Enterprise + Sovereign AI

What does a sovereign AI architecture for government look like?

A sovereign AI architecture for government keeps every layer — inference, storage, logs, keys, updates and personnel — inside the jurisdiction and, for classified workloads, inside a network with no external path. It pairs region-pinned or air-gapped deployment with locally held keys, cleared operational staff, exportable audit and a physical update process. The API can remain OpenAI-compatible so applications stay portable.

Key facts

Deployment tiersIn-country region, VPC, on-prem and air-gapped
Air-gap updateBundle ships on physical media with periodic model refresh by courier
Key custodyBYOK via cloud KMS or HSM; offline custody for air-gapped sites
IdentitySSO/SCIM and RBAC tied to government identity systems
AuditKey/admin events plus per-request logs, exportable to SIEM
ResilienceMulti-region options and tested DR for continuity tiers
Contractual frameTerms at /legal/terms and service commitments at /legal/sla
Compliance postureSOC 2 Type II and ISO 27001 readiness in progress (not yet certified)

TL;DR

  • Sovereignty is a full-stack property, not a region setting.
  • For classified work, the network has no path out — including support access.
  • Keys, updates and personnel stay inside the jurisdiction.
  • Audit every model call and every administrative action.
  • Start with an unclassified pilot, then expand by classification level.

How it works, step by step

  1. Classify workloads and map each to its legal and security requirements.
  2. Choose the tier: in-country region, VPC, on-prem or fully air-gapped.
  3. Define key custody and the update process, including physical media where required.
  4. Connect identity to the government IdP and define least-privilege roles.
  5. Confirm personnel and support access rules, with logging for every access.
  6. Stand up audit export and define anomaly alerting.
  7. Pilot on unclassified data, document evidence, then expand by classification level.
1Classify workloadsand map each to itslegal and security2Choose the tier:in-country region,VPC, on-prem or3Define key custodyand the updateprocess, including4Connect identity tothe government IdPand define5Confirm personneland support accessrules, with logging6Stand up auditexport and defineanomaly alerting.

Try it yourself

Open the sovereign AI readiness score →

Sovereignty across every layer

  • Compute and storage: inference and data live in-country; for classified workloads, in a network with no external path.
  • Keys: held in a KMS or HSM under national control, with offline custody for air-gapped sites.
  • Updates: model and platform refreshes arrive through a controlled process — physical media for air-gapped networks.
  • Identity: federated with the government identity provider, with RBAC and SCIM lifecycle automation.
  • Audit: request and administrative events retained and exportable to the national SIEM.
  • Personnel: support and operations access constrained by clearance and jurisdiction, and logged.

Building for air-gapped operation

Air-gapped sites invert normal operations. There is no telemetry streaming out, no live support session, and no automatic model update. Design for it: a gateway that works without external dependencies, a local model catalogue, a documented media-based update process with integrity verification and rollback, and an offline key ceremony for initial key material. Capacity planning becomes more conservative because you cannot burst to the cloud, so reserve failover headroom inside the installation. Plugsky's air-gapped option ships on physical media with periodic model refresh by courier, which makes the logistics contract part of the architecture review rather than an afterthought.

Continuity tiers for public services

Not every government workload needs the same isolation. A pragmatic portfolio separates citizen-facing services, internal productivity, analytical workloads and classified systems. Citizen-facing and analytical workloads often fit an in-country region with strict residency and audit; internal productivity sits between; classified systems take on-prem or air-gapped. Design the gateway once and deploy it across tiers so prompts, evaluation suites and application code transfer without rewrites — the same OpenAI-compatible contract holds across all of them.

Procurement evidence and honest gaps

Public sector diligence is evidence-heavy: architecture diagrams, data-flow maps, key custody descriptions, audit samples, personnel and access policy, update procedures and DR test results. Record what is proven and what is pending — Plugsky documents SOC 2 Type II and ISO 27001 as readiness in progress rather than completed certification, and specialised endpoints such as audio, images and fine-tuning are coming soon. Neither is fatal; both belong in the risk register with milestones and compensating controls. Contractual commitments should reference /legal/terms and /legal/sla, with sovereign deployment obligations written into the enterprise agreement.

Honest comparison

RequirementSovereign deploymentIn-country cloud regionGeneral cloud
Data pathAir-gapped option with no external routeIn-country region with pinningProvider regions
Key custodyNational KMS/HSM, offline optionBYOK to national KMSProvider-managed
UpdatesPhysical media, controlled processStandard releasesAutomatic
Support accessClearance-bound and loggedRegion-constrained supportGlobal support teams
ContinuityReserved local capacityMulti-region optionsProvider-managed
Startup effortHighestModerateLowest

Frequently asked questions

What makes AI deployment sovereign?

Every layer sits inside the jurisdiction: compute, storage, keys, updates, audit and personnel. For classified workloads, the network has no external path and updates arrive physically.

Can Plugsky run fully air-gapped?

Yes. The air-gapped deployment ships on physical media with periodic model refresh by courier, and the same OpenAI-compatible API contract applies so applications stay portable.

How do updates work without internet?

Through a documented media-based process with integrity verification and rollback. Treat update logistics, chain of custody and version pinning as part of the architecture review.

Who can access government data?

Support and operations access should be constrained by clearance and jurisdiction, with every access logged. Air-gapped deployments remove external access paths entirely.

How do we maintain audit evidence?

Request and administrative events are logged with actor, timestamp and resource, and export to the national SIEM. Define retention to match your records policy.

Does sovereignty conflict with using third-party model providers?

It can. Provider choice is part of the boundary. For the strictest tiers, plan to run models inside your own installation rather than calling external endpoints.

How should a pilot be scoped?

Start unclassified and low-risk: internal summarisation or document search on non-sensitive data. Verify the boundary, audit and support model, then expand by classification level with documented evidence at each step.

What is Plugsky's certification status for government?

SOC 2 Type II and ISO 27001 are readiness in progress rather than completed. Sovereign deployment controls — private tiers, BYOK/HSM, audit export, SSO/SCIM — can support your assessment while milestones are tracked.