Technical reference
DOC-003Deployment

What air gapped actually requires

Disconnecting the network is the easy part. The work is accreditation, update paths and proving what left the building.

Revised
1 September 2026
Recheck by
1 December 2026
What would make this wrong
UAE federal data and AI regulation, which is actively being written. PDPL implementing regulations were still unpublished at time of revision.

Air gapped is a procurement word before it is a technical one. Teams hear it and think about the network, which is the part that takes an afternoon. The part that takes quarters is proving to somebody else that the thing you built meets a standard they are accountable for.

The technical work is real but bounded

  • Model weights and their provenance, brought in and verified without a network path.
  • An update route for weights, runtime and dependencies that does not become a permanent exception.
  • Egress proof. Not a policy saying nothing leaves, but logs demonstrating it.
  • Local telemetry, because the usual observability stack assumes a callback that will not be permitted.
  • A sandbox around anything the agent executes, with the blast radius written down.

None of that is exotic. It is a few weeks of careful work for someone who has done it before, and considerably longer for someone who has not, mostly spent discovering which dependency quietly phones home.

The part that decides the timeline

What actually governs an air gapped deployment is the accreditation regime of the buyer. In practice that means a security questionnaire, an architecture review, and an attestation the buyer can point at when audited. Vendors selling into regulated environments carry SOC 2, ISO 27001 and, for defence adjacent work in some jurisdictions, considerably more.

It is worth being blunt about the maturity of this market. GitHub Copilot reached FedRAMP Moderate for its cloud offering in April 2026 and does not address on premise or air gapped deployment at all. Vendors that do offer it, GitLab Duo through an offline licence among them, treat it as a top tier enterprise entitlement. Established local AI vendors with nine person teams and years of shipping still list SOC 2 and ISO 27001 as pending.

Where the UAE is on this

The sovereign infrastructure is being built now rather than planned. Red Hat and Core42 announced a sovereign AI infrastructure partnership on 11 May 2026 covering, in Core42 own words, the full spectrum of sovereign cloud deployments from fully air gapped environments through to partially restricted and connected models.

The demand side has a date attached to it. In April 2026 the UAE set a target for 50 percent of government sectors, services and operations to run on agentic AI within two years. In June 2026 the Federal Authority for Artificial Intelligence and Data was established, consolidating the AI Office, TDRA digital government sector and the Emirates Data Office into a single regulator with a standards setting mandate.

We will say what we do not know, because it matters more than what we do. The implementing regulations under the PDPL were still unpublished at time of revision. No compliance timelines have been issued. What standard an agentic deployment inside a federal entity will actually be held to is not yet a published document, and anyone quoting you a compliance package against it today is quoting against a guess.

How we would scope it

Air gapped work is priced in stages, and the first stage is not a build. It is establishing what the buyer accreditation regime actually requires, in writing, before anyone specifies hardware. That is a short, cheap, fixed price piece of work, and it has saved more money than any other thing we do.

Sources

  1. Red Hat and Core42 sovereign AI infrastructure, 11 May 2026
  2. UAE agentic AI government mandate, April 2026
  3. UAE Federal Authority for AI and Data, June 2026
  4. GitHub Copilot FedRAMP and data residency, April 2026
  5. GitLab Duo self hosted with offline licence

We do this work, not only write about it.

Sizing, benchmarking on your own tasks, and scoping a restricted deployment against the accreditation regime you are actually held to.

Request a quote