Enterprise + Sovereign AI

What is the difference between sovereign, private and on-prem AI?

They answer different questions. Sovereign AI asks who has legal and operational control — no foreign access, keys and personnel under national jurisdiction. Private AI asks who else shares the infrastructure — dedicated tenancy rather than noisy neighbours. On-prem AI asks where it runs — inside your own data centre. A deployment can be private without being sovereign, and on-prem without being sovereign if a foreign vendor still operates it.

Key facts

SovereignJurisdiction and control: data, keys, operations and personnel inside one legal boundary
PrivateDedicated tenancy: your own VPC, cluster or workspace rather than shared infrastructure
On-premPhysical location: your data centre, connected or air-gapped
Plugsky tiersCloud region pinning, VPC, on-prem, air-gapped and bring-your-own-cloud
Key controlBYOK via cloud KMS or HSM, with offline custody for air-gapped sites
Air-gapNo internet path; updates ship on physical media with periodic model refresh
Contractual frameTerms at /legal/terms and service commitments at /legal/sla
Compliance postureSOC 2 Type II and ISO 27001 readiness in progress (not yet certified)

TL;DR

  • Sovereign is about jurisdiction; private is about tenancy; on-prem is about location.
  • Shared infrastructure can still be sovereign if control stays in-country.
  • On-prem with a foreign operator is not automatically sovereign.
  • Map requirements to the axis they actually belong to before shopping.
  • Expect to combine tiers: on-prem for classified data, region pinning for the rest.

How it works, step by step

  1. Write down the requirement in plain language: who may access, who may operate, where it runs.
  2. Assign each requirement to the sovereignty, privacy or location axis.
  3. Decide the strictest combination and check whether it is legally required or assumed.
  4. Match deployment tiers to that combination: region, VPC, on-prem or air-gapped.
  5. Verify key custody and personnel access, because they often determine sovereignty.
  6. Test the chosen tier with a pilot before migrating production workloads.
  7. Document the decision rationale for auditors and future architecture reviews.
1Write down therequirement inplain language: who2Assign eachrequirement to thesovereignty,3Decide thestrictestcombination and4Match deploymenttiers to thatcombination:5Verify key custodyand personnelaccess, because6Test the chosentier with a pilotbefore migrating

Try it yourself

Open the private LLM cost estimator →

Three questions, three axes

  • Sovereign: who controls it? Data stays in the jurisdiction, keys are held nationally, and operations and support personnel fall under local law. This is a legal and operational property.
  • Private: who shares it? Dedicated tenancy — your own VPC, cluster or isolated workspace — reduces cross-tenant risk but says nothing about jurisdiction.
  • On-prem: where is it? Physically in your data centre. On-prem is a location property and can be air-gapped or connected.

Most procurement confusion comes from using the words interchangeably. A hyperscaler region can be sovereign-ish and private; a colocated rack can be on-prem but operated by a foreign vendor and therefore not sovereign.

How the axes combine in practice

  • Region-pinned cloud: quick to start; private only against policy, sovereign only if the jurisdiction and operator qualify.
  • VPC in your cloud account: private, and sovereign if the cloud region and operator meet national rules; the data path stays inside your account.
  • On-prem, vendor-operated: location and often privacy, but sovereignty depends on who has administrative access.
  • Air-gapped on-prem, locally operated: the strongest combination — location, tenancy and jurisdiction together — at the highest operational cost.

Plugsky offers all four tiers behind one OpenAI-compatible API, plus bring-your-own-cloud for organisations that must keep consumption in their own account.

Choosing without overspending

Sovereignty is expensive, so define which workloads genuinely require it. Classified or citizen-data systems usually justify air-gapped deployment. Internal productivity rarely does; region pinning with audit and BYOK often satisfies the requirement at far lower cost. Build a workload table: data class, legal driver, acceptable latency, budget and who must operate it. The strictest row sets your deployment tier, but only for that row — a portfolio approach avoids paying sovereign prices for every internal tool.

Questions that expose the real answer

  • Who can access the data, from which country, under whose law?
  • Where are encryption keys generated, stored and revoked?
  • Which subprocessors and personnel touch the system, and where are they located?
  • How do updates reach the system, especially if it is air-gapped?
  • What happens to data on contract termination, and what evidence is provided?

Answer these before matching vendor names to deployment tiers. Contractual and service commitments belong in /legal/terms and /legal/sla; the deployment tier is only credible if the agreements and the architecture agree.

Honest comparison

PropertySovereignPrivateOn-prem
Core questionWho controls it legally and operationally?Who shares the infrastructure?Where does it physically run?
Typical controlNational jurisdiction for data, keys and personnelDedicated tenancy or VPCYour data centre or rack
Can be absent despite the labelForeign-operated on-prem still counts as non-sovereignShared cloud can be policy-acceptableCloud region may satisfy location without ownership
Cost driverHighest — local operations and updatesModerate — dedicated capacityCapital plus facilities
Plugsky tierAir-gapped or in-country with local custodyVPC or dedicated workspaceOn-prem Helm chart
Best forGovernment, defence, regulated citizen dataBanks and enterprises with tenant isolation needsNo external network paths

Frequently asked questions

Can shared-cloud AI be sovereign?

It can if the jurisdiction, operator, key custody and personnel satisfy your definition. Sovereignty is about control and law, not tenancy, so a region-pinned service can qualify while a foreign-operated on-prem rack might not.

Is on-prem always more sovereign?

No. On-prem guarantees location, but if a foreign vendor holds administrative access or keys, sovereignty is incomplete. Local operations and local key custody are what complete the picture.

Is private AI the same as a VPC deployment?

A VPC deployment is one way to achieve private tenancy: the workload runs inside your cloud account with your networking and KMS. Private simply means dedicated rather than shared.

Which tier should a bank choose?

Often VPC with BYOK and region pinning for most workloads, moving to on-prem for the highest-sensitivity systems. Regulators generally care about the controls, evidence and exit plan as much as the physical location.

What does air-gapped add?

No external network path at all, with updates delivered physically. It is the strongest isolation and the highest operational burden, suited to classified or critical systems rather than general enterprise use.

Does Plugsky support all three models?

Yes. Region pinning, VPC, on-prem, air-gapped and bring-your-own-cloud deployments are documented, all behind the same OpenAI-compatible API so workloads stay portable.

How do we avoid paying sovereign prices for everything?

Portfolio the workloads. Assign the strictest tier only to rows that legally require it, and use region pinning with audit, BYOK and scoped keys for the rest.

What evidence should we keep?

A workload-to-tier mapping, key custody description, personnel and access policy, update process for air-gapped sites, audit samples and the signed terms and SLA at /legal/terms and /legal/sla.