FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Glossary · 5 minute read

What Is an Air-Gapped AI Deployment? Isolated AI Explained

An air-gapped AI deployment runs models entirely within an isolated environment with no external network connectivity. It requires open-weight models, self-hosted infrastructure, and offline processes for updates and evaluation, and it forecloses the fastest capability improvements in exchange for complete isolation.

By FISTA Solutions· AI-Native Engineering Team·
What Is an Air-Gapped AI Deployment? Isolated AI Explained article cover

Air-gapped deployment is sometimes a genuine requirement and frequently an assumed one, adopted because it sounds maximally safe rather than because a specific constraint demands it. The cost is substantial and mostly operational, and it is worth knowing before committing. This explainer covers both sides. It complements what is a sovereign ai cloud and what is model serving, and reflects FISTA Solutions' approach in AI enablement delivery.

What does it require?

Open-weight models, because hosted APIs are unavailable by definition. Self-hosted inference infrastructure with its own capacity planning. Local storage for indexes, artefacts, and logs. And deliberate, controlled processes for moving anything across the boundary — model weights in, evaluation results out.

Everything a hosted provider handles becomes an internal responsibility: capacity, upgrades, security patching, monitoring, and the on-call rota behind it.

ConcernHostedAir-gapped
Model choiceProvider catalogueOpen-weight only
CapacityElasticYour planning
UpdatesAutomaticManual transfer and test
EvaluationStraightforwardInside the boundary
Operational burdenLowHigh
IsolationContractualPhysical

What capability is foreclosed?

Access to the newest frontier models, which are generally released through hosted APIs first and sometimes only. Open-weight models are genuinely capable and the gap on the hardest tasks is real and varies over time.

For many applications the gap does not matter. For the hardest reasoning tasks it does, and the decision should be made with a measurement on the actual workload rather than on general impressions about model rankings.

Why does evaluation become harder?

Because everything must happen inside the boundary. Evaluation sets, results, comparisons, and any tooling all live within the isolated environment, and moving results out for analysis requires a controlled process.

The predictable consequence is that teams under-invest in evaluation, which is precisely where air-gapped deployments need it most, since they cannot rely on a provider improving the model underneath them.

Who genuinely needs it?

Classified environments where the requirement is explicit. Some critical national infrastructure. Certain defence and intelligence contexts. Operations in locations without reliable connectivity, where the isolation is practical rather than chosen.

Outside those, many organisations that assume they need air-gapping would be satisfied by regional hosting with contractual controls on retention and training, which costs a fraction as much to operate.

What is partial isolation?

Self-hosted inference within a private network, with tightly controlled egress rather than complete disconnection. Model weights and updates can be pulled through a controlled channel; nothing sensitive leaves.

This satisfies most data protection and residency requirements while retaining the ability to update, evaluate, and monitor using ordinary tooling. It is frequently what the underlying concern actually requires, and it is worth testing the requirement before accepting full isolation.

What does the operational reality look like?

A small team responsible for inference capacity, model updates that require transfer and re-validation, monitoring built inside the boundary, and an upgrade cadence measured in months rather than days. That cadence is the part most teams underestimate.

What should you do first?

Write down the specific requirement driving the isolation and check whether controlled egress would satisfy it. In many cases the underlying concern is about data leaving, which egress control addresses, rather than about connectivity existing at all.

How are updates handled?

Through a controlled transfer process with validation on the inside. New model weights are brought in, evaluated against the internal suite, and promoted deliberately, which means updates arrive in months rather than days and each one is a small project.

That cadence should be planned for rather than discovered, because a team accustomed to hosted APIs improving underneath them will find the pace surprising.

What skills does it require?

Infrastructure and inference engineering that hosted deployments do not need: capacity planning for accelerators, serving stack operation, and enough understanding of the models to debug behaviour without vendor support. That capability has to exist internally or be contracted, and it is the requirement most often underestimated in the business case.

How is evaluation handled inside the boundary?

With the full apparatus recreated internally: labelled sets, scoring, comparison, and storage of results, all inside. That is more work than it sounds, because the tooling most teams use assumes network access, and substituting it is a project of its own.

It is also the part most likely to be deferred, which leaves an isolated deployment with less quality visibility than a connected one — the opposite of what the isolation was meant to achieve.

What does the business case need to include?

Infrastructure, staffing, the model capability gap, and the slower update cadence, weighed against the specific requirement driving the isolation. Business cases that count only hardware against hosted API pricing understate the total substantially, usually by the cost of the people who will operate it.

Stating the capability trade explicitly also matters, because a decision made on cost that later disappoints on quality tends to be revisited expensively.

How FISTA Solutions helps

FISTA Solutions tests whether full isolation is genuinely required before committing to it, designs partial isolation with controlled egress where that satisfies the constraint, builds offline evaluation and update processes for genuinely air-gapped environments, and sizes the operational burden honestly, through AI enablement, AI agents, and forward deployed engineers. The record behind the approach is 150+ projects for 50+ companies across 12+ countries.

To isolate AI infrastructure without over-building, message FISTA on WhatsApp, or read what is model serving.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What does air-gapping require?

Open-weight models, self-hosted inference infrastructure, local storage for indexes and artefacts, and deliberate processes for moving model weights, updates, and evaluation results across the boundary. Everything a hosted service provides becomes your responsibility.

02What capability is lost?

Access to the newest frontier models, which are generally available only through hosted APIs. Open-weight models are capable and the gap in some capabilities is real, so the requirement should be genuine rather than assumed.

03Why is evaluation harder?

Because evaluation sets, results, and comparisons all live inside the boundary, and moving anything across requires a controlled process. Teams frequently under-invest in offline evaluation as a result, which is exactly where isolated deployments most need it.

04Who genuinely needs it?

Classified environments, some critical national infrastructure, certain defence and intelligence contexts, and operations in locations without reliable connectivity. Many organisations that assume they need it would be satisfied by regional hosting with contractual controls.

05What is partial isolation?

Self-hosting within a private network with tightly controlled egress rather than complete disconnection. It satisfies most data-protection requirements at considerably lower operational cost, and it is frequently what the underlying concern actually needs.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project