stood on the day it was made?
We will answer all eight in writing. A vendor who cannot answer questions two and three quickly has told you something useful.
Talk about a sovereign deployment
Tell us what the rule actually is — the regulation, the classification, the contract clause — and we will say plainly whether we can work inside it.
Talk to us