The New Sovereign AI Playbook: How Nations Are Building AI Systems That Never Leave Home
Sovereign AI is moving from theory to operational reality, with governments and defense contractors now deploying artificial intelligence systems that process sensitive data entirely within national borders and air-gapped networks. Three separate announcements today reveal how nations are solving the central tension of sovereign AI: how to harness AI's power on the most critical systems, like power grids and defense networks, without creating the very security vulnerabilities those systems were designed to prevent (Sources 1, 2, 3).
What Exactly Is Sovereign AI, and Why Does It Matter Now?
Sovereign AI refers to artificial intelligence systems that operate entirely within a nation's control, with data and processing never leaving the country's borders or connecting to public internet infrastructure. For most countries, this has been a policy goal rather than a technical reality. The challenge is that traditional AI systems rely on cloud servers, APIs, and network connections that create potential entry points for cyberattacks or data breaches. When the systems in question control power grids, water supplies, or defense networks, that risk becomes unacceptable.
Malaysia is now evaluating Huawei's Ascend 910C chips for a MYR2 billion sovereign AI cloud infrastructure project, signaling how Southeast Asian nations are making strategic choices about which technology partners to trust with their AI infrastructure. Meanwhile, two U.S.-based partnerships are taking a different approach, focusing on how to deploy AI agents on systems that are deliberately isolated from networks altogether.
How Are Governments Deploying AI on Disconnected Critical Systems?
The technical challenge is straightforward but severe. A nation's most valuable systems, like SCADA (supervisory control and data acquisition) networks that manage infrastructure, are intentionally air-gapped, meaning they have no connection to the internet or external networks. This isolation is deliberate security by design. But if an AI agent needs to help operate those systems, it needs some way to connect to them, which creates the exact vulnerability the air-gap was meant to prevent.
Two announcements today address this problem through different architectural approaches:
- Seekr and SEMPRE Partnership: Seekr's explainable AI runs directly on SEMPRE's hardened edge devices, which operate independently and can mesh together as a decentralized national network. Models execute locally on the device itself, with no data or model calls crossing the public internet. The reasoning behind every AI decision is recorded on-site, where operators can audit it.
- Wand AI and Zeroport Integration: Wand AI added Zeroport's hardware-enforced boundary layer to its sovereign AI platform, creating a physical, non-IP connection between AI agents and protected systems. Instead of traditional network access, agents interact with critical systems the way cleared human operators do: keystrokes in, pixels out. Zeroport's Moativ enforcement layer, running on dedicated hardware, monitors every input and output in real time and can block or terminate sessions that deviate from authorized actions.
- On-Premises Inspection and Audit: Both approaches keep all session content within the nation's own facilities. No external party, not even the technology vendor, sees what the AI agent is doing or what data it processes. This addresses a core sovereign AI requirement: complete data residency and the ability to audit every action (Sources 2, 3).
The Zeroport approach is particularly novel because it moves the security boundary from software to hardware. Traditional guardrails and policy enforcement run in software on the same computer as the AI model, which means a sufficiently sophisticated model could theoretically argue around those rules through prompt injection or goal drift. Zeroport's hardware-enforced boundary cannot be negotiated with or bypassed by software, because it exists at the physical layer.
Why Can't Nations Just Use Existing Cloud AI Services?
Cloud-based AI services like OpenAI's ChatGPT or Google's Gemini require sending data to external servers, which violates the core principle of sovereignty. For classified defense work, critical infrastructure control, or sensitive government operations, this is simply not an option. Additionally, cloud services operate on shared infrastructure, meaning a nation's AI workloads could theoretically be interrupted or monitored by the cloud provider or other nations.
The sovereign AI approach trades some operational convenience for complete control. Instead of accessing a powerful model through an API call, nations deploy smaller, domain-specific models that run locally on their own hardware. These models are often less capable than large public models, but they are auditable, controllable, and never create a network route into protected systems.
"Sovereign AI is about data residency and the autonomy to ensure it does not need to leave the sovereign boundary in order to operate," said Rob Clark, President of Seekr. "With SEMPRE and Seekr, there is finally a complete all-in-one survivable edge network that combines the networking, AI compute, and edge-optimized AI layer all in one hardened and resilient package, deployable as a single node or mesh network."
Rob Clark, President of Seekr
What Are the Real-World Use Cases for Sovereign AI on Critical Systems?
The value of sovereign AI increases as AI agents get closer to systems that actually control national infrastructure. Potential applications include analyzing grid data to predict power failures, automating responses to water system anomalies, supporting military decision-making in contested environments, and automating routine tasks in core banking and government systems.
The Seekr and SEMPRE partnership specifically emphasizes operational continuity through disruption. If the public internet fails or telecommunications networks are compromised, SEMPRE's mesh network allows AI-enabled operations to continue because each device can operate independently. This is particularly relevant for defense and critical infrastructure scenarios where an adversary might attempt to disrupt communications.
Zeroport's hardware-enforced boundary addresses a different but equally critical concern: credential theft and remote access exploitation. According to Zeroport's analysis, roughly two-thirds of cyberattacks exploit remote access tooling, and 80 percent of breaches involve stolen or compromised credentials. By eliminating the network route entirely and replacing it with a one-way hardware boundary, the attack surface shrinks dramatically.
"Every guardrail an AI can reach is a guardrail an AI can eventually argue with," said Joseph Gertz, Co-Founder and Chief Executive Officer of Zeroport. "We moved the boundary into the physical layer: a break in the wire that cannot carry a packet, and an enforcement AI sitting on silicon the governed session has no address for. A ministry can put an agent to work on a control system and know that the agent's authority ends at physics rather than at a line in a config file."
Joseph Gertz, Co-Founder and Chief Executive Officer of Zeroport
How Do These Approaches Scale Across a Nation?
Both the Seekr/SEMPRE and Wand/Zeroport architectures are designed to scale from single installations to national networks. SEMPRE's decentralized mesh network allows multiple devices to connect and operate as a unified environment across different locations, all while maintaining the same security posture. Zeroport's hardware-enforced boundary scales by adding more Fantom Cores and appliances, with each appliance supporting hundreds of concurrent sessions. Because the boundary is a physical object rather than a software tunnel, capacity grows with hardware rather than being bottlenecked by network throughput (Sources 2, 3).
The latency performance is also critical for real-time operations. Zeroport's dedicated hardware pathways target sub-50-millisecond response times, which makes the channel usable for live control work rather than only for after-the-fact review or analysis. This is essential for applications like grid management or defense operations where delays can have serious consequences.
Malaysia's evaluation of Huawei chips for its sovereign AI cloud represents a different scaling strategy, one focused on building the underlying compute infrastructure that sovereign AI systems will run on. By choosing domestic or trusted-partner chip suppliers, nations reduce their dependence on U.S. or Western technology supply chains, which have become increasingly restricted through export controls.
What Happens to the Audit Trail and Accountability?
One of the defining features of these sovereign AI systems is their emphasis on explainability and auditability. Seekr specifically markets itself as the leader in "explainable and sovereign AI," with tools that surface the provenance, lineage, and intent behind every model decision. This allows government agencies and operators to understand not just what an AI agent did, but why it did it.
Wand AI's approach includes staged rule compilation and dry-run testing against historical session data before rules are armed. Every autonomous action lands in an audit log with evidence attached: what was on screen, what was typed, what was done, and why. Autonomy can be set on a five-step dial ranging from observe-only to self-tuning, giving operators granular control over how much independence an AI agent has.
This level of auditability serves multiple purposes. It provides accountability for government operations, enables rapid investigation if something goes wrong, and creates a historical record that can be reviewed by oversight bodies or security auditors. For nations building sovereign AI systems, this transparency is often a legal or policy requirement.
The convergence of these three announcements on the same day signals that sovereign AI is transitioning from research and pilot projects to production deployment. Malaysia's infrastructure investment, Seekr and SEMPRE's partnership for defense and critical infrastructure, and Wand and Zeroport's focus on air-gapped systems all point toward a near-term reality where AI agents operate on the systems nations depend on most, with complete data residency and hardware-enforced security boundaries.