Private AI Deployment: Governance for Controlled Environments

Written by Jakub Rusinowski · Last updated 2026-09-13 · Assessment logic is deterministic and runs in your browser

This section is practitioner guidance on deployment and governance mechanics, not legal advice. Regulatory classification turns on facts about intended purpose and real-world use that a questionnaire cannot establish — involve your counsel or DPO for decisions about your specific obligations.

Hosting mode does not change your regulatory classification, but it changes almost everything about which controls you can implement and what evidence you can produce. An air-gapped enclave makes network isolation trivial and model updates painful; a managed API makes updates trivial and log retention someone else's decision. This page walks the six hosting modes the assessment recognises and what each one gives you and costs you.

Six hosting modes, and what each one actually changes

The assessment asks which of these describes your deployment, because each makes a different set of controls cheap or impossible.

ModeWhat it makes easyWhat it makes hardTypical fit
Local — a workstationData path, isolation, costAvailability, access control, backup, anything operationalIndividuals, evaluation, small teams
On-premise — a server you ownLog control, version pinning, network placement, access controlCapacity planning, hardware lifecycle, on-callDepartments and companies with IT
Air-gapped — no network pathNetwork isolation, data residency, exfiltration riskModel updates, patching, monitoring, anything requiring egressDefence, some healthcare and legal work
Private cloud — dedicated tenancyElasticity with a defined boundary, operational maturityResidency proof, subprocessor analysisRegulated industries at scale
Public cloud — shared, your softwareElasticity, managed infrastructureData residency, tenancy isolation evidenceGeneral enterprise
Managed API — someone else's modelSpeed to deploy, no infrastructureVersion stability, log retention, data path, vendor dependencyPrototyping, non-sensitive workloads

Note what is not in that table: risk classification. It is identical across all six rows for the same intended purpose, which is the point.

The air-gap trade, honestly

Air-gapping is the most over-recommended control in this space and the most under-examined. It is genuinely the right answer for some work, and it is expensive in ways that are not obvious until you are living with it.

What it actually buys you. Exfiltration through the network becomes a non-problem rather than a monitoring problem. Data residency becomes a statement about a room. A whole class of subprocessor and transfer analysis disappears. For work where the threat model includes a capable adversary with network access, this is worth a great deal.

What it costs. Model updates become a physical process with a change window. Security patching becomes the same. Monitoring that assumes egress — most of it — has to be rebuilt. Nobody can see the logs remotely, which means the oversight procedure you wrote needs a person in the building. And the thing nobody warns you about: the update friction means air-gapped deployments run older model versions than their operators believe, because each update is a project rather than a command.

The honest recommendation. LLMs air-gap unusually well compared to most software, because inference has no inherent need for egress. If your work genuinely requires it, it is more achievable here than elsewhere. If it does not, an on-premise deployment with a properly placed gateway gets you most of the data-path benefit at a fraction of the operational cost. The air-gapped deployment guide covers who actually needs it.

Controls that only exist in a controlled environment

Some of what the assessment recommends is simply unavailable on a managed API, and it is worth knowing which before you choose:

Deterministic version pinning. You can pin a model revision only if you hold the artefact. API version guarantees are contractual rather than physical, and deprecation schedules are the vendor's.

Log completeness on your terms. Article 26(6) asks deployers to keep the automatically generated logs. On your own gateway you decide what is captured and for how long. On an API you get the export feature that exists.

Inference-path data minimisation you can verify. You can read the code that constructs the prompt. On an API you can read the documentation about the code that constructs the prompt.

Corpus-level access control. If retrieval happens inside your boundary, the index can enforce the same access rules as the documents in it. If retrieval happens at a vendor, that enforcement is theirs to implement and yours to take on trust.

None of this argues that managed APIs are the wrong choice — for many workloads they plainly are not. It argues that hosting mode is a control-availability decision, and worth making before the compliance conversation rather than during it.

Sovereignty is a separate question from compliance

These two get conflated and they are different. Compliance asks whether you meet the obligations that apply to you. Sovereignty asks whose jurisdiction, whose supply chain and whose commercial decisions you depend on. A deployment can be fully compliant and entirely dependent on a single foreign vendor; it can be sovereign and non-compliant.

They interact in one direction that matters: sovereignty choices change the evidence you can produce, which changes how expensive compliance is to demonstrate. That is the real argument for a controlled environment, and it is a better argument than the exemption one because it is true.

The sovereign AI guide covers the four layers — data, models, compute and operational control — and where the practical spectrum sits.

Assess a private deployment

Create Compliance Profile →

Automated assessment based on the information you provide. Not legal advice, certification or an audit.

Frequently asked questions

Does private cloud count as on-premise for compliance purposes?
Not automatically, and the distinction the assessment cares about is who holds the controls rather than who owns the metal. Private cloud typically gives you a defined tenancy boundary and someone else's operational maturity; it does not automatically give you log retention control or model version stability. Ask which of the four controls in the previous section you actually hold.
Is air-gapping required for sensitive data?
Rarely, and it is over-recommended. It is the right answer where the threat model includes a capable adversary with network access, or where a regulator or contract requires it. For most sensitive workloads an on-premise deployment with a properly placed gateway, authenticated access and corpus-level access control achieves the data-path objective at far lower operational cost — and stays patched, which an air-gapped deployment often does not.
Does hosting mode change our EU AI Act risk classification?
No. Classification comes from intended purpose under Articles 5, 6 and Annex III. Hosting mode changes which controls are available to you and what evidence you can produce, which is why the assessment asks about it — but the classification is identical across all six modes for the same purpose.
What is the single biggest governance mistake in private deployments?
Treating the retrieval corpus as a data store rather than as an access-control boundary. An index built from internal documents routinely ends up broader than the permissions of the people querying it, which turns a helpful assistant into a search engine over material its users could not otherwise open. It is invisible until someone asks the right question, and by then it has been true for months.

Keep going