Air-gapped AI deployment requirements: the buyer's checklist
True air-gapped AI means zero outbound network paths — no calls to a licensing server, no external DNS, no public time sync. If a platform "phones home" for anything, it is not air-gapped, whatever the datasheet says. This guide is the technical checklist for evaluating an AI security platform for a genuinely isolated environment.
The demand is no longer niche. Gartner projects that by 2030, more than 75% of European and Middle-Eastern enterprises will move workloads on-shore — up from under 5% today. Over 70% of enterprises plan to scale on-premise or edge AI by 2028.
What "air-gapped" actually means
Air-gapped is not a configuration flag. It is an architecture where every dependency the system needs at runtime already lives inside the enclave:
- •No outbound network paths — no HTTPS to a licence server, no DNS, no NTP, no telemetry
- •Physical and logical isolation — no link to any external or untrusted network
- •Unidirectional data entry — controlled transfer (write-once media, data diode), never an open connection
The single most common failure: a vendor calls a deployment on-premise while it still validates a licence over the internet. First question: does it work with the network cable physically unplugged?
The requirements checklist
Self-contained runtime
Model weights, tokenizers, container runtime, system libraries present as immutable assets.
Offline model — and full capability
Local model must be strong enough. Ask for the benchmark of the air-gapped model specifically.
Zero outbound, verifiable
Licensing, updates, time sync all offline. Ask vendor to demonstrate, not describe.
Local identity and access
Auth issued and verified inside the enclave, no external IdP callout.
An offline update strategy
Controlled one-way transfer with cryptographic chain-of-custody.
Local threat intelligence
Detection content and IOC feeds mirrored and updatable offline.
Governance that travels
Policy and audit controls identical offline, no weakened local path.
A realistic hardware footprint
Know the actual spec.
How Monarch meets it
- •100% on-premise, zero data export
- •Full capability behind the wire — the compact local model solves 25/33 Cybench on a single machine, ahead of cloud frontier agents
- •Single-VM footprint: CentOS Stream 9, systemd, 16 vCPU / 64 GB; SQLite mode, Redis optional
- •Local identity and governance — actor identity inside your environment, governance runtime <2ms, no ungoverned local path
- •Offline threat-intel mirror
The test we invite: evaluate Monarch with the checklist above, disconnected.
Frequently asked questions
What does air-gapped AI actually require?
Zero outbound network paths, self-contained runtime, offline local model, local identity, offline update path with cryptographic chain-of-custody.
Is an on-premise deployment the same as air-gapped?
No. On-premise can still connect to the internet. Air-gapped means no external connection at all.
Does an air-gapped model mean weaker performance?
Not necessarily. Monarch's compact local model solves 25/33 Cybench on a single machine. Always ask for the air-gapped benchmark specifically.
What hardware does air-gapped AI need?
Varies widely. Monarch runs on a single VM (16 vCPU / 64 GB).
How do you update an air-gapped system?
Controlled one-way transfer with cryptographic verification — never a download.
Evaluate air-gapped AI with the checklist — disconnected.
Request a briefing