If your organization has been told that serious AI requires sending data to someone else’s cloud, that claim is now several years out of date. The most security-obsessed institutions on earth, US intelligence agencies, the French Armed Forces, the US Army, are running large language models fully disconnected from the internet or on infrastructure they control end to end. The interesting shift is not technical. It is contractual: sovereignty has moved from a nice-to-have into the procurement requirement itself.
Who is already running AI with no internet connection at all?
Per Bloomberg’s reporting (May 2024), Microsoft deployed a GPT-4 based system for US intelligence agencies that is fully divorced from the internet: an air-gapped environment where a frontier model performs analysis on top-secret material, live, with no path out. Not a demo, not a restricted API with logging promises. A physically and logically disconnected deployment of one of the most capable models in existence.
That single fact retires an entire family of objections. If “the model needs the cloud” were true in any fundamental sense, this system could not exist.
Can frontier models operate inside classified government clouds?
Per Microsoft’s own announcement (August 2024), Palantir and Microsoft partnered to deliver GPT-4 through Azure OpenAI inside Azure Government’s Secret and Top Secret classified environments, the accreditation world known as IL6. This is the bureaucratically hard version of the problem: not just disconnecting a model, but passing it through the most demanding compliance regime the US government operates, so that classified national-security workloads can use it as ordinary infrastructure.
When a capability clears IL6, “our data is too sensitive for AI” stops being a technical statement and becomes a procurement choice.
What happens when a government makes sovereignty mandatory?
France answered directly. Per press reporting on the agreement, the French Armed Forces adopted a sovereign generative-AI framework with Mistral, deployed self-hosted and on-premises on infrastructure the state controls. The state chose to run operational AI where it holds the keys, and wrote that into the framework before capability discussions even began.
That sequencing is the lesson. Sovereignty was not an add-on evaluated against cost. It was the entry condition.
How big can a government-hosted AI assistant actually get?
Scale is the last refuge of skepticism: fine for a lab, but can a locked-down deployment serve a real organization? The US Army’s CamoGPT runs on government-hosted infrastructure and, per US Army reporting, serves roughly 75,000 users; per DefenseScoop’s coverage (January 2026) it is in active daily use and handles controlled unclassified information along with some classified work. We will not repeat claims about specific classified networks that remain unverified; the verified picture alone, tens of thousands of users on sovereign infrastructure, is sufficient.
Why does this matter to companies that are not armies?
Because procurement language travels. Defense sets the template, and regulated industry copies it: security questionnaires, data-residency clauses, and “no data leaves our environment” requirements are already standard in tenders far from any battlefield. Organizations that treated on-premises AI as an exotic demand are discovering it is becoming the default ask from serious customers, and organizations that can truthfully answer “everything runs inside your network” hold an advantage that has nothing to do with model benchmarks.
What should you take away?
- Fully disconnected frontier AI exists in production: Microsoft’s air-gapped GPT-4 for US intelligence, per Bloomberg’s reporting.
- The hardest compliance regimes have been cleared: GPT-4 inside Azure Government Secret and Top Secret (IL6), per Microsoft’s announcement with Palantir.
- Sovereignty can be the contract’s first clause: France’s armed forces run self-hosted, on-premises AI on national infrastructure, per press reporting.
- It scales to real organizations: ~75,000 users on the US Army’s government-hosted CamoGPT, per US Army reporting.
- The question has flipped: not “can AI run inside our walls” but “why would we accept AI that does not?”
What does this mean for a mid-size Israeli operation?
Israel is full of organizations, defense suppliers, medical operators, critical-infrastructure companies, kibbutz-industry plants with defense contracts, whose real constraint is exactly this: valuable data, and a hard rule that it never leaves. For years that rule was treated as a reason to sit AI out. The evidence above says the opposite: the pattern is proven at the most extreme security tier that exists, and the components (self-hosted models, retrieval over internal documents, private networking) are available to organizations far smaller than an army.
This is also work we do, and we will state it exactly as it happened. For a security-sensitive organization, DataWise architected and specified a zero-egress AI enclave: private networking end to end, an MLOps foundation, self-hosted language and vision models. And we built and demonstrated a fully isolated, self-contained AI assistant inside the closed network: chat over organizational knowledge, retrieval across internal documents, deep-research workflows, document and diagram generation, with nothing leaving the network. Architected and specified; built and demonstrated. We choose those verbs deliberately, because in this field, precision about what happened is the product.
If your data cannot leave your building and you want to see what a closed-network AI assistant looks like in practice, we are glad to walk you through it.