On-premises or air-gapped AI: choose the isolation level
Compare local processing with a physically disconnected zone by data flow, update path, administration, recovery, and the controls an auditor can repeat.
Local processing and a physically disconnected zone solve different operating problems. The right choice follows from data flow, administrative access, release handling, recovery, and the threat model.
Syntalith Team
An on-premises deployment keeps processing inside an environment that the organisation administers. An air-gapped deployment removes the permitted network path altogether and moves releases through a controlled transfer. They call for different equipment, skills, and recovery plans.
Begin with the information flow
Write down every path used by the workload:
- documents and questions entering the system;
- model, index, library, and configuration updates;
- authentication and secrets;
- logs, telemetry, backups, and support exports;
- people who administer the host and review results.
Then classify each path as required, optional, or prohibited. This list gives the security team something concrete to approve. It also reveals hidden dependencies such as package downloads, remote fonts, cloud logging, or an update check in a container startup script.
Local processing on the company network
On-premises processing is suitable when the organisation can administer a local server or cluster and its rules allow carefully controlled connectivity. Search, generation, the document index, and logs remain in the organisation's environment. A firewall, DNS policy, service account design, and outbound logging support the decision.
The operating plan should include:
- an inventory of models, packages, images, indexes, and configuration;
- a rule for every outbound destination, including a decision to block it;
- a patch and vulnerability process with an owner;
- backups that can be restored on the target hardware;
- representative documents for quality, latency, memory, and concurrency tests.
The system still needs hardening. Local storage does not answer who may open a document, who may export a result, or how a compromised administrator account is detected.
A physically disconnected zone
An air-gapped zone prohibits routine network traffic to the outside. Models and software arrive as a release bundle. The build team records each file in a manifest, scans the bundle, and signs it with a key held outside the zone. The zone operator verifies the signature and hashes before installation. A failed check stops the release and creates an incident for the named owner.
The same process covers model weights, container images, application code, indexes, migrations, and policy files. Keep the previous approved bundle available for rollback. Record the release version, operator, verification result, and any migration outcome inside the zone.
Physical separation adds work to diagnostics and emergency response. The zone needs its own monitoring, backup media, key custody, spare capacity, and staff who can repair a service without opening an improvised route. A firewall with a generous allowlist does not provide the same operating model.
Compare the two operating models
| Decision | On-premises processing | Air-gapped zone |
|---|---|---|
| Network path | Controlled connectivity can be permitted by policy | Routine external connectivity is absent |
| Releases | Signed or approved packages through the normal change process | Signed bundles transferred through an approved media path |
| Diagnostics | Central tools may be available after access review | Local tools and controlled export of findings |
| Administration | Shared service model can be possible | Dedicated staff and procedures are usually required |
| Recovery | Networked backup may be permitted after review | Local restore media and a rehearsed recovery path |
| Main tradeoff | Easier maintenance with more paths to govern | Stronger separation with slower updates and heavier operations |
Choose on-premises when local processing and controlled access satisfy the requirement. Choose an air-gapped zone when a formal rule or threat model requires physical separation and the organisation can fund the release, support, and recovery work.
Measure before buying hardware
Use representative documents and tasks. Record answer quality against a review rubric, time to first token, total response time, peak memory, throughput, concurrent users, and restore time. Keep the model version, prompt, retrieval settings, hardware, and test set with each result.
The NIST AI Risk Management Framework is a useful vocabulary for mapping these checks to governance, measurement, and operational response. It does not choose an isolation level for a particular organisation.
Acceptance checklist
- Does the requirement concern data location, outbound traffic, or physical separation?
- Who approves models, dependencies, indexes, and configuration changes?
- Can the team list every network destination and its purpose?
- Does every release have a version, manifest, provenance record, and signature?
- Are DNS, HTTP, HTTPS, and raw TCP checks part of the acceptance run?
- Can the team restore the service and the index on the target hardware?
- Who owns a failed verification, a vulnerability, and an incident?
- How long does a security patch take in each operating model?
- Can an auditor repeat the checks without vendor access?
The on-prem document workflow and air-gap release path show the kind of operating detail a project should document. Bring your data classification, network rules, update policy, and recovery target to an AI process scan before selecting hardware or a release method.
Free process scan
Start with a free process scan.
- A 30-minute call with the engineer who would lead the work.
- A review of the processes that cost you the most time and money.
- A written summary of what to automate first and the likely cost range.
The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.
€0
30 minutes · written takeaway within 2 business days
Times are shown in your own time zone. We work with clients across time zones.
Describe the process in the form