Air-gapped AI deployment requirements: the buyer's checklist

True air-gapped AI means zero outbound network paths — no calls to a licensing server, no external DNS, no public time sync. If a platform "phones home" for anything, it is not air-gapped, whatever the datasheet says. This guide is the technical checklist for evaluating an AI security platform for a genuinely isolated environment.

The demand is no longer niche. Gartner projects that by 2030, more than 75% of European and Middle-Eastern enterprises will move workloads on-shore — up from under 5% today. Over 70% of enterprises plan to scale on-premise or edge AI by 2028.

What "air-gapped" actually means

Air-gapped is not a configuration flag. It is an architecture where every dependency the system needs at runtime already lives inside the enclave:

  • No outbound network paths — no HTTPS to a licence server, no DNS, no NTP, no telemetry
  • Physical and logical isolation — no link to any external or untrusted network
  • Unidirectional data entry — controlled transfer (write-once media, data diode), never an open connection

The single most common failure: a vendor calls a deployment on-premise while it still validates a licence over the internet. First question: does it work with the network cable physically unplugged?

The requirements checklist

1

Self-contained runtime

Model weights, tokenizers, container runtime, system libraries present as immutable assets.

2

Offline model — and full capability

Local model must be strong enough. Ask for the benchmark of the air-gapped model specifically.

3

Zero outbound, verifiable

Licensing, updates, time sync all offline. Ask vendor to demonstrate, not describe.

4

Local identity and access

Auth issued and verified inside the enclave, no external IdP callout.

5

An offline update strategy

Controlled one-way transfer with cryptographic chain-of-custody.

6

Local threat intelligence

Detection content and IOC feeds mirrored and updatable offline.

7

Governance that travels

Policy and audit controls identical offline, no weakened local path.

8

A realistic hardware footprint

Know the actual spec.

Common pitfalls when evaluating air-gapped AI

The checklist above tells you what to look for. These are the five ways deployments fail it in practice — each one common enough to warrant its own warning.

1. Licence-server callout disguised as "on-prem"

The platform installs locally but phones home to validate a licence on every startup — or periodically. If the licence server is unreachable, the product degrades or stops. This is not air-gapped. Ask the vendor to demonstrate a cold boot with the network cable physically unplugged. If the licence validation requires DNS, HTTPS or any outbound path, the deployment fails at the first requirement: zero outbound.

2. Model too weak for air-gapped — always ask for the isolated benchmark

Some vendors ship a smaller, cheaper model for air-gapped environments while quoting benchmarks from their cloud-hosted frontier model. The headline number says "95% detection" — the model you actually get behind the wire scores 40%. Always ask for the benchmark of the specific model that runs in the isolated environment, not the cloud edition. Monarch publishes this explicitly: the compact sovereign model solves 25/33 Cybench on a single machine, the same model you get air-gapped.

3. No offline update path — stuck on the day-one model

An air-gapped system that cannot be updated is a system that degrades from the day it is deployed. Threat landscapes change; models need retraining; governance policies need revision. Without a defined offline transfer path — write-once media, data diode, cryptographic verification — you are locked to the day-one model. Ask how updates reach the enclave, what the verification mechanism is, and how long the transfer takes.

4. Governance gaps offline — an ungoverned local path

Some platforms enforce governance when they can reach the cloud policy server but relax or drop it in offline mode. An offensive AI tool operating without governance behind an air-gap is the worst combination: powerful and unconstrained, with no external visibility. Confirm that governance is architecturally identical in the offline deployment — same policy engine, same evaluation latency, same audit trail. There should be no ungoverned path, online or offline.

5. Hardware spec mismatch — cluster vs single VM

A vendor says "runs on-prem" but requires a multi-node Kubernetes cluster with GPU acceleration. In many air-gapped environments — particularly defence and critical infrastructure — the available hardware is a single hardened VM on existing compute. If the platform needs a cluster, that is a procurement and certification cycle of its own. Ask for the actual hardware spec, not "contact us." Monarch runs the entire stack on a single VM: 16 vCPU, 64 GB RAM, CentOS Stream 9, systemd. No GPU required.

Vendor evaluation — what to ask

Five questions that separate a genuinely air-gapped platform from one that markets itself as such. What a good answer looks like is as important as the question itself.

QuestionWhat a good answer looks like
Does it work with the cable unplugged?Live demo, not a claim
What's the air-gapped model's benchmark?Per-category results, not headline
How do updates reach the enclave?Defined offline transfer + crypto verification
Is governance identical offline?Yes, with proof — no ungoverned path
What's the hardware footprint?Specific (e.g., single VM spec), not "contact us"

How Monarch meets it

  • 100% on-premise, zero data export
  • Full capability behind the wire — the compact local model solves 25/33 Cybench on a single machine, ahead of cloud frontier agents
  • Single-VM footprint: CentOS Stream 9, systemd, 16 vCPU / 64 GB; SQLite mode, Redis optional
  • Local identity and governance — actor identity inside your environment, governance runtime <2ms, no ungoverned local path
  • Offline threat-intel mirror

The test we invite: evaluate Monarch with the checklist above, disconnected.

Frequently asked questions

What does air-gapped AI actually require?

Zero outbound network paths, self-contained runtime, offline local model, local identity, offline update path with cryptographic chain-of-custody.

Is an on-premise deployment the same as air-gapped?

No. On-premise can still connect to the internet. Air-gapped means no external connection at all.

Does an air-gapped model mean weaker performance?

Not necessarily. Monarch's compact local model solves 25/33 Cybench on a single machine. Always ask for the air-gapped benchmark specifically.

What hardware does air-gapped AI need?

Varies widely. Monarch runs on a single VM (16 vCPU / 64 GB).

How do you update an air-gapped system?

Controlled one-way transfer with cryptographic verification — never a download.

Evaluate air-gapped AI with the checklist — disconnected.

Request a briefing