[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:en":3,"public-menus:all":38,"post:air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access:en":205,"related:post:air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access:en:1":2443},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","en","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":2442},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1685,"featuredImage":1686,"featuredImageAlt":1687,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1688,"publishedAt":1689,"createdAt":1690,"updatedAt":1691,"seoLocalePaths":1692,"categories":1701,"author":1714,"translations":1719},"494","Air-Gapped AI: How AI Systems Work Without Internet or Cloud Access","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","{\"time\":1791495428517,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is an AI system deployed inside a security domain that has no physical network connection to the external systems it is separated from, with any transfer across that boundary performed through deliberately controlled, non-automated procedures. The AI model, runtime, data, retrieval indexes, tools and operational dependencies required for inference must therefore be available inside the isolated environment. Air-gapped AI is not simply “a local model” or “an on-premise server”: the defining property is the network and transfer boundary around the complete system.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"An air-gapped AI system can run LLM inference, RAG, document analysis and even agentic workflows without internet or cloud APIs if every required dependency is available inside the isolated domain.\u003Cbr>\u003Cbr>A practical architecture is:\u003Cbr>\u003Cstrong>controlled import → internal artifact\u002Fmodel repositories → local AI runtime → local data\u002FRAG → local tools → internal users\u002Fservices → local monitoring\u002Faudit\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The difficult part is not making one LLM answer offline. It is operating the whole AI lifecycle — updates, models, drivers, packages, data imports, credentials, logging and security — without silently depending on external services.\"},\"tunes\":{}},{\"id\":\"nist-boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Air gap has a stricter meaning than “no internet”\",\"body\":\"NIST's cybersecurity glossary defines an air gap as an interface where two systems are \u003Cstrong>not physically connected\u003C\u002Fstrong> and where any logical transfer is \u003Cstrong>not automated\u003C\u002Fstrong>; data crosses only manually under human control. Vendor documentation sometimes uses “air-gapped” or “disconnected” more broadly for environments with no outside-internet connection but with internal networking and controlled staging infrastructure. Architecture documentation should state which meaning is actually implemented.\"},\"tunes\":{}},{\"id\":\"not-security\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Air-gapped does not mean secure by definition\",\"body\":\"Removing direct network connectivity eliminates many remote paths, but it does not eliminate malicious removable media, compromised software\u002Fmodel imports, insider threats, vulnerable internal services, physical compromise, prompt injection through imported documents or lateral movement inside the isolated network.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"Current NVIDIA NIM and Red Hat AI Inference documentation both support LLM serving without outside-internet access by pre-staging model and container assets. NVIDIA documents a connected preparation phase followed by an isolated execution phase with local assets and no cloud registry credentials. Red Hat uses mirrored container\u002Fmodel repositories for disconnected OpenShift environments. These are useful implementation examples, but they do not override the stricter NIST definition of an air gap.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What air-gapped AI really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The word AI does not change the basic security concept. An air gap is a boundary between security domains. AI simply makes the isolated side more operationally demanding because modern AI stacks normally assume downloadable models, package registries, telemetry, APIs, model hubs and frequent software updates.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The isolated environment can still contain many connected machines. An internal cluster may have GPUs, application servers, storage, databases, identity services and monitoring connected to each other. The air gap exists between that enclave and the outside domain.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The relevant question is therefore not “Does this GPU have Wi-Fi?” but “Can this AI environment exchange information with the external domain through an automated physical or logical path?”\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Imagine a company wants an internal assistant for confidential technical documents, but the environment is not permitted to send those documents to the internet.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The company downloads an approved LLM, embedding model, container images and software packages in a connected staging environment. After validation, approved artifacts are transferred into the isolated environment.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Inside the enclave, the model server, document parser, vector database, application and identity services run locally. Users can ask questions and use RAG against internal documents without a cloud model or public model registry.\"},\"tunes\":{}},{\"id\":\"p-simple-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"When an update is required, the update passes through the controlled import process again rather than being downloaded directly by the production AI server.\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A basic air-gapped AI operating cycle\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Acquire outside the enclave\",\"description\":\"Download approved models, packages, containers, drivers, signatures and documentation in a connected staging environment.\"},{\"label\":\"2. Verify before transfer\",\"description\":\"Check provenance, signatures\u002Fchecksums, malware status, licensing and compatibility according to organizational policy.\"},{\"label\":\"3. Transfer through controlled boundary\",\"description\":\"Move approved artifacts using the authorized manual or mediated process.\"},{\"label\":\"4. Publish internally\",\"description\":\"Place artifacts in internal model, container, package or file repositories.\"},{\"label\":\"5. Deploy locally\",\"description\":\"Run inference, RAG, applications and tools without external dependencies.\"},{\"label\":\"6. Monitor inside the enclave\",\"description\":\"Collect logs, metrics, model\u002Fruntime status and security events locally.\"},{\"label\":\"7. Export only approved evidence\",\"description\":\"Move selected reports or artifacts outward through the reverse controlled process where policy permits.\"},{\"label\":\"8. Repeat for updates\",\"description\":\"Treat new models, patches, corpora and dependencies as new supply-chain imports.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A production air-gapped environment can be much larger than one workstation. It may include Kubernetes\u002FOpenShift, internal registries, object storage, identity providers, vector databases, observability, backup infrastructure and several model-serving nodes.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The more services exist inside the enclave, the more the organization must reproduce capabilities that connected environments normally consume from the internet.\"},\"tunes\":{}},{\"id\":\"p-stops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapping therefore shifts complexity. It reduces direct external connectivity but increases artifact-management, patching, dependency, supply-chain and operational responsibility inside the isolated domain.\"},\"tunes\":{}},{\"id\":\"h-terms\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped vs offline vs local vs on-premises vs private vs sovereign AI\",\"level\":2},\"tunes\":{}},{\"id\":\"terms-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Term\",\"What it primarily describes\",\"Internet\u002Fexternal connectivity required?\"],[\"Local AI\",\"Inference\u002Fruntime runs on local hardware\",\"No; but it may still call cloud services\"],[\"Offline-capable AI\",\"Can continue operating without internet\",\"No during offline operation; reconnection may be normal\"],[\"Disconnected environment\",\"No direct external-internet path from deployment environment\",\"Usually no; may use controlled mirrors\u002Fbastions\"],[\"On-premises AI\",\"Infrastructure runs in an organization's own\u002Fon-prem environment\",\"Could still have full internet connectivity\"],[\"Private AI\",\"AI processing is controlled to meet privacy\u002Fconfidentiality requirements\",\"Architecture-specific; can be connected or disconnected\"],[\"Air-gapped AI\",\"Security domains are physically disconnected and cross-boundary transfer is non-automated\u002Fmanual under strict definition\",\"No automated external path\"],[\"Sovereign AI\",\"Control\u002Fjurisdiction over models, data, infrastructure and dependencies\",\"Not necessarily; sovereignty is broader than network isolation\"]]},\"tunes\":{}},{\"id\":\"p-terms-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"These terms can overlap but are not synonyms. A local Ollama server connected to the internet is local AI, not air-gapped AI. An on-premises RAG platform that calls a cloud model is on-premises application infrastructure with cloud inference, not air-gapped AI.\"},\"tunes\":{}},{\"id\":\"p-terms-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air-gapped system is often private by design because data remains inside the enclave, but privacy also depends on authorization, logging, data handling, physical security and operational policy.\"},\"tunes\":{}},{\"id\":\"h-strict\",\"type\":\"header\",\"data\":{\"text\":\"Strict air gap vs practical disconnected deployment\",\"level\":2},\"tunes\":{}},{\"id\":\"strict-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Two meanings frequently called “air-gapped”\",\"layout\":\"table\",\"columns\":[{\"id\":\"strict\",\"label\":\"Strict air gap\"},{\"id\":\"disconnected\",\"label\":\"Disconnected \u002F no-internet deployment\"}],\"rows\":[{\"id\":\"physical\",\"label\":\"External physical connection\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"transfer\",\"label\":\"Cross-boundary transfer\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"internet\",\"label\":\"Internet access from AI workload\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"internalnet\",\"label\":\"Internal networking\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"best\",\"label\":\"Use term when\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}}]},\"tunes\":{}},{\"id\":\"naming-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Document the boundary instead of relying on the label\",\"body\":\"For architecture and security reviews, write the actual rule: \u003Cstrong>no outbound internet\u003C\u002Fstrong>, \u003Cstrong>no physical external network path\u003C\u002Fstrong>, \u003Cstrong>manual transfer only\u003C\u002Fstrong>, or \u003Cstrong>disconnected cluster with approved bastion\u002Fmirror\u003C\u002Fstrong>. That is more precise than saying only “air-gapped.”\"},\"tunes\":{}},{\"id\":\"h-architecture\",\"type\":\"header\",\"data\":{\"text\":\"A practical air-gapped AI architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"architecture-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"What must exist inside the isolated environment\"],[\"User\u002Fapplication layer\",\"Chat UI, APIs, business application or internal agent interface\"],[\"Identity &amp; authorization\",\"Local\u002Finternal authentication, RBAC, tenant\u002Fresource permissions\"],[\"AI gateway\u002Fruntime\",\"Model routing, request policy, context assembly and runtime controls\"],[\"Model serving\",\"Local model server(s), weights, tokenizer\u002Fconfig and accelerator runtime\"],[\"RAG \u002F knowledge\",\"Document store, parser, embeddings, vector\u002Flexical indexes, metadata and provenance\"],[\"Tools\u002Fservices\",\"Only internal\u002Flocal APIs and approved systems reachable from the enclave\"],[\"Artifact repositories\",\"Local container registry, package mirror, model store and optionally OS\u002Fupdate repositories\"],[\"Observability\",\"Internal logs, metrics, traces and audit records\"],[\"Backup\u002Frecovery\",\"Local or separately controlled backup process appropriate to the security domain\"],[\"Transfer boundary\",\"Controlled import\u002Fexport process with inspection and approval\"]]},\"tunes\":{}},{\"id\":\"p-architecture-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A complete architecture should be able to start and operate without DNS lookups, license checks, package downloads or API calls to public services unless those dependencies have approved internal replacements.\"},\"tunes\":{}},{\"id\":\"p-architecture-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A useful design test is to disconnect the deployment from every external service and cold-start the stack. Hidden dependencies tend to appear during startup, model loading, authentication, package resolution or telemetry initialization.\"},\"tunes\":{}},{\"id\":\"h-models\",\"type\":\"header\",\"data\":{\"text\":\"Models must be pre-staged\",\"level\":2},\"tunes\":{}},{\"id\":\"p-models-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Cloud model APIs are unavailable by definition if the isolated workload has no path to them. The enclave therefore needs locally runnable model artifacts or an internally hosted inference service.\"},\"tunes\":{}},{\"id\":\"p-models-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NVIDIA's current NIM air-gap documentation explicitly uses a two-phase pattern: download and prepare model assets on a connected machine, transfer them, then run the isolated NIM from local storage without outbound registry access or cloud API keys.\"},\"tunes\":{}},{\"id\":\"p-models-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model weights are only part of the dependency set. Tokenizers, configuration files, adapters, quantization metadata and any required runtime code must also be present.\"},\"tunes\":{}},{\"id\":\"h-remote-code\",\"type\":\"header\",\"data\":{\"text\":\"Models with remote-code dependencies are an air-gap hazard\",\"level\":2},\"tunes\":{}},{\"id\":\"p-remote-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some model repositories contain custom Python code or runtime hooks that normally fetch additional code or assets.\"},\"tunes\":{}},{\"id\":\"p-remote-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Current Red Hat AI Inference documentation explicitly warns that some Hugging Face models requiring remote code cannot operate normally in disconnected environments because the library attempts network access even when offline mode is configured.\"},\"tunes\":{}},{\"id\":\"p-remote-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The practical lesson is to test a model's entire loading path offline before approving it for an isolated deployment. “I downloaded the weights” is not proof that the model is self-contained.\"},\"tunes\":{}},{\"id\":\"h-artifacts\",\"type\":\"header\",\"data\":{\"text\":\"Containers, packages and drivers become local supply-chain artifacts\",\"level\":2},\"tunes\":{}},{\"id\":\"p-artifacts-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Connected environments routinely pull container images, Python packages, OS updates and GPU components from public registries. An air-gapped environment cannot assume any of those services.\"},\"tunes\":{}},{\"id\":\"p-artifacts-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Red Hat's disconnected AI deployment model uses internal mirror registries for container images and operator catalogs. Models can be mirrored as OCI artifacts or transferred to persistent storage.\"},\"tunes\":{}},{\"id\":\"p-artifacts-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For broader stacks, the same pattern often applies to language packages, Linux repositories, JavaScript packages and internal binaries: approved artifacts enter once through the transfer process and are then served from trusted internal repositories.\"},\"tunes\":{}},{\"id\":\"h-bom\",\"type\":\"header\",\"data\":{\"text\":\"Know the complete dependency bill\",\"level\":2},\"tunes\":{}},{\"id\":\"dependency-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Dependency class\",\"Examples\"],[\"Model artifacts\",\"Weights, tokenizer, config, adapters, quantization metadata\"],[\"Inference runtime\",\"vLLM, llama.cpp, Ollama, NIM or other serving runtime\"],[\"GPU\u002Fruntime stack\",\"Drivers, CUDA\u002FROCm libraries, container runtime\"],[\"Application packages\",\"Python wheels, npm packages, system libraries\"],[\"Containers\",\"Application, inference, DB, vector DB, monitoring images\"],[\"RAG models\",\"Embedding model, reranker, OCR\u002Fvision models\"],[\"Data\",\"Knowledge corpus, metadata, schemas, evaluation datasets\"],[\"Security material\",\"Certificates, CA bundles, policy\u002Fconfiguration, malware signatures where applicable\"],[\"Operational artifacts\",\"Dashboards, alert rules, backup tools, runbooks\"],[\"Licensing\",\"Offline-compatible licenses\u002Fentitlements where required\"]]},\"tunes\":{}},{\"id\":\"h-mirror\",\"type\":\"header\",\"data\":{\"text\":\"Internal mirrors are infrastructure, not a convenience\",\"level\":2},\"tunes\":{}},{\"id\":\"p-mirror-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A disconnected deployment becomes maintainable when the isolated domain has known internal sources for approved artifacts.\"},\"tunes\":{}},{\"id\":\"p-mirror-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Red Hat's documented approach uses a mirror registry available to the disconnected cluster so workloads do not need public registries.\"},\"tunes\":{}},{\"id\":\"p-mirror-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The same architectural idea can be applied to model stores and package repositories. The objective is to make artifact origin, version and approval explicit rather than copy random files manually to each server.\"},\"tunes\":{}},{\"id\":\"h-rag\",\"type\":\"header\",\"data\":{\"text\":\"RAG can work fully air-gapped\",\"level\":2},\"tunes\":{}},{\"id\":\"p-rag-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG does not require the public internet. It requires a retrievable corpus, an ingestion\u002Findexing pipeline and a model that can use the retrieved context.\"},\"tunes\":{}},{\"id\":\"p-rag-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Inside an air-gapped environment, the document store, parser\u002FOCR, embedding model, vector or lexical index, reranker and generation model can all run locally.\"},\"tunes\":{}},{\"id\":\"p-rag-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"What changes is source acquisition. Live web search and cloud document connectors are unavailable unless equivalent data is imported through the controlled boundary.\"},\"tunes\":{}},{\"id\":\"p-rag-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"The corpus therefore becomes a governed artifact. Every import should preserve source identity, date\u002Fversion and provenance so users know what knowledge the isolated system actually contains.\"},\"tunes\":{}},{\"id\":\"ref-rag\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\",\"title\":\"What Is RAG? The Simplest Explanation of How It Works\",\"excerpt\":\"RAG itself is independent of cloud hosting. In an air-gapped architecture, retrieval and generation simply have to be supplied by local\u002Finternal components.\",\"ctaLabel\":\"Read the RAG foundation\"},\"tunes\":{}},{\"id\":\"h-agents\",\"type\":\"header\",\"data\":{\"text\":\"Agents can run air-gapped — but only with reachable tools\",\"level\":2},\"tunes\":{}},{\"id\":\"p-agents-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent loop can run entirely inside an isolated enclave if the model\u002Fruntime and required tools are local or reachable on the internal network.\"},\"tunes\":{}},{\"id\":\"p-agents-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A tool that depends on GitHub, public web search, cloud email or an external SaaS API will fail unless the architecture provides an approved internal equivalent or controlled asynchronous exchange process.\"},\"tunes\":{}},{\"id\":\"p-agents-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is why air-gapped agent design should begin with a capability inventory: every tool endpoint must be classified as internal, imported, unavailable or deliberately excluded.\"},\"tunes\":{}},{\"id\":\"h-mcp\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not bypass the air gap\",\"level\":2},\"tunes\":{}},{\"id\":\"p-mcp-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can expose local tools and resources inside an isolated AI environment, but the protocol does not create connectivity through the security boundary.\"},\"tunes\":{}},{\"id\":\"p-mcp-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A local MCP server that reads internal documents can work perfectly offline. A remote MCP server on the public internet cannot be reached from a strict air-gapped enclave.\"},\"tunes\":{}},{\"id\":\"p-mcp-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The same principle applies to any connector protocol: interoperability is separate from network authority.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"Identity and authentication must also work offline\",\"level\":2},\"tunes\":{}},{\"id\":\"p-id-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI application can be locally hosted while still depending on a cloud identity provider. That hidden dependency breaks truly disconnected operation.\"},\"tunes\":{}},{\"id\":\"p-id-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped designs therefore need an identity architecture that functions inside the enclave: local directory, internal identity provider, internal PKI, local service credentials or another approved mechanism.\"},\"tunes\":{}},{\"id\":\"p-id-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Authorization remains necessary even though the internet is absent. Air gaps do not replace RBAC, tenant isolation or least privilege.\"},\"tunes\":{}},{\"id\":\"h-time\",\"type\":\"header\",\"data\":{\"text\":\"Time, certificates and trust stores become local dependencies\",\"level\":2},\"tunes\":{}},{\"id\":\"p-time-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Many authentication and logging systems depend on reliable time. Certificates expire. Trust stores change. Signed artifacts need validation.\"},\"tunes\":{}},{\"id\":\"p-time-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A disconnected enclave should therefore have internal time synchronization and a certificate\u002Ftrust lifecycle that does not depend on reaching public services during ordinary operation.\"},\"tunes\":{}},{\"id\":\"p-time-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"These are ordinary infrastructure concerns that become visible only when an architecture is tested without internet access.\"},\"tunes\":{}},{\"id\":\"h-telemetry\",\"type\":\"header\",\"data\":{\"text\":\"Telemetry and crash reporting need explicit policy\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tel-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Many modern libraries attempt analytics, update checks or error reporting by default.\"},\"tunes\":{}},{\"id\":\"p-tel-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"In an isolated environment those calls should either be disabled or redirected to internal observability. Repeated failed telemetry attempts can create delays, noisy logs and unexpected startup behavior.\"},\"tunes\":{}},{\"id\":\"p-tel-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air-gapped deployment should know which components attempt egress even if the firewall would block them.\"},\"tunes\":{}},{\"id\":\"h-updates\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped systems still need patches\",\"level\":2},\"tunes\":{}},{\"id\":\"p-update-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Network isolation does not stop software from developing vulnerabilities. It only changes how patches reach the system.\"},\"tunes\":{}},{\"id\":\"p-update-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST frames patch management as preventive maintenance: organizations still need to identify, acquire, prioritize, install and verify patches and updates.\"},\"tunes\":{}},{\"id\":\"p-update-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped operations therefore need a repeatable import cadence for OS packages, container images, drivers, AI runtimes and security updates. The trade-off is between isolation stability and vulnerability exposure from stale software.\"},\"tunes\":{}},{\"id\":\"h-patch-flow\",\"type\":\"header\",\"data\":{\"text\":\"A controlled update path\",\"level\":2},\"tunes\":{}},{\"id\":\"patch-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Example update lifecycle for an isolated AI environment\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Identify required update\",\"description\":\"Security advisory, model\u002Fruntime improvement or operational need triggers change.\"},{\"label\":\"2. Acquire in connected staging\",\"description\":\"Download exact versions plus signatures\u002Fchecksums and metadata.\"},{\"label\":\"3. Validate supply-chain evidence\",\"description\":\"Verify source, integrity, compatibility and policy requirements.\"},{\"label\":\"4. Test in representative offline staging\",\"description\":\"Confirm the update works without unexpected network dependencies.\"},{\"label\":\"5. Approve transfer\",\"description\":\"Apply the organization's change and security process.\"},{\"label\":\"6. Import into enclave repository\",\"description\":\"Publish the artifact to the internal trusted source.\"},{\"label\":\"7. Deploy gradually\",\"description\":\"Apply to test\u002Fcanary nodes before wider rollout where architecture permits.\"},{\"label\":\"8. Verify and record\",\"description\":\"Confirm version, health, behavior and rollback state.\"}]},\"tunes\":{}},{\"id\":\"h-transfer\",\"type\":\"header\",\"data\":{\"text\":\"The transfer boundary is the most sensitive operational interface\",\"level\":2},\"tunes\":{}},{\"id\":\"p-transfer-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"If external information must enter an air-gapped system, the import channel becomes a major security control point.\"},\"tunes\":{}},{\"id\":\"p-transfer-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The NSA Cybersecurity Technical Cyber Threat Framework explicitly recognizes replication through removable media as a path adversaries can use to cross into disconnected or air-gapped networks.\"},\"tunes\":{}},{\"id\":\"p-transfer-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That is why controlled media handling, inspection, provenance, encryption where required, malware scanning and role separation can matter as much as the AI stack itself.\"},\"tunes\":{}},{\"id\":\"h-media\",\"type\":\"header\",\"data\":{\"text\":\"Removable media is not a neutral pipe\",\"level\":2},\"tunes\":{}},{\"id\":\"p-media-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"USB drives and other portable media can carry both legitimate model\u002Fdata artifacts and malicious content.\"},\"tunes\":{}},{\"id\":\"p-media-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST's media-sanitization guidance treats storage media as a confidentiality lifecycle object that may require clearing, purging or destruction according to sensitivity and reuse needs.\"},\"tunes\":{}},{\"id\":\"p-media-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The exact transfer procedure is organization-specific, but the architectural principle is stable: cross-boundary media should be governed as a security asset, not treated as an informal convenience.\"},\"tunes\":{}},{\"id\":\"h-supply\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapping increases supply-chain importance\",\"level\":2},\"tunes\":{}},{\"id\":\"p-supply-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An isolated system receives fewer live external inputs, but every imported binary, model, container and package becomes more consequential because the enclave may trust it for a long time.\"},\"tunes\":{}},{\"id\":\"p-supply-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST software-supply-chain guidance emphasizes provenance, supplier risk, vulnerability management, software verification and SBOM-oriented practices. These concerns become directly relevant to offline AI artifact import.\"},\"tunes\":{}},{\"id\":\"p-supply-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model supply chain deserves the same attention as application supply chain: model origin, license, hash, format, required code, tokenizer, adapters and evaluation status should be known before import.\"},\"tunes\":{}},{\"id\":\"h-readiness\",\"type\":\"header\",\"data\":{\"text\":\"Air-gap readiness should be tested, not assumed\",\"level\":2},\"tunes\":{}},{\"id\":\"readiness-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Proposed validation pattern\",\"body\":\"The following air-gap-readiness test is an engineering synthesis, not a NIST or vendor certification method. It is designed to expose hidden external dependencies before deployment.\"},\"tunes\":{}},{\"id\":\"readiness-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Test\",\"What it proves\"],[\"Cold start with all outbound network blocked\",\"Runtime does not require public services during startup\"],[\"Load every approved model from local storage\",\"Weights\u002Ftokenizers\u002Fconfigs are complete\"],[\"Rebuild\u002Fredeploy from internal registries only\",\"Container\u002Fpackage mirrors are sufficient\"],[\"Authenticate users while external IdP is unreachable\",\"Identity works inside the enclave\"],[\"Run RAG ingestion and query offline\",\"Embedding\u002Findexing\u002Fretrieval stack is local\"],[\"Run representative agent tools\",\"Tools do not depend on external APIs\"],[\"Restart after cache deletion\",\"Offline operation is not accidentally relying on previously cached downloads\"],[\"Advance simulated certificate\u002Fupdate lifecycle\",\"Trust and maintenance dependencies are understood\"],[\"Import a new model through staging path\",\"Transfer\u002Fchange procedure is operational\"],[\"Restore from backup\",\"Recovery does not require unavailable cloud storage\"]]},\"tunes\":{}},{\"id\":\"h-cache\",\"type\":\"header\",\"data\":{\"text\":\"Cached once is not the same as air-gap ready\",\"level\":2},\"tunes\":{}},{\"id\":\"p-cache-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A system may appear offline because the model and packages are already cached from earlier internet access.\"},\"tunes\":{}},{\"id\":\"p-cache-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Deleting caches or deploying to a clean node can reveal missing tokenizer files, Python packages, model manifests or remote-code dependencies.\"},\"tunes\":{}},{\"id\":\"p-cache-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gap readiness should therefore be validated from clean internal artifacts, not only from a developer workstation that was previously connected.\"},\"tunes\":{}},{\"id\":\"h-threats\",\"type\":\"header\",\"data\":{\"text\":\"What threats remain inside an air gap?\",\"level\":2},\"tunes\":{}},{\"id\":\"threat-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Threat\",\"Why the air gap does not remove it\"],[\"Compromised imported artifact\",\"Malware\u002Fmodel\u002Fpackage can enter through the authorized transfer path\"],[\"Malicious removable media\",\"Physical transfer can carry executable payloads\"],[\"Insider misuse\",\"Authorized users already exist inside the enclave\"],[\"Prompt injection in imported documents\",\"Untrusted content can influence RAG\u002Fagents without internet\"],[\"Overprivileged agent tools\",\"Local tools can still damage local systems\"],[\"Cross-tenant data leakage\",\"Internal authorization bugs remain possible\"],[\"Vulnerable internal software\",\"Lack of external connection does not remove exploitable bugs\"],[\"Lateral movement\",\"A compromised node can attack other internally connected nodes\"],[\"Stale dependencies\",\"Slow update cadence can leave known vulnerabilities unpatched\"],[\"Physical theft\u002Ftampering\",\"Hardware and media security remain critical\"],[\"Bad model behavior\",\"Hallucination, bias and task failure are independent of networking\"],[\"Supply-chain poisoning\",\"Trusted import sources can still be compromised\"]]},\"tunes\":{}},{\"id\":\"h-benefits\",\"type\":\"header\",\"data\":{\"text\":\"What an air gap actually improves\",\"level\":2},\"tunes\":{}},{\"id\":\"p-benefit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A genuine air gap can materially reduce attack paths that depend on direct remote connectivity: external command-and-control, cloud credential misuse, internet-facing service exploitation and accidental data exfiltration through ordinary outbound APIs.\"},\"tunes\":{}},{\"id\":\"p-benefit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"It also makes data residency simple in one narrow sense: inference data cannot be sent to an external cloud service if no path exists.\"},\"tunes\":{}},{\"id\":\"p-benefit-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Those benefits are strongest when the transfer boundary and internal access controls are equally disciplined. A poorly managed USB process can undermine the intended isolation.\"},\"tunes\":{}},{\"id\":\"h-costs\",\"type\":\"header\",\"data\":{\"text\":\"What an air gap makes harder\",\"level\":2},\"tunes\":{}},{\"id\":\"cost-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Area\",\"Operational consequence\"],[\"Model updates\",\"Manual\u002Fstaged transfer instead of direct model-hub pull\"],[\"Security patches\",\"Delayed and governed import workflow\"],[\"Package installation\",\"Internal mirrors or prebuilt artifacts required\"],[\"Cloud AI APIs\",\"Unavailable\"],[\"Web search\u002Fconnectors\",\"Unavailable unless data is imported separately\"],[\"Authentication\",\"Needs internal\u002Foffline-capable identity services\"],[\"Monitoring\",\"Needs internal observability and controlled export\"],[\"Licensing\",\"Products requiring online activation may be unsuitable\"],[\"Troubleshooting\",\"No easy live access to vendor resources from production enclave\"],[\"Capacity\",\"All inference compute must exist locally\"],[\"Disaster recovery\",\"Cloud backups may be unavailable or policy-restricted\"],[\"Knowledge freshness\",\"External information arrives only as fast as the import process\"]]},\"tunes\":{}},{\"id\":\"h-private\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI vs private AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-private-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Private AI is primarily about controlling sensitive data and AI processing. A private AI platform may be on-premises and still access approved cloud models or external services.\"},\"tunes\":{}},{\"id\":\"p-private-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is stricter on connectivity. A system can be private without being air-gapped, and an air-gapped system can still have poor privacy if every internal user has unrestricted access.\"},\"tunes\":{}},{\"id\":\"p-private-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The security objective should determine the architecture: confidentiality, sovereignty, resilience and isolation are related but distinct requirements.\"},\"tunes\":{}},{\"id\":\"h-sovereign\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI vs sovereign AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sovereign-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereign AI concerns control over the broader dependency chain: data, models, infrastructure, operators, jurisdiction and strategic dependencies.\"},\"tunes\":{}},{\"id\":\"p-sovereign-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air gap can support sovereignty by reducing external runtime dependency, but it does not guarantee sovereign control. The enclave may still depend on foreign hardware, proprietary model licenses or external update suppliers.\"},\"tunes\":{}},{\"id\":\"p-sovereign-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The next canonical article separates those control dimensions explicitly.\"},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence: what the Aaasaasa AI Client proves — and what it does not\",\"level\":2},\"tunes\":{}},{\"id\":\"impl-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Implementation boundary\",\"body\":\"Aaasaasa AI Client is useful evidence for \u003Cstrong>local inference architecture\u003C\u002Fstrong>, provider abstraction and separation of runtime\u002Fmodel location. It is \u003Cstrong>not evidence of a deployed air-gapped environment\u003C\u002Fstrong>. The repository also supports cloud and remote paths, and no verified project evidence establishes a physically isolated security domain.\"},\"tunes\":{}},{\"id\":\"p-impl-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The AI Hub separates agent\u002Fclient, provider, model and connection location. It supports local Ollama inference and local-provider Codex operation as distinct choices rather than assuming that every AI request goes to a cloud model.\"},\"tunes\":{}},{\"id\":\"p-impl-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The repository explicitly notes that a local runtime can still use a cloud model, while Direct Ollama chat is local inference. This distinction is directly relevant to air-gap architecture: local execution does not prove that the model or surrounding dependencies are disconnected.\"},\"tunes\":{}},{\"id\":\"p-impl-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction, local model discovery and local inference are therefore building blocks for an air-gap-capable product architecture, but the network boundary, offline dependency mirror, controlled transfer process and offline identity\u002Foperations must still be engineered separately.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Verified project capability\",\"Air-gap relevance\"],[\"Local Ollama inference\",\"Supports local model execution\"],[\"Local provider\u002Fruntime paths\",\"Reduces dependency on cloud inference\"],[\"Provider\u002Fmodel\u002Fruntime separation\",\"Makes cloud dependencies explicit rather than hidden\"],[\"Central permissions\",\"Supports local tool\u002Fdata access control\"],[\"Cloud\u002Fremote provider support also exists\",\"Proves the product itself is hybrid-capable, not inherently air-gapped\"],[\"No verified isolated deployment boundary\",\"Prevents overclaiming air-gap maturity\"]]},\"tunes\":{}},{\"id\":\"h-when\",\"type\":\"header\",\"data\":{\"text\":\"When is air-gapped AI justified?\",\"level\":2},\"tunes\":{}},{\"id\":\"when-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Air gap may be justified when\",\"A connected private architecture may be better when\"],[\"Security policy explicitly requires physically separated domains\",\"Main requirement is only that prompts\u002Fdata are not used by public consumer services\"],[\"Classified or extremely sensitive data cannot cross external networks\",\"Approved enterprise cloud\u002Fprivate endpoints satisfy data controls\"],[\"Operational environment has no reliable external connectivity\",\"Internet is available and operational agility matters\"],[\"Mission continuity must not depend on cloud\u002Fprovider availability\",\"Managed model quality and rapid upgrades are more valuable\"],[\"Regulated\u002Fcritical environment mandates controlled transfer\",\"Standard security controls can meet the actual threat model\"],[\"External SaaS\u002FAPI access is prohibited\",\"Business workflow relies heavily on external connectors\"]]},\"tunes\":{}},{\"id\":\"p-when-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapping should be a requirement derived from a threat model or policy, not a prestige feature. It has real security value when the eliminated connectivity path is itself unacceptable.\"},\"tunes\":{}},{\"id\":\"p-when-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"For many enterprise use cases, a tightly controlled private network with egress restrictions, local inference and approved update channels may provide a better balance of security and maintainability than a strict physical air gap.\"},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical air-gapped AI design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design from the boundary inward\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define what the air gap separates\",\"description\":\"Name the security domains and whether the requirement is strict physical separation or simply no internet.\"},{\"label\":\"2. Inventory every external dependency\",\"description\":\"Models, packages, registries, identity, telemetry, licensing, storage, APIs, DNS\u002Ftime and support services.\"},{\"label\":\"3. Select offline-capable models and runtimes\",\"description\":\"Verify model assets and runtime code can load without remote calls.\"},{\"label\":\"4. Build internal artifact repositories\",\"description\":\"Create trusted sources for containers, packages, models and updates.\"},{\"label\":\"5. Design controlled transfer\",\"description\":\"Define staging, verification, media\u002Fgateway handling, approval and provenance.\"},{\"label\":\"6. Build internal identity and authorization\",\"description\":\"Ensure users, services and tools can authenticate without cloud dependencies.\"},{\"label\":\"7. Keep RAG and tools local\",\"description\":\"Deploy knowledge, embeddings, indexes and required service APIs inside the enclave.\"},{\"label\":\"8. Build internal observability\",\"description\":\"Operate logs, metrics, traces and security monitoring locally.\"},{\"label\":\"9. Define patch\u002Fmodel update cadence\",\"description\":\"Balance vulnerability response with the controlled import process.\"},{\"label\":\"10. Test from a clean disconnected state\",\"description\":\"Cold-start and operate without inherited caches or hidden internet access.\"},{\"label\":\"11. Test compromise paths\",\"description\":\"Exercise removable-media, supply-chain, prompt-injection, insider and lateral-movement scenarios.\"},{\"label\":\"12. Document exceptions and exports\",\"description\":\"Every permitted cross-boundary path should have a named purpose, owner and control set.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"What exactly is isolated from what?\",\"Documented security-domain boundary\"],[\"Is the boundary physically disconnected?\",\"Network\u002Fphysical architecture evidence if strict air gap is claimed\"],[\"How does data cross the boundary?\",\"Authorized non-automated\u002Fmanual or explicitly documented disconnected workflow\"],[\"Can every model cold-start offline?\",\"Offline loading test\"],[\"Are tokenizer\u002Fconfig\u002Fruntime assets complete?\",\"Verified internal model bundle\"],[\"Where do containers\u002Fpackages come from?\",\"Internal trusted mirror\u002Frepository\"],[\"Can identity work without cloud services?\",\"Internal IdP\u002FPKI\u002Fservice credential path\"],[\"Can RAG ingest\u002Fquery offline?\",\"Local ingestion, embeddings, index and retrieval\"],[\"Which agent tools remain available?\",\"Internal capability inventory\"],[\"How are patches imported?\",\"Controlled maintenance process\"],[\"How are artifacts verified?\",\"Integrity\u002Fprovenance\u002Fmalware\u002Fsupply-chain controls\"],[\"How is removable media governed?\",\"Media handling and sanitization policy\"],[\"Can the system run after caches are cleared?\",\"Clean-environment offline test\"],[\"Where are logs and traces stored?\",\"Internal observability platform\"],[\"How are exports approved?\",\"Controlled egress process\"],[\"What proves this is air-gapped rather than merely local?\",\"Boundary and transfer evidence, not model location\"]]},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common air-gapped AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failure-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"What actually failed\"],[\"Local model still downloads tokenizer\u002Fconfig at startup\",\"Model bundle was incomplete\"],[\"Container references public registry\",\"Deployment was not self-contained\"],[\"Cloud identity required for login\",\"Application was local but identity was not\"],[\"License server required externally\",\"Vendor dependency contradicted offline operation\"],[\"Embedding model missing\",\"Chat works but RAG ingestion fails\"],[\"Agent tool calls public SaaS\",\"Agent architecture was not air-gap compatible\"],[\"Only GPU node is isolated\",\"Database, UI or monitoring still depends on external services\"],[\"USB imports are informal\",\"Transfer boundary becomes uncontrolled attack path\"],[\"No patch process\",\"Isolation creates growing vulnerability debt\"],[\"Cached developer machine used as proof\",\"Fresh deployment fails without internet\"],[\"Air gap replaces authorization thinking\",\"Internal users\u002Fservices become overprivileged\"],[\"Air-gapped label used for firewall-only egress block\",\"Security documentation overstates the actual boundary\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“Local AI is air-gapped AI.”\",\"Local describes where inference runs; air gap describes the security\u002Fnetwork boundary.\"],[\"“Air-gapped means one standalone PC.”\",\"An isolated enclave can contain an entire internal network or cluster.\"],[\"“No internet equals strict air gap.”\",\"Under NIST's definition, the separated systems also lack physical connection and cross-boundary transfer is non-automated.\"],[\"“Air gaps eliminate cyber risk.”\",\"Supply-chain, removable-media, insider, internal-network and application risks remain.\"],[\"“RAG needs the cloud.”\",\"RAG can run entirely with local models, indexes and data.\"],[\"“Agents cannot work offline.”\",\"Agents can use internal\u002Flocal tools; they simply cannot reach unavailable external services.\"],[\"“Once installed, the system needs no updates.”\",\"Patches, drivers, models and dependencies still require lifecycle management.\"],[\"“A downloaded model is self-contained.”\",\"Tokenizers, remote code, libraries or model assets may still trigger network dependencies.\"],[\"“Private AI and air-gapped AI are identical.”\",\"Private AI is a data\u002Fcontrol property; air gap is a connectivity property.\"],[\"“Air gap guarantees sovereignty.”\",\"External hardware, licenses, models and supply chain can remain dependencies.\"]]},\"tunes\":{}},{\"id\":\"h-limitations\",\"type\":\"header\",\"data\":{\"text\":\"Limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-limit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Strict air gaps make external knowledge freshness slower because every new source must pass through a transfer process.\"},\"tunes\":{}},{\"id\":\"p-limit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"They can constrain model choice when licenses, remote-code requirements, hardware needs or provider-only APIs cannot be satisfied offline.\"},\"tunes\":{}},{\"id\":\"p-limit-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"They increase operational cost because infrastructure normally consumed as cloud services must be owned and maintained internally.\"},\"tunes\":{}},{\"id\":\"p-limit-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"They can also create patch latency: stronger change control may keep systems stable while delaying urgent vulnerability remediation.\"},\"tunes\":{}},{\"id\":\"p-limit-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI should therefore be evaluated as one security architecture among several, not assumed to be universally superior.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Vendor support for disconnected operation changes quickly. New model formats, signed OCI artifacts, offline license mechanisms and integrated model registries can reduce operational friction.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The distinction between strict air gap and disconnected deployment will remain important even if vendors continue using the terms loosely.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The stable principle is that genuine air-gap claims depend on the system boundary and transfer mechanism, not on whether the LLM happens to run locally.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-Gapped AI is a deployment\u002Fsecurity architecture node. Private AI, Sovereign AI and provider abstraction answer different questions about confidentiality, control and dependency.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MLOps\u002FLLMOps becomes more demanding inside a disconnected environment because model, package and update lifecycles must operate through internal repositories and controlled transfer.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG and Agentic AI remain valid patterns inside the enclave as long as their data and tools are internally available.\"},\"tunes\":{}},{\"id\":\"ref-memory\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\",\"title\":\"AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context\",\"excerpt\":\"Air-gapped AI still needs correct internal boundaries between durable memory, authoritative state, retrieval and model context.\",\"ctaLabel\":\"Read the memory architecture article\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Air-gapped AI FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is air-gapped AI?\",\"answer\":\"Air-gapped AI is AI deployed inside a security domain physically disconnected from the external systems it is separated from, with cross-boundary transfer performed through controlled non-automated procedures under the strict NIST definition.\"},{\"id\":\"faq2\",\"question\":\"Does air-gapped AI need internet access?\",\"answer\":\"No for normal inference and operation. Required models, packages, data and services must be available inside the isolated environment.\"},{\"id\":\"faq3\",\"question\":\"Is a local LLM automatically air-gapped?\",\"answer\":\"No. A local model can run on a machine that still has internet access or uses cloud identity, tools or storage. Air gap describes the complete system boundary.\"},{\"id\":\"faq4\",\"question\":\"Can RAG work in an air-gapped network?\",\"answer\":\"Yes. Documents, embedding models, vector or lexical indexes, rerankers and generation models can all run locally. External knowledge must be imported through the controlled boundary.\"},{\"id\":\"faq5\",\"question\":\"Can AI agents work air-gapped?\",\"answer\":\"Yes, if their tools and required systems are available inside the isolated network. Public SaaS and cloud APIs are unavailable without a permitted cross-boundary mechanism.\"},{\"id\":\"faq6\",\"question\":\"How are models updated in an air-gapped environment?\",\"answer\":\"Models are typically acquired and validated in a connected staging environment, transferred through an approved process and published to an internal model\u002Fartifact repository.\"},{\"id\":\"faq7\",\"question\":\"Is on-premises AI the same as air-gapped AI?\",\"answer\":\"No. On-premises describes infrastructure location. On-prem systems can remain internet-connected.\"},{\"id\":\"faq8\",\"question\":\"Is private AI the same as air-gapped AI?\",\"answer\":\"No. Private AI is about data\u002Fcontrol requirements and can still use connected infrastructure. Air gap specifically describes network\u002Fdomain separation.\"},{\"id\":\"faq9\",\"question\":\"Does an air gap make AI secure?\",\"answer\":\"It removes or reduces some remote connectivity risks but does not remove supply-chain, removable-media, insider, internal authorization, physical or model-behavior risks.\"},{\"id\":\"faq10\",\"question\":\"What is the best test for air-gap readiness?\",\"answer\":\"Deploy or cold-start the full stack in a clean environment with all external connectivity unavailable and verify that models, identity, RAG, tools, monitoring, updates and recovery depend only on approved internal artifacts and services.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key air-gapped AI terms\",\"entries\":[{\"term\":\"Air gap\",\"definition\":\"Security-domain interface where systems are not physically connected and any cross-boundary logical transfer is non-automated\u002Fmanual under the NIST glossary definition.\",\"anchor\":\"air-gap\"},{\"term\":\"Air-gapped AI\",\"definition\":\"AI system deployed inside an air-gapped security domain with locally available inference and operational dependencies.\",\"anchor\":\"air-gapped-ai\"},{\"term\":\"Disconnected environment\",\"definition\":\"Deployment environment without direct outside-internet access; implementations may use controlled mirror or bastion workflows.\",\"anchor\":\"disconnected-environment\"},{\"term\":\"Offline-capable AI\",\"definition\":\"AI application able to operate for some or all functions without internet connectivity, without necessarily being permanently isolated.\",\"anchor\":\"offline-capable-ai\"},{\"term\":\"Local AI\",\"definition\":\"AI inference or runtime executing on local hardware rather than a remote model endpoint; does not imply network isolation.\",\"anchor\":\"local-ai\"},{\"term\":\"Mirror registry\",\"definition\":\"Internal repository containing approved copies of container images or other artifacts needed by a disconnected deployment.\",\"anchor\":\"mirror-registry\"},{\"term\":\"Staging environment\",\"definition\":\"Connected or controlled zone where artifacts are acquired, verified and prepared before transfer into an isolated domain.\",\"anchor\":\"staging-environment\"},{\"term\":\"Controlled transfer\",\"definition\":\"Governed movement of data or software across the isolation boundary using approved media\u002Fprocesses and verification.\",\"anchor\":\"controlled-transfer\"},{\"term\":\"Artifact provenance\",\"definition\":\"Information showing where a model, package, container or other imported artifact originated and how it was produced or verified.\",\"anchor\":\"artifact-provenance\"},{\"term\":\"Removable media\",\"definition\":\"Portable storage used to transfer data between systems; a potential security path across disconnected domains.\",\"anchor\":\"removable-media\"},{\"term\":\"Internal model store\",\"definition\":\"Repository inside the isolated environment from which approved model artifacts are served or deployed.\",\"anchor\":\"internal-model-store\"},{\"term\":\"Air-gap readiness\",\"definition\":\"Demonstrated ability of the complete AI stack to install, start, operate, update and recover without unapproved external connectivity.\",\"anchor\":\"air-gap-readiness\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is not a special kind of model. It is an AI architecture operating inside a deliberately isolated security domain.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The model can be the easy part. Production readiness depends on whether every surrounding dependency — model assets, packages, registries, identity, RAG, tools, monitoring, updates and recovery — can function without an automated external path.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The shortest reliable rule is: local inference proves where the model runs; air-gap evidence proves how the complete system is separated and how every permitted transfer crosses that boundary.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current implementation references\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"The sources below establish the security definition, current disconnected AI deployment patterns and lifecycle risks. Vendor use of “air-gapped” is intentionally distinguished from the stricter NIST definition.\"},\"tunes\":{}},{\"id\":\"src-nist-airgap\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fair_gap\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST CSRC — Air gap\",\"description\":\"NIST glossary definition: physically disconnected systems with non-automated, manually controlled logical transfer across the boundary.\"}},\"tunes\":{}},{\"id\":\"src-nvidia-airgap\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.nvidia.com\u002Fnim\u002Flarge-language-models\u002Flatest\u002Fdeploy-air-gap.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NVIDIA NIM — Air-Gap Deployment\",\"description\":\"Current operational guidance for staging model assets on a connected system and running NIM from local storage without internet, public registries or cloud API keys.\"}},\"tunes\":{}},{\"id\":\"src-redhat-disconnected\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Findex\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Red Hat AI Inference — Disconnected deployment\",\"description\":\"Current Red Hat guidance for serving LLMs in disconnected environments with mirrored artifacts and internal infrastructure.\"}},\"tunes\":{}},{\"id\":\"src-redhat-models\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Fstoring-models-in-disconnected-environments_disconnected-deploy\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Red Hat AI Inference — Storing models in disconnected environments\",\"description\":\"Current guidance covering OCI model images, persistent model storage and limitations of models requiring remote code.\"}},\"tunes\":{}},{\"id\":\"src-nsa-framework\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nsa.gov\u002Fportals\u002F75\u002Fdocuments\u002Fwhat-we-do\u002Fcybersecurity\u002Fprofessional-resources\u002Fctr-nsa-css-technical-cyber-threat-framework.pdf\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NSA — Technical Cyber Threat Framework\",\"description\":\"Threat framework explicitly identifying removable-media replication as a path into disconnected or air-gapped networks.\"}},\"tunes\":{}},{\"id\":\"src-nist-media\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fguidelines-media-sanitization\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitization\",\"description\":\"Guidance for managing and sanitizing storage media according to information confidentiality requirements.\"}},\"tunes\":{}},{\"id\":\"src-nist-patch\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F40\u002Fr4\u002Ffinal\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST SP 800-40 Rev. 4 — Enterprise Patch Management Planning\",\"description\":\"Guidance framing patching and updates as preventive maintenance across enterprise systems.\"}},\"tunes\":{}},{\"id\":\"src-nist-supply\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-security-supply-chains\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST — Software Security in Supply Chains\",\"description\":\"NIST guidance covering software supply-chain risk, provenance, verification, SBOM-related practices and vulnerability management.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":212,"blocks":213,"version":1684},1791495428517,[214,220,228,235,241,248,256,261,266,271,276,281,286,291,296,301,333,338,343,348,353,358,396,401,406,411,446,453,458,496,501,506,511,516,521,526,531,536,541,546,551,556,561,566,571,609,614,619,624,629,634,639,644,649,654,663,668,673,678,683,688,693,698,703,708,713,718,723,728,733,738,743,748,753,758,763,768,773,778,783,788,818,823,828,833,838,843,848,853,858,863,868,873,878,883,889,927,932,937,942,947,952,996,1001,1006,1011,1016,1021,1064,1069,1074,1079,1084,1089,1094,1099,1104,1109,1115,1120,1125,1130,1156,1161,1187,1192,1197,1202,1244,1249,1305,1310,1354,1359,1397,1402,1407,1412,1417,1422,1427,1432,1437,1442,1447,1452,1457,1462,1467,1475,1480,1526,1531,1581,1586,1591,1596,1601,1606,1611,1621,1630,1639,1648,1657,1666,1675],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"Air-gapped AI is an AI system deployed inside a security domain that has no physical network connection to the external systems it is separated from, with any transfer across that boundary performed through deliberately controlled, non-automated procedures. The AI model, runtime, data, retrieval indexes, tools and operational dependencies required for inference must therefore be available inside the isolated environment. Air-gapped AI is not simply “a local model” or “an on-premise server”: the defining property is the network and transfer boundary around the complete system.","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"An air-gapped AI system can run LLM inference, RAG, document analysis and even agentic workflows without internet or cloud APIs if every required dependency is available inside the isolated domain.\u003Cbr>\u003Cbr>A practical architecture is:\u003Cbr>\u003Cstrong>controlled import → internal artifact\u002Fmodel repositories → local AI runtime → local data\u002FRAG → local tools → internal users\u002Fservices → local monitoring\u002Faudit\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The difficult part is not making one LLM answer offline. It is operating the whole AI lifecycle — updates, models, drivers, packages, data imports, credentials, logging and security — without silently depending on external services.","Direct answer","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"nist-boundary",{"body":231,"title":232,"variant":233},"NIST's cybersecurity glossary defines an air gap as an interface where two systems are \u003Cstrong>not physically connected\u003C\u002Fstrong> and where any logical transfer is \u003Cstrong>not automated\u003C\u002Fstrong>; data crosses only manually under human control. Vendor documentation sometimes uses “air-gapped” or “disconnected” more broadly for environments with no outside-internet connection but with internal networking and controlled staging infrastructure. Architecture documentation should state which meaning is actually implemented.","Air gap has a stricter meaning than “no internet”","warning",{},{"id":236,"data":237,"type":226,"tunes":240},"not-security",{"body":238,"title":239,"variant":233},"Removing direct network connectivity eliminates many remote paths, but it does not eliminate malicious removable media, compromised software\u002Fmodel imports, insider threats, vulnerable internal services, physical compromise, prompt injection through imported documents or lateral movement inside the isolated network.","Air-gapped does not mean secure by definition",{},{"id":242,"data":243,"type":226,"tunes":247},"current",{"body":244,"title":245,"variant":246},"Current NVIDIA NIM and Red Hat AI Inference documentation both support LLM serving without outside-internet access by pre-staging model and container assets. NVIDIA documents a connected preparation phase followed by an isolated execution phase with local assets and no cloud registry credentials. Red Hat uses mirrored container\u002Fmodel repositories for disconnected OpenShift environments. These are useful implementation examples, but they do not override the stricter NIST definition of an air gap.","Current-source note — 8 October 2026","note",{},{"id":249,"data":250,"type":254,"tunes":255},"toc",{"title":251,"maxLevel":252,"minLevel":253},"Contents",3,2,"tableOfContents",{},{"id":257,"data":258,"type":42,"tunes":260},"h-meaning",{"text":259,"level":253},"What air-gapped AI really means",{},{"id":262,"data":263,"type":218,"tunes":265},"p-meaning-1",{"text":264},"The word AI does not change the basic security concept. An air gap is a boundary between security domains. AI simply makes the isolated side more operationally demanding because modern AI stacks normally assume downloadable models, package registries, telemetry, APIs, model hubs and frequent software updates.",{},{"id":267,"data":268,"type":218,"tunes":270},"p-meaning-2",{"text":269},"The isolated environment can still contain many connected machines. An internal cluster may have GPUs, application servers, storage, databases, identity services and monitoring connected to each other. The air gap exists between that enclave and the outside domain.",{},{"id":272,"data":273,"type":218,"tunes":275},"p-meaning-3",{"text":274},"The relevant question is therefore not “Does this GPU have Wi-Fi?” but “Can this AI environment exchange information with the external domain through an automated physical or logical path?”",{},{"id":277,"data":278,"type":42,"tunes":280},"h-simple",{"text":279,"level":253},"The simplest example",{},{"id":282,"data":283,"type":218,"tunes":285},"p-simple-1",{"text":284},"Imagine a company wants an internal assistant for confidential technical documents, but the environment is not permitted to send those documents to the internet.",{},{"id":287,"data":288,"type":218,"tunes":290},"p-simple-2",{"text":289},"The company downloads an approved LLM, embedding model, container images and software packages in a connected staging environment. After validation, approved artifacts are transferred into the isolated environment.",{},{"id":292,"data":293,"type":218,"tunes":295},"p-simple-3",{"text":294},"Inside the enclave, the model server, document parser, vector database, application and identity services run locally. Users can ask questions and use RAG against internal documents without a cloud model or public model registry.",{},{"id":297,"data":298,"type":218,"tunes":300},"p-simple-4",{"text":299},"When an update is required, the update passes through the controlled import process again rather than being downloaded directly by the production AI server.",{},{"id":302,"data":303,"type":331,"tunes":332},"simple-flow",{"steps":304,"title":329,"orientation":330},[305,308,311,314,317,320,323,326],{"label":306,"description":307},"1. Acquire outside the enclave","Download approved models, packages, containers, drivers, signatures and documentation in a connected staging environment.",{"label":309,"description":310},"2. Verify before transfer","Check provenance, signatures\u002Fchecksums, malware status, licensing and compatibility according to organizational policy.",{"label":312,"description":313},"3. Transfer through controlled boundary","Move approved artifacts using the authorized manual or mediated process.",{"label":315,"description":316},"4. Publish internally","Place artifacts in internal model, container, package or file repositories.",{"label":318,"description":319},"5. Deploy locally","Run inference, RAG, applications and tools without external dependencies.",{"label":321,"description":322},"6. Monitor inside the enclave","Collect logs, metrics, model\u002Fruntime status and security events locally.",{"label":324,"description":325},"7. Export only approved evidence","Move selected reports or artifacts outward through the reverse controlled process where policy permits.",{"label":327,"description":328},"8. Repeat for updates","Treat new models, patches, corpora and dependencies as new supply-chain imports.","A basic air-gapped AI operating cycle","auto","processFlow",{},{"id":334,"data":335,"type":42,"tunes":337},"h-stops",{"text":336,"level":253},"Where the simple example stops",{},{"id":339,"data":340,"type":218,"tunes":342},"p-stops-1",{"text":341},"A production air-gapped environment can be much larger than one workstation. It may include Kubernetes\u002FOpenShift, internal registries, object storage, identity providers, vector databases, observability, backup infrastructure and several model-serving nodes.",{},{"id":344,"data":345,"type":218,"tunes":347},"p-stops-2",{"text":346},"The more services exist inside the enclave, the more the organization must reproduce capabilities that connected environments normally consume from the internet.",{},{"id":349,"data":350,"type":218,"tunes":352},"p-stops-3",{"text":351},"Air-gapping therefore shifts complexity. It reduces direct external connectivity but increases artifact-management, patching, dependency, supply-chain and operational responsibility inside the isolated domain.",{},{"id":354,"data":355,"type":42,"tunes":357},"h-terms",{"text":356,"level":253},"Air-gapped vs offline vs local vs on-premises vs private vs sovereign AI",{},{"id":359,"data":360,"type":394,"tunes":395},"terms-table",{"content":361,"stretched":43,"withHeadings":14},[362,366,370,374,378,382,386,390],[363,364,365],"Term","What it primarily describes","Internet\u002Fexternal connectivity required?",[367,368,369],"Local AI","Inference\u002Fruntime runs on local hardware","No; but it may still call cloud services",[371,372,373],"Offline-capable AI","Can continue operating without internet","No during offline operation; reconnection may be normal",[375,376,377],"Disconnected environment","No direct external-internet path from deployment environment","Usually no; may use controlled mirrors\u002Fbastions",[379,380,381],"On-premises AI","Infrastructure runs in an organization's own\u002Fon-prem environment","Could still have full internet connectivity",[383,384,385],"Private AI","AI processing is controlled to meet privacy\u002Fconfidentiality requirements","Architecture-specific; can be connected or disconnected",[387,388,389],"Air-gapped AI","Security domains are physically disconnected and cross-boundary transfer is non-automated\u002Fmanual under strict definition","No automated external path",[391,392,393],"Sovereign AI","Control\u002Fjurisdiction over models, data, infrastructure and dependencies","Not necessarily; sovereignty is broader than network isolation","table",{},{"id":397,"data":398,"type":218,"tunes":400},"p-terms-1",{"text":399},"These terms can overlap but are not synonyms. A local Ollama server connected to the internet is local AI, not air-gapped AI. An on-premises RAG platform that calls a cloud model is on-premises application infrastructure with cloud inference, not air-gapped AI.",{},{"id":402,"data":403,"type":218,"tunes":405},"p-terms-2",{"text":404},"An air-gapped system is often private by design because data remains inside the enclave, but privacy also depends on authorization, logging, data handling, physical security and operational policy.",{},{"id":407,"data":408,"type":42,"tunes":410},"h-strict",{"text":409,"level":253},"Strict air gap vs practical disconnected deployment",{},{"id":412,"data":413,"type":444,"tunes":445},"strict-comparison",{"rows":414,"title":436,"layout":394,"columns":437},[415,420,424,428,432],{"id":416,"label":417,"values":418},"physical","External physical connection",{"strict":419,"disconnected":419},"",{"id":421,"label":422,"values":423},"transfer","Cross-boundary transfer",{"strict":419,"disconnected":419},{"id":425,"label":426,"values":427},"internet","Internet access from AI workload",{"strict":419,"disconnected":419},{"id":429,"label":430,"values":431},"internalnet","Internal networking",{"strict":419,"disconnected":419},{"id":433,"label":434,"values":435},"best","Use term when",{"strict":419,"disconnected":419},"Two meanings frequently called “air-gapped”",[438,441],{"id":439,"label":440},"strict","Strict air gap",{"id":442,"label":443},"disconnected","Disconnected \u002F no-internet deployment","comparison",{},{"id":447,"data":448,"type":226,"tunes":452},"naming-rule",{"body":449,"title":450,"variant":451},"For architecture and security reviews, write the actual rule: \u003Cstrong>no outbound internet\u003C\u002Fstrong>, \u003Cstrong>no physical external network path\u003C\u002Fstrong>, \u003Cstrong>manual transfer only\u003C\u002Fstrong>, or \u003Cstrong>disconnected cluster with approved bastion\u002Fmirror\u003C\u002Fstrong>. That is more precise than saying only “air-gapped.”","Document the boundary instead of relying on the label","success",{},{"id":454,"data":455,"type":42,"tunes":457},"h-architecture",{"text":456,"level":253},"A practical air-gapped AI architecture",{},{"id":459,"data":460,"type":394,"tunes":495},"architecture-table",{"content":461,"stretched":43,"withHeadings":14},[462,465,468,471,474,477,480,483,486,489,492],[463,464],"Layer","What must exist inside the isolated environment",[466,467],"User\u002Fapplication layer","Chat UI, APIs, business application or internal agent interface",[469,470],"Identity &amp; authorization","Local\u002Finternal authentication, RBAC, tenant\u002Fresource permissions",[472,473],"AI gateway\u002Fruntime","Model routing, request policy, context assembly and runtime controls",[475,476],"Model serving","Local model server(s), weights, tokenizer\u002Fconfig and accelerator runtime",[478,479],"RAG \u002F knowledge","Document store, parser, embeddings, vector\u002Flexical indexes, metadata and provenance",[481,482],"Tools\u002Fservices","Only internal\u002Flocal APIs and approved systems reachable from the enclave",[484,485],"Artifact repositories","Local container registry, package mirror, model store and optionally OS\u002Fupdate repositories",[487,488],"Observability","Internal logs, metrics, traces and audit records",[490,491],"Backup\u002Frecovery","Local or separately controlled backup process appropriate to the security domain",[493,494],"Transfer boundary","Controlled import\u002Fexport process with inspection and approval",{},{"id":497,"data":498,"type":218,"tunes":500},"p-architecture-1",{"text":499},"A complete architecture should be able to start and operate without DNS lookups, license checks, package downloads or API calls to public services unless those dependencies have approved internal replacements.",{},{"id":502,"data":503,"type":218,"tunes":505},"p-architecture-2",{"text":504},"A useful design test is to disconnect the deployment from every external service and cold-start the stack. Hidden dependencies tend to appear during startup, model loading, authentication, package resolution or telemetry initialization.",{},{"id":507,"data":508,"type":42,"tunes":510},"h-models",{"text":509,"level":253},"Models must be pre-staged",{},{"id":512,"data":513,"type":218,"tunes":515},"p-models-1",{"text":514},"Cloud model APIs are unavailable by definition if the isolated workload has no path to them. The enclave therefore needs locally runnable model artifacts or an internally hosted inference service.",{},{"id":517,"data":518,"type":218,"tunes":520},"p-models-2",{"text":519},"NVIDIA's current NIM air-gap documentation explicitly uses a two-phase pattern: download and prepare model assets on a connected machine, transfer them, then run the isolated NIM from local storage without outbound registry access or cloud API keys.",{},{"id":522,"data":523,"type":218,"tunes":525},"p-models-3",{"text":524},"Model weights are only part of the dependency set. Tokenizers, configuration files, adapters, quantization metadata and any required runtime code must also be present.",{},{"id":527,"data":528,"type":42,"tunes":530},"h-remote-code",{"text":529,"level":253},"Models with remote-code dependencies are an air-gap hazard",{},{"id":532,"data":533,"type":218,"tunes":535},"p-remote-1",{"text":534},"Some model repositories contain custom Python code or runtime hooks that normally fetch additional code or assets.",{},{"id":537,"data":538,"type":218,"tunes":540},"p-remote-2",{"text":539},"Current Red Hat AI Inference documentation explicitly warns that some Hugging Face models requiring remote code cannot operate normally in disconnected environments because the library attempts network access even when offline mode is configured.",{},{"id":542,"data":543,"type":218,"tunes":545},"p-remote-3",{"text":544},"The practical lesson is to test a model's entire loading path offline before approving it for an isolated deployment. “I downloaded the weights” is not proof that the model is self-contained.",{},{"id":547,"data":548,"type":42,"tunes":550},"h-artifacts",{"text":549,"level":253},"Containers, packages and drivers become local supply-chain artifacts",{},{"id":552,"data":553,"type":218,"tunes":555},"p-artifacts-1",{"text":554},"Connected environments routinely pull container images, Python packages, OS updates and GPU components from public registries. An air-gapped environment cannot assume any of those services.",{},{"id":557,"data":558,"type":218,"tunes":560},"p-artifacts-2",{"text":559},"Red Hat's disconnected AI deployment model uses internal mirror registries for container images and operator catalogs. Models can be mirrored as OCI artifacts or transferred to persistent storage.",{},{"id":562,"data":563,"type":218,"tunes":565},"p-artifacts-3",{"text":564},"For broader stacks, the same pattern often applies to language packages, Linux repositories, JavaScript packages and internal binaries: approved artifacts enter once through the transfer process and are then served from trusted internal repositories.",{},{"id":567,"data":568,"type":42,"tunes":570},"h-bom",{"text":569,"level":253},"Know the complete dependency bill",{},{"id":572,"data":573,"type":394,"tunes":608},"dependency-table",{"content":574,"stretched":43,"withHeadings":14},[575,578,581,584,587,590,593,596,599,602,605],[576,577],"Dependency class","Examples",[579,580],"Model artifacts","Weights, tokenizer, config, adapters, quantization metadata",[582,583],"Inference runtime","vLLM, llama.cpp, Ollama, NIM or other serving runtime",[585,586],"GPU\u002Fruntime stack","Drivers, CUDA\u002FROCm libraries, container runtime",[588,589],"Application packages","Python wheels, npm packages, system libraries",[591,592],"Containers","Application, inference, DB, vector DB, monitoring images",[594,595],"RAG models","Embedding model, reranker, OCR\u002Fvision models",[597,598],"Data","Knowledge corpus, metadata, schemas, evaluation datasets",[600,601],"Security material","Certificates, CA bundles, policy\u002Fconfiguration, malware signatures where applicable",[603,604],"Operational artifacts","Dashboards, alert rules, backup tools, runbooks",[606,607],"Licensing","Offline-compatible licenses\u002Fentitlements where required",{},{"id":610,"data":611,"type":42,"tunes":613},"h-mirror",{"text":612,"level":253},"Internal mirrors are infrastructure, not a convenience",{},{"id":615,"data":616,"type":218,"tunes":618},"p-mirror-1",{"text":617},"A disconnected deployment becomes maintainable when the isolated domain has known internal sources for approved artifacts.",{},{"id":620,"data":621,"type":218,"tunes":623},"p-mirror-2",{"text":622},"Red Hat's documented approach uses a mirror registry available to the disconnected cluster so workloads do not need public registries.",{},{"id":625,"data":626,"type":218,"tunes":628},"p-mirror-3",{"text":627},"The same architectural idea can be applied to model stores and package repositories. The objective is to make artifact origin, version and approval explicit rather than copy random files manually to each server.",{},{"id":630,"data":631,"type":42,"tunes":633},"h-rag",{"text":632,"level":253},"RAG can work fully air-gapped",{},{"id":635,"data":636,"type":218,"tunes":638},"p-rag-1",{"text":637},"RAG does not require the public internet. It requires a retrievable corpus, an ingestion\u002Findexing pipeline and a model that can use the retrieved context.",{},{"id":640,"data":641,"type":218,"tunes":643},"p-rag-2",{"text":642},"Inside an air-gapped environment, the document store, parser\u002FOCR, embedding model, vector or lexical index, reranker and generation model can all run locally.",{},{"id":645,"data":646,"type":218,"tunes":648},"p-rag-3",{"text":647},"What changes is source acquisition. Live web search and cloud document connectors are unavailable unless equivalent data is imported through the controlled boundary.",{},{"id":650,"data":651,"type":218,"tunes":653},"p-rag-4",{"text":652},"The corpus therefore becomes a governed artifact. Every import should preserve source identity, date\u002Fversion and provenance so users know what knowledge the isolated system actually contains.",{},{"id":655,"data":656,"type":661,"tunes":662},"ref-rag",{"url":657,"title":658,"excerpt":659,"ctaLabel":660},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","What Is RAG? The Simplest Explanation of How It Works","RAG itself is independent of cloud hosting. In an air-gapped architecture, retrieval and generation simply have to be supplied by local\u002Finternal components.","Read the RAG foundation","referralArticle",{},{"id":664,"data":665,"type":42,"tunes":667},"h-agents",{"text":666,"level":253},"Agents can run air-gapped — but only with reachable tools",{},{"id":669,"data":670,"type":218,"tunes":672},"p-agents-1",{"text":671},"An agent loop can run entirely inside an isolated enclave if the model\u002Fruntime and required tools are local or reachable on the internal network.",{},{"id":674,"data":675,"type":218,"tunes":677},"p-agents-2",{"text":676},"A tool that depends on GitHub, public web search, cloud email or an external SaaS API will fail unless the architecture provides an approved internal equivalent or controlled asynchronous exchange process.",{},{"id":679,"data":680,"type":218,"tunes":682},"p-agents-3",{"text":681},"This is why air-gapped agent design should begin with a capability inventory: every tool endpoint must be classified as internal, imported, unavailable or deliberately excluded.",{},{"id":684,"data":685,"type":42,"tunes":687},"h-mcp",{"text":686,"level":253},"MCP does not bypass the air gap",{},{"id":689,"data":690,"type":218,"tunes":692},"p-mcp-1",{"text":691},"MCP can expose local tools and resources inside an isolated AI environment, but the protocol does not create connectivity through the security boundary.",{},{"id":694,"data":695,"type":218,"tunes":697},"p-mcp-2",{"text":696},"A local MCP server that reads internal documents can work perfectly offline. A remote MCP server on the public internet cannot be reached from a strict air-gapped enclave.",{},{"id":699,"data":700,"type":218,"tunes":702},"p-mcp-3",{"text":701},"The same principle applies to any connector protocol: interoperability is separate from network authority.",{},{"id":704,"data":705,"type":42,"tunes":707},"h-identity",{"text":706,"level":253},"Identity and authentication must also work offline",{},{"id":709,"data":710,"type":218,"tunes":712},"p-id-1",{"text":711},"An AI application can be locally hosted while still depending on a cloud identity provider. That hidden dependency breaks truly disconnected operation.",{},{"id":714,"data":715,"type":218,"tunes":717},"p-id-2",{"text":716},"Air-gapped designs therefore need an identity architecture that functions inside the enclave: local directory, internal identity provider, internal PKI, local service credentials or another approved mechanism.",{},{"id":719,"data":720,"type":218,"tunes":722},"p-id-3",{"text":721},"Authorization remains necessary even though the internet is absent. Air gaps do not replace RBAC, tenant isolation or least privilege.",{},{"id":724,"data":725,"type":42,"tunes":727},"h-time",{"text":726,"level":253},"Time, certificates and trust stores become local dependencies",{},{"id":729,"data":730,"type":218,"tunes":732},"p-time-1",{"text":731},"Many authentication and logging systems depend on reliable time. Certificates expire. Trust stores change. Signed artifacts need validation.",{},{"id":734,"data":735,"type":218,"tunes":737},"p-time-2",{"text":736},"A disconnected enclave should therefore have internal time synchronization and a certificate\u002Ftrust lifecycle that does not depend on reaching public services during ordinary operation.",{},{"id":739,"data":740,"type":218,"tunes":742},"p-time-3",{"text":741},"These are ordinary infrastructure concerns that become visible only when an architecture is tested without internet access.",{},{"id":744,"data":745,"type":42,"tunes":747},"h-telemetry",{"text":746,"level":253},"Telemetry and crash reporting need explicit policy",{},{"id":749,"data":750,"type":218,"tunes":752},"p-tel-1",{"text":751},"Many modern libraries attempt analytics, update checks or error reporting by default.",{},{"id":754,"data":755,"type":218,"tunes":757},"p-tel-2",{"text":756},"In an isolated environment those calls should either be disabled or redirected to internal observability. Repeated failed telemetry attempts can create delays, noisy logs and unexpected startup behavior.",{},{"id":759,"data":760,"type":218,"tunes":762},"p-tel-3",{"text":761},"An air-gapped deployment should know which components attempt egress even if the firewall would block them.",{},{"id":764,"data":765,"type":42,"tunes":767},"h-updates",{"text":766,"level":253},"Air-gapped systems still need patches",{},{"id":769,"data":770,"type":218,"tunes":772},"p-update-1",{"text":771},"Network isolation does not stop software from developing vulnerabilities. It only changes how patches reach the system.",{},{"id":774,"data":775,"type":218,"tunes":777},"p-update-2",{"text":776},"NIST frames patch management as preventive maintenance: organizations still need to identify, acquire, prioritize, install and verify patches and updates.",{},{"id":779,"data":780,"type":218,"tunes":782},"p-update-3",{"text":781},"Air-gapped operations therefore need a repeatable import cadence for OS packages, container images, drivers, AI runtimes and security updates. The trade-off is between isolation stability and vulnerability exposure from stale software.",{},{"id":784,"data":785,"type":42,"tunes":787},"h-patch-flow",{"text":786,"level":253},"A controlled update path",{},{"id":789,"data":790,"type":331,"tunes":817},"patch-flow",{"steps":791,"title":816,"orientation":330},[792,795,798,801,804,807,810,813],{"label":793,"description":794},"1. Identify required update","Security advisory, model\u002Fruntime improvement or operational need triggers change.",{"label":796,"description":797},"2. Acquire in connected staging","Download exact versions plus signatures\u002Fchecksums and metadata.",{"label":799,"description":800},"3. Validate supply-chain evidence","Verify source, integrity, compatibility and policy requirements.",{"label":802,"description":803},"4. Test in representative offline staging","Confirm the update works without unexpected network dependencies.",{"label":805,"description":806},"5. Approve transfer","Apply the organization's change and security process.",{"label":808,"description":809},"6. Import into enclave repository","Publish the artifact to the internal trusted source.",{"label":811,"description":812},"7. Deploy gradually","Apply to test\u002Fcanary nodes before wider rollout where architecture permits.",{"label":814,"description":815},"8. Verify and record","Confirm version, health, behavior and rollback state.","Example update lifecycle for an isolated AI environment",{},{"id":819,"data":820,"type":42,"tunes":822},"h-transfer",{"text":821,"level":253},"The transfer boundary is the most sensitive operational interface",{},{"id":824,"data":825,"type":218,"tunes":827},"p-transfer-1",{"text":826},"If external information must enter an air-gapped system, the import channel becomes a major security control point.",{},{"id":829,"data":830,"type":218,"tunes":832},"p-transfer-2",{"text":831},"The NSA Cybersecurity Technical Cyber Threat Framework explicitly recognizes replication through removable media as a path adversaries can use to cross into disconnected or air-gapped networks.",{},{"id":834,"data":835,"type":218,"tunes":837},"p-transfer-3",{"text":836},"That is why controlled media handling, inspection, provenance, encryption where required, malware scanning and role separation can matter as much as the AI stack itself.",{},{"id":839,"data":840,"type":42,"tunes":842},"h-media",{"text":841,"level":253},"Removable media is not a neutral pipe",{},{"id":844,"data":845,"type":218,"tunes":847},"p-media-1",{"text":846},"USB drives and other portable media can carry both legitimate model\u002Fdata artifacts and malicious content.",{},{"id":849,"data":850,"type":218,"tunes":852},"p-media-2",{"text":851},"NIST's media-sanitization guidance treats storage media as a confidentiality lifecycle object that may require clearing, purging or destruction according to sensitivity and reuse needs.",{},{"id":854,"data":855,"type":218,"tunes":857},"p-media-3",{"text":856},"The exact transfer procedure is organization-specific, but the architectural principle is stable: cross-boundary media should be governed as a security asset, not treated as an informal convenience.",{},{"id":859,"data":860,"type":42,"tunes":862},"h-supply",{"text":861,"level":253},"Air-gapping increases supply-chain importance",{},{"id":864,"data":865,"type":218,"tunes":867},"p-supply-1",{"text":866},"An isolated system receives fewer live external inputs, but every imported binary, model, container and package becomes more consequential because the enclave may trust it for a long time.",{},{"id":869,"data":870,"type":218,"tunes":872},"p-supply-2",{"text":871},"NIST software-supply-chain guidance emphasizes provenance, supplier risk, vulnerability management, software verification and SBOM-oriented practices. These concerns become directly relevant to offline AI artifact import.",{},{"id":874,"data":875,"type":218,"tunes":877},"p-supply-3",{"text":876},"Model supply chain deserves the same attention as application supply chain: model origin, license, hash, format, required code, tokenizer, adapters and evaluation status should be known before import.",{},{"id":879,"data":880,"type":42,"tunes":882},"h-readiness",{"text":881,"level":253},"Air-gap readiness should be tested, not assumed",{},{"id":884,"data":885,"type":226,"tunes":888},"readiness-note",{"body":886,"title":887,"variant":246},"The following air-gap-readiness test is an engineering synthesis, not a NIST or vendor certification method. It is designed to expose hidden external dependencies before deployment.","Proposed validation pattern",{},{"id":890,"data":891,"type":394,"tunes":926},"readiness-table",{"content":892,"stretched":43,"withHeadings":14},[893,896,899,902,905,908,911,914,917,920,923],[894,895],"Test","What it proves",[897,898],"Cold start with all outbound network blocked","Runtime does not require public services during startup",[900,901],"Load every approved model from local storage","Weights\u002Ftokenizers\u002Fconfigs are complete",[903,904],"Rebuild\u002Fredeploy from internal registries only","Container\u002Fpackage mirrors are sufficient",[906,907],"Authenticate users while external IdP is unreachable","Identity works inside the enclave",[909,910],"Run RAG ingestion and query offline","Embedding\u002Findexing\u002Fretrieval stack is local",[912,913],"Run representative agent tools","Tools do not depend on external APIs",[915,916],"Restart after cache deletion","Offline operation is not accidentally relying on previously cached downloads",[918,919],"Advance simulated certificate\u002Fupdate lifecycle","Trust and maintenance dependencies are understood",[921,922],"Import a new model through staging path","Transfer\u002Fchange procedure is operational",[924,925],"Restore from backup","Recovery does not require unavailable cloud storage",{},{"id":928,"data":929,"type":42,"tunes":931},"h-cache",{"text":930,"level":253},"Cached once is not the same as air-gap ready",{},{"id":933,"data":934,"type":218,"tunes":936},"p-cache-1",{"text":935},"A system may appear offline because the model and packages are already cached from earlier internet access.",{},{"id":938,"data":939,"type":218,"tunes":941},"p-cache-2",{"text":940},"Deleting caches or deploying to a clean node can reveal missing tokenizer files, Python packages, model manifests or remote-code dependencies.",{},{"id":943,"data":944,"type":218,"tunes":946},"p-cache-3",{"text":945},"Air-gap readiness should therefore be validated from clean internal artifacts, not only from a developer workstation that was previously connected.",{},{"id":948,"data":949,"type":42,"tunes":951},"h-threats",{"text":950,"level":253},"What threats remain inside an air gap?",{},{"id":953,"data":954,"type":394,"tunes":995},"threat-table",{"content":955,"stretched":43,"withHeadings":14},[956,959,962,965,968,971,974,977,980,983,986,989,992],[957,958],"Threat","Why the air gap does not remove it",[960,961],"Compromised imported artifact","Malware\u002Fmodel\u002Fpackage can enter through the authorized transfer path",[963,964],"Malicious removable media","Physical transfer can carry executable payloads",[966,967],"Insider misuse","Authorized users already exist inside the enclave",[969,970],"Prompt injection in imported documents","Untrusted content can influence RAG\u002Fagents without internet",[972,973],"Overprivileged agent tools","Local tools can still damage local systems",[975,976],"Cross-tenant data leakage","Internal authorization bugs remain possible",[978,979],"Vulnerable internal software","Lack of external connection does not remove exploitable bugs",[981,982],"Lateral movement","A compromised node can attack other internally connected nodes",[984,985],"Stale dependencies","Slow update cadence can leave known vulnerabilities unpatched",[987,988],"Physical theft\u002Ftampering","Hardware and media security remain critical",[990,991],"Bad model behavior","Hallucination, bias and task failure are independent of networking",[993,994],"Supply-chain poisoning","Trusted import sources can still be compromised",{},{"id":997,"data":998,"type":42,"tunes":1000},"h-benefits",{"text":999,"level":253},"What an air gap actually improves",{},{"id":1002,"data":1003,"type":218,"tunes":1005},"p-benefit-1",{"text":1004},"A genuine air gap can materially reduce attack paths that depend on direct remote connectivity: external command-and-control, cloud credential misuse, internet-facing service exploitation and accidental data exfiltration through ordinary outbound APIs.",{},{"id":1007,"data":1008,"type":218,"tunes":1010},"p-benefit-2",{"text":1009},"It also makes data residency simple in one narrow sense: inference data cannot be sent to an external cloud service if no path exists.",{},{"id":1012,"data":1013,"type":218,"tunes":1015},"p-benefit-3",{"text":1014},"Those benefits are strongest when the transfer boundary and internal access controls are equally disciplined. A poorly managed USB process can undermine the intended isolation.",{},{"id":1017,"data":1018,"type":42,"tunes":1020},"h-costs",{"text":1019,"level":253},"What an air gap makes harder",{},{"id":1022,"data":1023,"type":394,"tunes":1063},"cost-table",{"content":1024,"stretched":43,"withHeadings":14},[1025,1028,1031,1034,1037,1040,1043,1046,1049,1051,1054,1057,1060],[1026,1027],"Area","Operational consequence",[1029,1030],"Model updates","Manual\u002Fstaged transfer instead of direct model-hub pull",[1032,1033],"Security patches","Delayed and governed import workflow",[1035,1036],"Package installation","Internal mirrors or prebuilt artifacts required",[1038,1039],"Cloud AI APIs","Unavailable",[1041,1042],"Web search\u002Fconnectors","Unavailable unless data is imported separately",[1044,1045],"Authentication","Needs internal\u002Foffline-capable identity services",[1047,1048],"Monitoring","Needs internal observability and controlled export",[606,1050],"Products requiring online activation may be unsuitable",[1052,1053],"Troubleshooting","No easy live access to vendor resources from production enclave",[1055,1056],"Capacity","All inference compute must exist locally",[1058,1059],"Disaster recovery","Cloud backups may be unavailable or policy-restricted",[1061,1062],"Knowledge freshness","External information arrives only as fast as the import process",{},{"id":1065,"data":1066,"type":42,"tunes":1068},"h-private",{"text":1067,"level":253},"Air-gapped AI vs private AI",{},{"id":1070,"data":1071,"type":218,"tunes":1073},"p-private-1",{"text":1072},"Private AI is primarily about controlling sensitive data and AI processing. A private AI platform may be on-premises and still access approved cloud models or external services.",{},{"id":1075,"data":1076,"type":218,"tunes":1078},"p-private-2",{"text":1077},"Air-gapped AI is stricter on connectivity. A system can be private without being air-gapped, and an air-gapped system can still have poor privacy if every internal user has unrestricted access.",{},{"id":1080,"data":1081,"type":218,"tunes":1083},"p-private-3",{"text":1082},"The security objective should determine the architecture: confidentiality, sovereignty, resilience and isolation are related but distinct requirements.",{},{"id":1085,"data":1086,"type":42,"tunes":1088},"h-sovereign",{"text":1087,"level":253},"Air-gapped AI vs sovereign AI",{},{"id":1090,"data":1091,"type":218,"tunes":1093},"p-sovereign-1",{"text":1092},"Sovereign AI concerns control over the broader dependency chain: data, models, infrastructure, operators, jurisdiction and strategic dependencies.",{},{"id":1095,"data":1096,"type":218,"tunes":1098},"p-sovereign-2",{"text":1097},"An air gap can support sovereignty by reducing external runtime dependency, but it does not guarantee sovereign control. The enclave may still depend on foreign hardware, proprietary model licenses or external update suppliers.",{},{"id":1100,"data":1101,"type":218,"tunes":1103},"p-sovereign-3",{"text":1102},"The next canonical article separates those control dimensions explicitly.",{},{"id":1105,"data":1106,"type":42,"tunes":1108},"h-implementation",{"text":1107,"level":253},"Original implementation evidence: what the Aaasaasa AI Client proves — and what it does not",{},{"id":1110,"data":1111,"type":226,"tunes":1114},"impl-note",{"body":1112,"title":1113,"variant":246},"Aaasaasa AI Client is useful evidence for \u003Cstrong>local inference architecture\u003C\u002Fstrong>, provider abstraction and separation of runtime\u002Fmodel location. It is \u003Cstrong>not evidence of a deployed air-gapped environment\u003C\u002Fstrong>. The repository also supports cloud and remote paths, and no verified project evidence establishes a physically isolated security domain.","Implementation boundary",{},{"id":1116,"data":1117,"type":218,"tunes":1119},"p-impl-1",{"text":1118},"The AI Hub separates agent\u002Fclient, provider, model and connection location. It supports local Ollama inference and local-provider Codex operation as distinct choices rather than assuming that every AI request goes to a cloud model.",{},{"id":1121,"data":1122,"type":218,"tunes":1124},"p-impl-2",{"text":1123},"The repository explicitly notes that a local runtime can still use a cloud model, while Direct Ollama chat is local inference. This distinction is directly relevant to air-gap architecture: local execution does not prove that the model or surrounding dependencies are disconnected.",{},{"id":1126,"data":1127,"type":218,"tunes":1129},"p-impl-3",{"text":1128},"Provider abstraction, local model discovery and local inference are therefore building blocks for an air-gap-capable product architecture, but the network boundary, offline dependency mirror, controlled transfer process and offline identity\u002Foperations must still be engineered separately.",{},{"id":1131,"data":1132,"type":394,"tunes":1155},"impl-table",{"content":1133,"stretched":43,"withHeadings":14},[1134,1137,1140,1143,1146,1149,1152],[1135,1136],"Verified project capability","Air-gap relevance",[1138,1139],"Local Ollama inference","Supports local model execution",[1141,1142],"Local provider\u002Fruntime paths","Reduces dependency on cloud inference",[1144,1145],"Provider\u002Fmodel\u002Fruntime separation","Makes cloud dependencies explicit rather than hidden",[1147,1148],"Central permissions","Supports local tool\u002Fdata access control",[1150,1151],"Cloud\u002Fremote provider support also exists","Proves the product itself is hybrid-capable, not inherently air-gapped",[1153,1154],"No verified isolated deployment boundary","Prevents overclaiming air-gap maturity",{},{"id":1157,"data":1158,"type":42,"tunes":1160},"h-when",{"text":1159,"level":253},"When is air-gapped AI justified?",{},{"id":1162,"data":1163,"type":394,"tunes":1186},"when-table",{"content":1164,"stretched":43,"withHeadings":14},[1165,1168,1171,1174,1177,1180,1183],[1166,1167],"Air gap may be justified when","A connected private architecture may be better when",[1169,1170],"Security policy explicitly requires physically separated domains","Main requirement is only that prompts\u002Fdata are not used by public consumer services",[1172,1173],"Classified or extremely sensitive data cannot cross external networks","Approved enterprise cloud\u002Fprivate endpoints satisfy data controls",[1175,1176],"Operational environment has no reliable external connectivity","Internet is available and operational agility matters",[1178,1179],"Mission continuity must not depend on cloud\u002Fprovider availability","Managed model quality and rapid upgrades are more valuable",[1181,1182],"Regulated\u002Fcritical environment mandates controlled transfer","Standard security controls can meet the actual threat model",[1184,1185],"External SaaS\u002FAPI access is prohibited","Business workflow relies heavily on external connectors",{},{"id":1188,"data":1189,"type":218,"tunes":1191},"p-when-1",{"text":1190},"Air-gapping should be a requirement derived from a threat model or policy, not a prestige feature. It has real security value when the eliminated connectivity path is itself unacceptable.",{},{"id":1193,"data":1194,"type":218,"tunes":1196},"p-when-2",{"text":1195},"For many enterprise use cases, a tightly controlled private network with egress restrictions, local inference and approved update channels may provide a better balance of security and maintainability than a strict physical air gap.",{},{"id":1198,"data":1199,"type":42,"tunes":1201},"h-design",{"text":1200,"level":253},"A practical air-gapped AI design sequence",{},{"id":1203,"data":1204,"type":331,"tunes":1243},"design-flow",{"steps":1205,"title":1242,"orientation":330},[1206,1209,1212,1215,1218,1221,1224,1227,1230,1233,1236,1239],{"label":1207,"description":1208},"1. Define what the air gap separates","Name the security domains and whether the requirement is strict physical separation or simply no internet.",{"label":1210,"description":1211},"2. Inventory every external dependency","Models, packages, registries, identity, telemetry, licensing, storage, APIs, DNS\u002Ftime and support services.",{"label":1213,"description":1214},"3. Select offline-capable models and runtimes","Verify model assets and runtime code can load without remote calls.",{"label":1216,"description":1217},"4. Build internal artifact repositories","Create trusted sources for containers, packages, models and updates.",{"label":1219,"description":1220},"5. Design controlled transfer","Define staging, verification, media\u002Fgateway handling, approval and provenance.",{"label":1222,"description":1223},"6. Build internal identity and authorization","Ensure users, services and tools can authenticate without cloud dependencies.",{"label":1225,"description":1226},"7. Keep RAG and tools local","Deploy knowledge, embeddings, indexes and required service APIs inside the enclave.",{"label":1228,"description":1229},"8. Build internal observability","Operate logs, metrics, traces and security monitoring locally.",{"label":1231,"description":1232},"9. Define patch\u002Fmodel update cadence","Balance vulnerability response with the controlled import process.",{"label":1234,"description":1235},"10. Test from a clean disconnected state","Cold-start and operate without inherited caches or hidden internet access.",{"label":1237,"description":1238},"11. Test compromise paths","Exercise removable-media, supply-chain, prompt-injection, insider and lateral-movement scenarios.",{"label":1240,"description":1241},"12. Document exceptions and exports","Every permitted cross-boundary path should have a named purpose, owner and control set.","Design from the boundary inward",{},{"id":1245,"data":1246,"type":42,"tunes":1248},"h-checklist",{"text":1247,"level":253},"Air-gapped AI architecture checklist",{},{"id":1250,"data":1251,"type":394,"tunes":1304},"checklist-table",{"content":1252,"stretched":43,"withHeadings":14},[1253,1256,1259,1262,1265,1268,1271,1274,1277,1280,1283,1286,1289,1292,1295,1298,1301],[1254,1255],"Question","Expected evidence",[1257,1258],"What exactly is isolated from what?","Documented security-domain boundary",[1260,1261],"Is the boundary physically disconnected?","Network\u002Fphysical architecture evidence if strict air gap is claimed",[1263,1264],"How does data cross the boundary?","Authorized non-automated\u002Fmanual or explicitly documented disconnected workflow",[1266,1267],"Can every model cold-start offline?","Offline loading test",[1269,1270],"Are tokenizer\u002Fconfig\u002Fruntime assets complete?","Verified internal model bundle",[1272,1273],"Where do containers\u002Fpackages come from?","Internal trusted mirror\u002Frepository",[1275,1276],"Can identity work without cloud services?","Internal IdP\u002FPKI\u002Fservice credential path",[1278,1279],"Can RAG ingest\u002Fquery offline?","Local ingestion, embeddings, index and retrieval",[1281,1282],"Which agent tools remain available?","Internal capability inventory",[1284,1285],"How are patches imported?","Controlled maintenance process",[1287,1288],"How are artifacts verified?","Integrity\u002Fprovenance\u002Fmalware\u002Fsupply-chain controls",[1290,1291],"How is removable media governed?","Media handling and sanitization policy",[1293,1294],"Can the system run after caches are cleared?","Clean-environment offline test",[1296,1297],"Where are logs and traces stored?","Internal observability platform",[1299,1300],"How are exports approved?","Controlled egress process",[1302,1303],"What proves this is air-gapped rather than merely local?","Boundary and transfer evidence, not model location",{},{"id":1306,"data":1307,"type":42,"tunes":1309},"h-failures",{"text":1308,"level":253},"Common air-gapped AI failure modes",{},{"id":1311,"data":1312,"type":394,"tunes":1353},"failure-table",{"content":1313,"stretched":43,"withHeadings":14},[1314,1317,1320,1323,1326,1329,1332,1335,1338,1341,1344,1347,1350],[1315,1316],"Failure mode","What actually failed",[1318,1319],"Local model still downloads tokenizer\u002Fconfig at startup","Model bundle was incomplete",[1321,1322],"Container references public registry","Deployment was not self-contained",[1324,1325],"Cloud identity required for login","Application was local but identity was not",[1327,1328],"License server required externally","Vendor dependency contradicted offline operation",[1330,1331],"Embedding model missing","Chat works but RAG ingestion fails",[1333,1334],"Agent tool calls public SaaS","Agent architecture was not air-gap compatible",[1336,1337],"Only GPU node is isolated","Database, UI or monitoring still depends on external services",[1339,1340],"USB imports are informal","Transfer boundary becomes uncontrolled attack path",[1342,1343],"No patch process","Isolation creates growing vulnerability debt",[1345,1346],"Cached developer machine used as proof","Fresh deployment fails without internet",[1348,1349],"Air gap replaces authorization thinking","Internal users\u002Fservices become overprivileged",[1351,1352],"Air-gapped label used for firewall-only egress block","Security documentation overstates the actual boundary",{},{"id":1355,"data":1356,"type":42,"tunes":1358},"h-misconceptions",{"text":1357,"level":253},"Common misconceptions",{},{"id":1360,"data":1361,"type":394,"tunes":1396},"misconceptions-table",{"content":1362,"stretched":43,"withHeadings":14},[1363,1366,1369,1372,1375,1378,1381,1384,1387,1390,1393],[1364,1365],"Misconception","Correction",[1367,1368],"“Local AI is air-gapped AI.”","Local describes where inference runs; air gap describes the security\u002Fnetwork boundary.",[1370,1371],"“Air-gapped means one standalone PC.”","An isolated enclave can contain an entire internal network or cluster.",[1373,1374],"“No internet equals strict air gap.”","Under NIST's definition, the separated systems also lack physical connection and cross-boundary transfer is non-automated.",[1376,1377],"“Air gaps eliminate cyber risk.”","Supply-chain, removable-media, insider, internal-network and application risks remain.",[1379,1380],"“RAG needs the cloud.”","RAG can run entirely with local models, indexes and data.",[1382,1383],"“Agents cannot work offline.”","Agents can use internal\u002Flocal tools; they simply cannot reach unavailable external services.",[1385,1386],"“Once installed, the system needs no updates.”","Patches, drivers, models and dependencies still require lifecycle management.",[1388,1389],"“A downloaded model is self-contained.”","Tokenizers, remote code, libraries or model assets may still trigger network dependencies.",[1391,1392],"“Private AI and air-gapped AI are identical.”","Private AI is a data\u002Fcontrol property; air gap is a connectivity property.",[1394,1395],"“Air gap guarantees sovereignty.”","External hardware, licenses, models and supply chain can remain dependencies.",{},{"id":1398,"data":1399,"type":42,"tunes":1401},"h-limitations",{"text":1400,"level":253},"Limitations",{},{"id":1403,"data":1404,"type":218,"tunes":1406},"p-limit-1",{"text":1405},"Strict air gaps make external knowledge freshness slower because every new source must pass through a transfer process.",{},{"id":1408,"data":1409,"type":218,"tunes":1411},"p-limit-2",{"text":1410},"They can constrain model choice when licenses, remote-code requirements, hardware needs or provider-only APIs cannot be satisfied offline.",{},{"id":1413,"data":1414,"type":218,"tunes":1416},"p-limit-3",{"text":1415},"They increase operational cost because infrastructure normally consumed as cloud services must be owned and maintained internally.",{},{"id":1418,"data":1419,"type":218,"tunes":1421},"p-limit-4",{"text":1420},"They can also create patch latency: stronger change control may keep systems stable while delaying urgent vulnerability remediation.",{},{"id":1423,"data":1424,"type":218,"tunes":1426},"p-limit-5",{"text":1425},"Air-gapped AI should therefore be evaluated as one security architecture among several, not assumed to be universally superior.",{},{"id":1428,"data":1429,"type":42,"tunes":1431},"h-change",{"text":1430,"level":253},"What would change this answer?",{},{"id":1433,"data":1434,"type":218,"tunes":1436},"p-change-1",{"text":1435},"Vendor support for disconnected operation changes quickly. New model formats, signed OCI artifacts, offline license mechanisms and integrated model registries can reduce operational friction.",{},{"id":1438,"data":1439,"type":218,"tunes":1441},"p-change-2",{"text":1440},"The distinction between strict air gap and disconnected deployment will remain important even if vendors continue using the terms loosely.",{},{"id":1443,"data":1444,"type":218,"tunes":1446},"p-change-3",{"text":1445},"The stable principle is that genuine air-gap claims depend on the system boundary and transfer mechanism, not on whether the LLM happens to run locally.",{},{"id":1448,"data":1449,"type":42,"tunes":1451},"h-related",{"text":1450,"level":253},"Related canonical knowledge",{},{"id":1453,"data":1454,"type":218,"tunes":1456},"p-related-1",{"text":1455},"Air-Gapped AI is a deployment\u002Fsecurity architecture node. Private AI, Sovereign AI and provider abstraction answer different questions about confidentiality, control and dependency.",{},{"id":1458,"data":1459,"type":218,"tunes":1461},"p-related-2",{"text":1460},"MLOps\u002FLLMOps becomes more demanding inside a disconnected environment because model, package and update lifecycles must operate through internal repositories and controlled transfer.",{},{"id":1463,"data":1464,"type":218,"tunes":1466},"p-related-3",{"text":1465},"RAG and Agentic AI remain valid patterns inside the enclave as long as their data and tools are internally available.",{},{"id":1468,"data":1469,"type":661,"tunes":1474},"ref-memory",{"url":1470,"title":1471,"excerpt":1472,"ctaLabel":1473},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context","Air-gapped AI still needs correct internal boundaries between durable memory, authoritative state, retrieval and model context.","Read the memory architecture article",{},{"id":1476,"data":1477,"type":42,"tunes":1479},"h-faq",{"text":1478,"level":253},"Frequently asked questions",{},{"id":1481,"data":1482,"type":1481,"tunes":1525},"faq",{"items":1483,"title":1524},[1484,1488,1492,1496,1500,1504,1508,1512,1516,1520],{"id":1485,"answer":1486,"question":1487},"faq1","Air-gapped AI is AI deployed inside a security domain physically disconnected from the external systems it is separated from, with cross-boundary transfer performed through controlled non-automated procedures under the strict NIST definition.","What is air-gapped AI?",{"id":1489,"answer":1490,"question":1491},"faq2","No for normal inference and operation. Required models, packages, data and services must be available inside the isolated environment.","Does air-gapped AI need internet access?",{"id":1493,"answer":1494,"question":1495},"faq3","No. A local model can run on a machine that still has internet access or uses cloud identity, tools or storage. Air gap describes the complete system boundary.","Is a local LLM automatically air-gapped?",{"id":1497,"answer":1498,"question":1499},"faq4","Yes. Documents, embedding models, vector or lexical indexes, rerankers and generation models can all run locally. External knowledge must be imported through the controlled boundary.","Can RAG work in an air-gapped network?",{"id":1501,"answer":1502,"question":1503},"faq5","Yes, if their tools and required systems are available inside the isolated network. Public SaaS and cloud APIs are unavailable without a permitted cross-boundary mechanism.","Can AI agents work air-gapped?",{"id":1505,"answer":1506,"question":1507},"faq6","Models are typically acquired and validated in a connected staging environment, transferred through an approved process and published to an internal model\u002Fartifact repository.","How are models updated in an air-gapped environment?",{"id":1509,"answer":1510,"question":1511},"faq7","No. On-premises describes infrastructure location. On-prem systems can remain internet-connected.","Is on-premises AI the same as air-gapped AI?",{"id":1513,"answer":1514,"question":1515},"faq8","No. Private AI is about data\u002Fcontrol requirements and can still use connected infrastructure. Air gap specifically describes network\u002Fdomain separation.","Is private AI the same as air-gapped AI?",{"id":1517,"answer":1518,"question":1519},"faq9","It removes or reduces some remote connectivity risks but does not remove supply-chain, removable-media, insider, internal authorization, physical or model-behavior risks.","Does an air gap make AI secure?",{"id":1521,"answer":1522,"question":1523},"faq10","Deploy or cold-start the full stack in a clean environment with all external connectivity unavailable and verify that models, identity, RAG, tools, monitoring, updates and recovery depend only on approved internal artifacts and services.","What is the best test for air-gap readiness?","Air-gapped AI FAQ",{},{"id":1527,"data":1528,"type":42,"tunes":1530},"h-glossary",{"text":1529,"level":253},"Glossary",{},{"id":1532,"data":1533,"type":1532,"tunes":1580},"glossary",{"title":1534,"entries":1535},"Key air-gapped AI terms",[1536,1540,1543,1546,1549,1552,1556,1560,1564,1568,1572,1576],{"term":1537,"anchor":1538,"definition":1539},"Air gap","air-gap","Security-domain interface where systems are not physically connected and any cross-boundary logical transfer is non-automated\u002Fmanual under the NIST glossary definition.",{"term":387,"anchor":1541,"definition":1542},"air-gapped-ai","AI system deployed inside an air-gapped security domain with locally available inference and operational dependencies.",{"term":375,"anchor":1544,"definition":1545},"disconnected-environment","Deployment environment without direct outside-internet access; implementations may use controlled mirror or bastion workflows.",{"term":371,"anchor":1547,"definition":1548},"offline-capable-ai","AI application able to operate for some or all functions without internet connectivity, without necessarily being permanently isolated.",{"term":367,"anchor":1550,"definition":1551},"local-ai","AI inference or runtime executing on local hardware rather than a remote model endpoint; does not imply network isolation.",{"term":1553,"anchor":1554,"definition":1555},"Mirror registry","mirror-registry","Internal repository containing approved copies of container images or other artifacts needed by a disconnected deployment.",{"term":1557,"anchor":1558,"definition":1559},"Staging environment","staging-environment","Connected or controlled zone where artifacts are acquired, verified and prepared before transfer into an isolated domain.",{"term":1561,"anchor":1562,"definition":1563},"Controlled transfer","controlled-transfer","Governed movement of data or software across the isolation boundary using approved media\u002Fprocesses and verification.",{"term":1565,"anchor":1566,"definition":1567},"Artifact provenance","artifact-provenance","Information showing where a model, package, container or other imported artifact originated and how it was produced or verified.",{"term":1569,"anchor":1570,"definition":1571},"Removable media","removable-media","Portable storage used to transfer data between systems; a potential security path across disconnected domains.",{"term":1573,"anchor":1574,"definition":1575},"Internal model store","internal-model-store","Repository inside the isolated environment from which approved model artifacts are served or deployed.",{"term":1577,"anchor":1578,"definition":1579},"Air-gap readiness","air-gap-readiness","Demonstrated ability of the complete AI stack to install, start, operate, update and recover without unapproved external connectivity.",{},{"id":1582,"data":1583,"type":42,"tunes":1585},"h-conclusion",{"text":1584,"level":253},"Conclusion",{},{"id":1587,"data":1588,"type":218,"tunes":1590},"p-conclusion-1",{"text":1589},"Air-gapped AI is not a special kind of model. It is an AI architecture operating inside a deliberately isolated security domain.",{},{"id":1592,"data":1593,"type":218,"tunes":1595},"p-conclusion-2",{"text":1594},"The model can be the easy part. Production readiness depends on whether every surrounding dependency — model assets, packages, registries, identity, RAG, tools, monitoring, updates and recovery — can function without an automated external path.",{},{"id":1597,"data":1598,"type":218,"tunes":1600},"p-conclusion-3",{"text":1599},"The shortest reliable rule is: local inference proves where the model runs; air-gap evidence proves how the complete system is separated and how every permitted transfer crosses that boundary.",{},{"id":1602,"data":1603,"type":42,"tunes":1605},"h-sources",{"text":1604,"level":253},"Primary sources and current implementation references",{},{"id":1607,"data":1608,"type":218,"tunes":1610},"p-sources-note",{"text":1609},"The sources below establish the security definition, current disconnected AI deployment patterns and lifecycle risks. Vendor use of “air-gapped” is intentionally distinguished from the stricter NIST definition.",{},{"id":1612,"data":1613,"type":1619,"tunes":1620},"src-nist-airgap",{"link":1614,"meta":1615},"https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fair_gap",{"image":1616,"title":1617,"description":1618},{"url":419},"NIST CSRC — Air gap","NIST glossary definition: physically disconnected systems with non-automated, manually controlled logical transfer across the boundary.","linkTool",{},{"id":1622,"data":1623,"type":1619,"tunes":1629},"src-nvidia-airgap",{"link":1624,"meta":1625},"https:\u002F\u002Fdocs.nvidia.com\u002Fnim\u002Flarge-language-models\u002Flatest\u002Fdeploy-air-gap.html",{"image":1626,"title":1627,"description":1628},{"url":419},"NVIDIA NIM — Air-Gap Deployment","Current operational guidance for staging model assets on a connected system and running NIM from local storage without internet, public registries or cloud API keys.",{},{"id":1631,"data":1632,"type":1619,"tunes":1638},"src-redhat-disconnected",{"link":1633,"meta":1634},"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Findex",{"image":1635,"title":1636,"description":1637},{"url":419},"Red Hat AI Inference — Disconnected deployment","Current Red Hat guidance for serving LLMs in disconnected environments with mirrored artifacts and internal infrastructure.",{},{"id":1640,"data":1641,"type":1619,"tunes":1647},"src-redhat-models",{"link":1642,"meta":1643},"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Fstoring-models-in-disconnected-environments_disconnected-deploy",{"image":1644,"title":1645,"description":1646},{"url":419},"Red Hat AI Inference — Storing models in disconnected environments","Current guidance covering OCI model images, persistent model storage and limitations of models requiring remote code.",{},{"id":1649,"data":1650,"type":1619,"tunes":1656},"src-nsa-framework",{"link":1651,"meta":1652},"https:\u002F\u002Fwww.nsa.gov\u002Fportals\u002F75\u002Fdocuments\u002Fwhat-we-do\u002Fcybersecurity\u002Fprofessional-resources\u002Fctr-nsa-css-technical-cyber-threat-framework.pdf",{"image":1653,"title":1654,"description":1655},{"url":419},"NSA — Technical Cyber Threat Framework","Threat framework explicitly identifying removable-media replication as a path into disconnected or air-gapped networks.",{},{"id":1658,"data":1659,"type":1619,"tunes":1665},"src-nist-media",{"link":1660,"meta":1661},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fguidelines-media-sanitization",{"image":1662,"title":1663,"description":1664},{"url":419},"NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitization","Guidance for managing and sanitizing storage media according to information confidentiality requirements.",{},{"id":1667,"data":1668,"type":1619,"tunes":1674},"src-nist-patch",{"link":1669,"meta":1670},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F40\u002Fr4\u002Ffinal",{"image":1671,"title":1672,"description":1673},{"url":419},"NIST SP 800-40 Rev. 4 — Enterprise Patch Management Planning","Guidance framing patching and updates as preventive maintenance across enterprise systems.",{},{"id":1676,"data":1677,"type":1619,"tunes":1683},"src-nist-supply",{"link":1678,"meta":1679},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-security-supply-chains",{"image":1680,"title":1681,"description":1682},{"url":419},"NIST — Software Security in Supply Chains","NIST guidance covering software supply-chain risk, provenance, verification, SBOM-related practices and vulnerability management.",{},"2.31.6","Air-gapped AI runs models, RAG and AI applications inside an isolated security domain without internet or cloud dependencies. Learn how models, data, updates and tools operate offline.","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0","PUBLISHED","2026-10-08T11:32:00.000Z","2026-10-08T19:32:11.607Z","2026-10-08T21:37:26.788Z",{"en":1693,"de":1694,"sr":1695,"es":1696,"fr":1697,"it":1698,"ru":1699,"zh":1700},"\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fde\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fsr\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fes\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Ffr\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fit\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fru\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fzh\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access",[1702,1706,1710],{"id":1703,"name":1704,"slug":1705},57,"Data Boundaries","data-boundaries",{"id":1707,"name":1708,"slug":1709},54,"Threat Model","threat-model",{"id":1711,"name":1712,"slug":1713},49,"Controls & Evidence","controls",{"id":1715,"login":1716,"email":1717,"displayName":1718},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1720],{"lang":7,"title":208,"content":210,"contentJson":1721,"excerpt":1685},{"time":212,"blocks":1722,"version":1684},[1723,1726,1729,1732,1735,1738,1741,1744,1747,1750,1753,1756,1759,1762,1765,1768,1780,1783,1786,1789,1792,1795,1807,1810,1813,1816,1833,1836,1839,1854,1857,1860,1863,1866,1869,1872,1875,1878,1881,1884,1887,1890,1893,1896,1899,1914,1917,1920,1923,1926,1929,1932,1935,1938,1941,1944,1947,1950,1953,1956,1959,1962,1965,1968,1971,1974,1977,1980,1983,1986,1989,1992,1995,1998,2001,2004,2007,2010,2013,2016,2019,2031,2034,2037,2040,2043,2046,2049,2052,2055,2058,2061,2064,2067,2070,2073,2088,2091,2094,2097,2100,2103,2120,2123,2126,2129,2132,2135,2152,2155,2158,2161,2164,2167,2170,2173,2176,2179,2182,2185,2188,2191,2202,2205,2216,2219,2222,2225,2241,2244,2265,2268,2285,2288,2303,2306,2309,2312,2315,2318,2321,2324,2327,2330,2333,2336,2339,2342,2345,2348,2351,2365,2368,2384,2387,2390,2393,2396,2399,2402,2407,2412,2417,2422,2427,2432,2437],{"id":215,"data":1724,"type":218,"tunes":1725},{"text":217},{},{"id":221,"data":1727,"type":226,"tunes":1728},{"body":223,"title":224,"variant":225},{},{"id":229,"data":1730,"type":226,"tunes":1731},{"body":231,"title":232,"variant":233},{},{"id":236,"data":1733,"type":226,"tunes":1734},{"body":238,"title":239,"variant":233},{},{"id":242,"data":1736,"type":226,"tunes":1737},{"body":244,"title":245,"variant":246},{},{"id":249,"data":1739,"type":254,"tunes":1740},{"title":251,"maxLevel":252,"minLevel":253},{},{"id":257,"data":1742,"type":42,"tunes":1743},{"text":259,"level":253},{},{"id":262,"data":1745,"type":218,"tunes":1746},{"text":264},{},{"id":267,"data":1748,"type":218,"tunes":1749},{"text":269},{},{"id":272,"data":1751,"type":218,"tunes":1752},{"text":274},{},{"id":277,"data":1754,"type":42,"tunes":1755},{"text":279,"level":253},{},{"id":282,"data":1757,"type":218,"tunes":1758},{"text":284},{},{"id":287,"data":1760,"type":218,"tunes":1761},{"text":289},{},{"id":292,"data":1763,"type":218,"tunes":1764},{"text":294},{},{"id":297,"data":1766,"type":218,"tunes":1767},{"text":299},{},{"id":302,"data":1769,"type":331,"tunes":1779},{"steps":1770,"title":329,"orientation":330},[1771,1772,1773,1774,1775,1776,1777,1778],{"label":306,"description":307},{"label":309,"description":310},{"label":312,"description":313},{"label":315,"description":316},{"label":318,"description":319},{"label":321,"description":322},{"label":324,"description":325},{"label":327,"description":328},{},{"id":334,"data":1781,"type":42,"tunes":1782},{"text":336,"level":253},{},{"id":339,"data":1784,"type":218,"tunes":1785},{"text":341},{},{"id":344,"data":1787,"type":218,"tunes":1788},{"text":346},{},{"id":349,"data":1790,"type":218,"tunes":1791},{"text":351},{},{"id":354,"data":1793,"type":42,"tunes":1794},{"text":356,"level":253},{},{"id":359,"data":1796,"type":394,"tunes":1806},{"content":1797,"stretched":43,"withHeadings":14},[1798,1799,1800,1801,1802,1803,1804,1805],[363,364,365],[367,368,369],[371,372,373],[375,376,377],[379,380,381],[383,384,385],[387,388,389],[391,392,393],{},{"id":397,"data":1808,"type":218,"tunes":1809},{"text":399},{},{"id":402,"data":1811,"type":218,"tunes":1812},{"text":404},{},{"id":407,"data":1814,"type":42,"tunes":1815},{"text":409,"level":253},{},{"id":412,"data":1817,"type":444,"tunes":1832},{"rows":1818,"title":436,"layout":394,"columns":1829},[1819,1821,1823,1825,1827],{"id":416,"label":417,"values":1820},{"strict":419,"disconnected":419},{"id":421,"label":422,"values":1822},{"strict":419,"disconnected":419},{"id":425,"label":426,"values":1824},{"strict":419,"disconnected":419},{"id":429,"label":430,"values":1826},{"strict":419,"disconnected":419},{"id":433,"label":434,"values":1828},{"strict":419,"disconnected":419},[1830,1831],{"id":439,"label":440},{"id":442,"label":443},{},{"id":447,"data":1834,"type":226,"tunes":1835},{"body":449,"title":450,"variant":451},{},{"id":454,"data":1837,"type":42,"tunes":1838},{"text":456,"level":253},{},{"id":459,"data":1840,"type":394,"tunes":1853},{"content":1841,"stretched":43,"withHeadings":14},[1842,1843,1844,1845,1846,1847,1848,1849,1850,1851,1852],[463,464],[466,467],[469,470],[472,473],[475,476],[478,479],[481,482],[484,485],[487,488],[490,491],[493,494],{},{"id":497,"data":1855,"type":218,"tunes":1856},{"text":499},{},{"id":502,"data":1858,"type":218,"tunes":1859},{"text":504},{},{"id":507,"data":1861,"type":42,"tunes":1862},{"text":509,"level":253},{},{"id":512,"data":1864,"type":218,"tunes":1865},{"text":514},{},{"id":517,"data":1867,"type":218,"tunes":1868},{"text":519},{},{"id":522,"data":1870,"type":218,"tunes":1871},{"text":524},{},{"id":527,"data":1873,"type":42,"tunes":1874},{"text":529,"level":253},{},{"id":532,"data":1876,"type":218,"tunes":1877},{"text":534},{},{"id":537,"data":1879,"type":218,"tunes":1880},{"text":539},{},{"id":542,"data":1882,"type":218,"tunes":1883},{"text":544},{},{"id":547,"data":1885,"type":42,"tunes":1886},{"text":549,"level":253},{},{"id":552,"data":1888,"type":218,"tunes":1889},{"text":554},{},{"id":557,"data":1891,"type":218,"tunes":1892},{"text":559},{},{"id":562,"data":1894,"type":218,"tunes":1895},{"text":564},{},{"id":567,"data":1897,"type":42,"tunes":1898},{"text":569,"level":253},{},{"id":572,"data":1900,"type":394,"tunes":1913},{"content":1901,"stretched":43,"withHeadings":14},[1902,1903,1904,1905,1906,1907,1908,1909,1910,1911,1912],[576,577],[579,580],[582,583],[585,586],[588,589],[591,592],[594,595],[597,598],[600,601],[603,604],[606,607],{},{"id":610,"data":1915,"type":42,"tunes":1916},{"text":612,"level":253},{},{"id":615,"data":1918,"type":218,"tunes":1919},{"text":617},{},{"id":620,"data":1921,"type":218,"tunes":1922},{"text":622},{},{"id":625,"data":1924,"type":218,"tunes":1925},{"text":627},{},{"id":630,"data":1927,"type":42,"tunes":1928},{"text":632,"level":253},{},{"id":635,"data":1930,"type":218,"tunes":1931},{"text":637},{},{"id":640,"data":1933,"type":218,"tunes":1934},{"text":642},{},{"id":645,"data":1936,"type":218,"tunes":1937},{"text":647},{},{"id":650,"data":1939,"type":218,"tunes":1940},{"text":652},{},{"id":655,"data":1942,"type":661,"tunes":1943},{"url":657,"title":658,"excerpt":659,"ctaLabel":660},{},{"id":664,"data":1945,"type":42,"tunes":1946},{"text":666,"level":253},{},{"id":669,"data":1948,"type":218,"tunes":1949},{"text":671},{},{"id":674,"data":1951,"type":218,"tunes":1952},{"text":676},{},{"id":679,"data":1954,"type":218,"tunes":1955},{"text":681},{},{"id":684,"data":1957,"type":42,"tunes":1958},{"text":686,"level":253},{},{"id":689,"data":1960,"type":218,"tunes":1961},{"text":691},{},{"id":694,"data":1963,"type":218,"tunes":1964},{"text":696},{},{"id":699,"data":1966,"type":218,"tunes":1967},{"text":701},{},{"id":704,"data":1969,"type":42,"tunes":1970},{"text":706,"level":253},{},{"id":709,"data":1972,"type":218,"tunes":1973},{"text":711},{},{"id":714,"data":1975,"type":218,"tunes":1976},{"text":716},{},{"id":719,"data":1978,"type":218,"tunes":1979},{"text":721},{},{"id":724,"data":1981,"type":42,"tunes":1982},{"text":726,"level":253},{},{"id":729,"data":1984,"type":218,"tunes":1985},{"text":731},{},{"id":734,"data":1987,"type":218,"tunes":1988},{"text":736},{},{"id":739,"data":1990,"type":218,"tunes":1991},{"text":741},{},{"id":744,"data":1993,"type":42,"tunes":1994},{"text":746,"level":253},{},{"id":749,"data":1996,"type":218,"tunes":1997},{"text":751},{},{"id":754,"data":1999,"type":218,"tunes":2000},{"text":756},{},{"id":759,"data":2002,"type":218,"tunes":2003},{"text":761},{},{"id":764,"data":2005,"type":42,"tunes":2006},{"text":766,"level":253},{},{"id":769,"data":2008,"type":218,"tunes":2009},{"text":771},{},{"id":774,"data":2011,"type":218,"tunes":2012},{"text":776},{},{"id":779,"data":2014,"type":218,"tunes":2015},{"text":781},{},{"id":784,"data":2017,"type":42,"tunes":2018},{"text":786,"level":253},{},{"id":789,"data":2020,"type":331,"tunes":2030},{"steps":2021,"title":816,"orientation":330},[2022,2023,2024,2025,2026,2027,2028,2029],{"label":793,"description":794},{"label":796,"description":797},{"label":799,"description":800},{"label":802,"description":803},{"label":805,"description":806},{"label":808,"description":809},{"label":811,"description":812},{"label":814,"description":815},{},{"id":819,"data":2032,"type":42,"tunes":2033},{"text":821,"level":253},{},{"id":824,"data":2035,"type":218,"tunes":2036},{"text":826},{},{"id":829,"data":2038,"type":218,"tunes":2039},{"text":831},{},{"id":834,"data":2041,"type":218,"tunes":2042},{"text":836},{},{"id":839,"data":2044,"type":42,"tunes":2045},{"text":841,"level":253},{},{"id":844,"data":2047,"type":218,"tunes":2048},{"text":846},{},{"id":849,"data":2050,"type":218,"tunes":2051},{"text":851},{},{"id":854,"data":2053,"type":218,"tunes":2054},{"text":856},{},{"id":859,"data":2056,"type":42,"tunes":2057},{"text":861,"level":253},{},{"id":864,"data":2059,"type":218,"tunes":2060},{"text":866},{},{"id":869,"data":2062,"type":218,"tunes":2063},{"text":871},{},{"id":874,"data":2065,"type":218,"tunes":2066},{"text":876},{},{"id":879,"data":2068,"type":42,"tunes":2069},{"text":881,"level":253},{},{"id":884,"data":2071,"type":226,"tunes":2072},{"body":886,"title":887,"variant":246},{},{"id":890,"data":2074,"type":394,"tunes":2087},{"content":2075,"stretched":43,"withHeadings":14},[2076,2077,2078,2079,2080,2081,2082,2083,2084,2085,2086],[894,895],[897,898],[900,901],[903,904],[906,907],[909,910],[912,913],[915,916],[918,919],[921,922],[924,925],{},{"id":928,"data":2089,"type":42,"tunes":2090},{"text":930,"level":253},{},{"id":933,"data":2092,"type":218,"tunes":2093},{"text":935},{},{"id":938,"data":2095,"type":218,"tunes":2096},{"text":940},{},{"id":943,"data":2098,"type":218,"tunes":2099},{"text":945},{},{"id":948,"data":2101,"type":42,"tunes":2102},{"text":950,"level":253},{},{"id":953,"data":2104,"type":394,"tunes":2119},{"content":2105,"stretched":43,"withHeadings":14},[2106,2107,2108,2109,2110,2111,2112,2113,2114,2115,2116,2117,2118],[957,958],[960,961],[963,964],[966,967],[969,970],[972,973],[975,976],[978,979],[981,982],[984,985],[987,988],[990,991],[993,994],{},{"id":997,"data":2121,"type":42,"tunes":2122},{"text":999,"level":253},{},{"id":1002,"data":2124,"type":218,"tunes":2125},{"text":1004},{},{"id":1007,"data":2127,"type":218,"tunes":2128},{"text":1009},{},{"id":1012,"data":2130,"type":218,"tunes":2131},{"text":1014},{},{"id":1017,"data":2133,"type":42,"tunes":2134},{"text":1019,"level":253},{},{"id":1022,"data":2136,"type":394,"tunes":2151},{"content":2137,"stretched":43,"withHeadings":14},[2138,2139,2140,2141,2142,2143,2144,2145,2146,2147,2148,2149,2150],[1026,1027],[1029,1030],[1032,1033],[1035,1036],[1038,1039],[1041,1042],[1044,1045],[1047,1048],[606,1050],[1052,1053],[1055,1056],[1058,1059],[1061,1062],{},{"id":1065,"data":2153,"type":42,"tunes":2154},{"text":1067,"level":253},{},{"id":1070,"data":2156,"type":218,"tunes":2157},{"text":1072},{},{"id":1075,"data":2159,"type":218,"tunes":2160},{"text":1077},{},{"id":1080,"data":2162,"type":218,"tunes":2163},{"text":1082},{},{"id":1085,"data":2165,"type":42,"tunes":2166},{"text":1087,"level":253},{},{"id":1090,"data":2168,"type":218,"tunes":2169},{"text":1092},{},{"id":1095,"data":2171,"type":218,"tunes":2172},{"text":1097},{},{"id":1100,"data":2174,"type":218,"tunes":2175},{"text":1102},{},{"id":1105,"data":2177,"type":42,"tunes":2178},{"text":1107,"level":253},{},{"id":1110,"data":2180,"type":226,"tunes":2181},{"body":1112,"title":1113,"variant":246},{},{"id":1116,"data":2183,"type":218,"tunes":2184},{"text":1118},{},{"id":1121,"data":2186,"type":218,"tunes":2187},{"text":1123},{},{"id":1126,"data":2189,"type":218,"tunes":2190},{"text":1128},{},{"id":1131,"data":2192,"type":394,"tunes":2201},{"content":2193,"stretched":43,"withHeadings":14},[2194,2195,2196,2197,2198,2199,2200],[1135,1136],[1138,1139],[1141,1142],[1144,1145],[1147,1148],[1150,1151],[1153,1154],{},{"id":1157,"data":2203,"type":42,"tunes":2204},{"text":1159,"level":253},{},{"id":1162,"data":2206,"type":394,"tunes":2215},{"content":2207,"stretched":43,"withHeadings":14},[2208,2209,2210,2211,2212,2213,2214],[1166,1167],[1169,1170],[1172,1173],[1175,1176],[1178,1179],[1181,1182],[1184,1185],{},{"id":1188,"data":2217,"type":218,"tunes":2218},{"text":1190},{},{"id":1193,"data":2220,"type":218,"tunes":2221},{"text":1195},{},{"id":1198,"data":2223,"type":42,"tunes":2224},{"text":1200,"level":253},{},{"id":1203,"data":2226,"type":331,"tunes":2240},{"steps":2227,"title":1242,"orientation":330},[2228,2229,2230,2231,2232,2233,2234,2235,2236,2237,2238,2239],{"label":1207,"description":1208},{"label":1210,"description":1211},{"label":1213,"description":1214},{"label":1216,"description":1217},{"label":1219,"description":1220},{"label":1222,"description":1223},{"label":1225,"description":1226},{"label":1228,"description":1229},{"label":1231,"description":1232},{"label":1234,"description":1235},{"label":1237,"description":1238},{"label":1240,"description":1241},{},{"id":1245,"data":2242,"type":42,"tunes":2243},{"text":1247,"level":253},{},{"id":1250,"data":2245,"type":394,"tunes":2264},{"content":2246,"stretched":43,"withHeadings":14},[2247,2248,2249,2250,2251,2252,2253,2254,2255,2256,2257,2258,2259,2260,2261,2262,2263],[1254,1255],[1257,1258],[1260,1261],[1263,1264],[1266,1267],[1269,1270],[1272,1273],[1275,1276],[1278,1279],[1281,1282],[1284,1285],[1287,1288],[1290,1291],[1293,1294],[1296,1297],[1299,1300],[1302,1303],{},{"id":1306,"data":2266,"type":42,"tunes":2267},{"text":1308,"level":253},{},{"id":1311,"data":2269,"type":394,"tunes":2284},{"content":2270,"stretched":43,"withHeadings":14},[2271,2272,2273,2274,2275,2276,2277,2278,2279,2280,2281,2282,2283],[1315,1316],[1318,1319],[1321,1322],[1324,1325],[1327,1328],[1330,1331],[1333,1334],[1336,1337],[1339,1340],[1342,1343],[1345,1346],[1348,1349],[1351,1352],{},{"id":1355,"data":2286,"type":42,"tunes":2287},{"text":1357,"level":253},{},{"id":1360,"data":2289,"type":394,"tunes":2302},{"content":2290,"stretched":43,"withHeadings":14},[2291,2292,2293,2294,2295,2296,2297,2298,2299,2300,2301],[1364,1365],[1367,1368],[1370,1371],[1373,1374],[1376,1377],[1379,1380],[1382,1383],[1385,1386],[1388,1389],[1391,1392],[1394,1395],{},{"id":1398,"data":2304,"type":42,"tunes":2305},{"text":1400,"level":253},{},{"id":1403,"data":2307,"type":218,"tunes":2308},{"text":1405},{},{"id":1408,"data":2310,"type":218,"tunes":2311},{"text":1410},{},{"id":1413,"data":2313,"type":218,"tunes":2314},{"text":1415},{},{"id":1418,"data":2316,"type":218,"tunes":2317},{"text":1420},{},{"id":1423,"data":2319,"type":218,"tunes":2320},{"text":1425},{},{"id":1428,"data":2322,"type":42,"tunes":2323},{"text":1430,"level":253},{},{"id":1433,"data":2325,"type":218,"tunes":2326},{"text":1435},{},{"id":1438,"data":2328,"type":218,"tunes":2329},{"text":1440},{},{"id":1443,"data":2331,"type":218,"tunes":2332},{"text":1445},{},{"id":1448,"data":2334,"type":42,"tunes":2335},{"text":1450,"level":253},{},{"id":1453,"data":2337,"type":218,"tunes":2338},{"text":1455},{},{"id":1458,"data":2340,"type":218,"tunes":2341},{"text":1460},{},{"id":1463,"data":2343,"type":218,"tunes":2344},{"text":1465},{},{"id":1468,"data":2346,"type":661,"tunes":2347},{"url":1470,"title":1471,"excerpt":1472,"ctaLabel":1473},{},{"id":1476,"data":2349,"type":42,"tunes":2350},{"text":1478,"level":253},{},{"id":1481,"data":2352,"type":1481,"tunes":2364},{"items":2353,"title":1524},[2354,2355,2356,2357,2358,2359,2360,2361,2362,2363],{"id":1485,"answer":1486,"question":1487},{"id":1489,"answer":1490,"question":1491},{"id":1493,"answer":1494,"question":1495},{"id":1497,"answer":1498,"question":1499},{"id":1501,"answer":1502,"question":1503},{"id":1505,"answer":1506,"question":1507},{"id":1509,"answer":1510,"question":1511},{"id":1513,"answer":1514,"question":1515},{"id":1517,"answer":1518,"question":1519},{"id":1521,"answer":1522,"question":1523},{},{"id":1527,"data":2366,"type":42,"tunes":2367},{"text":1529,"level":253},{},{"id":1532,"data":2369,"type":1532,"tunes":2383},{"title":1534,"entries":2370},[2371,2372,2373,2374,2375,2376,2377,2378,2379,2380,2381,2382],{"term":1537,"anchor":1538,"definition":1539},{"term":387,"anchor":1541,"definition":1542},{"term":375,"anchor":1544,"definition":1545},{"term":371,"anchor":1547,"definition":1548},{"term":367,"anchor":1550,"definition":1551},{"term":1553,"anchor":1554,"definition":1555},{"term":1557,"anchor":1558,"definition":1559},{"term":1561,"anchor":1562,"definition":1563},{"term":1565,"anchor":1566,"definition":1567},{"term":1569,"anchor":1570,"definition":1571},{"term":1573,"anchor":1574,"definition":1575},{"term":1577,"anchor":1578,"definition":1579},{},{"id":1582,"data":2385,"type":42,"tunes":2386},{"text":1584,"level":253},{},{"id":1587,"data":2388,"type":218,"tunes":2389},{"text":1589},{},{"id":1592,"data":2391,"type":218,"tunes":2392},{"text":1594},{},{"id":1597,"data":2394,"type":218,"tunes":2395},{"text":1599},{},{"id":1602,"data":2397,"type":42,"tunes":2398},{"text":1604,"level":253},{},{"id":1607,"data":2400,"type":218,"tunes":2401},{"text":1609},{},{"id":1612,"data":2403,"type":1619,"tunes":2406},{"link":1614,"meta":2404},{"image":2405,"title":1617,"description":1618},{"url":419},{},{"id":1622,"data":2408,"type":1619,"tunes":2411},{"link":1624,"meta":2409},{"image":2410,"title":1627,"description":1628},{"url":419},{},{"id":1631,"data":2413,"type":1619,"tunes":2416},{"link":1633,"meta":2414},{"image":2415,"title":1636,"description":1637},{"url":419},{},{"id":1640,"data":2418,"type":1619,"tunes":2421},{"link":1642,"meta":2419},{"image":2420,"title":1645,"description":1646},{"url":419},{},{"id":1649,"data":2423,"type":1619,"tunes":2426},{"link":1651,"meta":2424},{"image":2425,"title":1654,"description":1655},{"url":419},{},{"id":1658,"data":2428,"type":1619,"tunes":2431},{"link":1660,"meta":2429},{"image":2430,"title":1663,"description":1664},{"url":419},{},{"id":1667,"data":2433,"type":1619,"tunes":2436},{"link":1669,"meta":2434},{"image":2435,"title":1672,"description":1673},{"url":419},{},{"id":1676,"data":2438,"type":1619,"tunes":2441},{"link":1678,"meta":2439},{"image":2440,"title":1681,"description":1682},{"url":419},{},"Post erfolgreich abgerufen",{"items":2444,"source":2527,"manualIds":2528,"manualMatchedIds":2529},[2445,2452,2459,2465,2472,2479,2486,2493,2500,2507,2514,2521],{"id":2446,"slug":2447,"title":2448,"excerpt":2449,"featuredImage":2450,"publishedAt":2451},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","What Is an AI Platform Architect? Models, Data, Runtime, Security and Operations","An AI Platform Architect designs reusable AI foundations across models, providers, retrieval, agents, identity, security, evaluation, observability and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":2453,"slug":2454,"title":2455,"excerpt":2456,"featuredImage":2457,"publishedAt":2458},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","Vector Databases, Embeddings and Reranking: Three Different Parts of Retrieval","Embeddings represent meaning, vector databases retrieve candidates, and rerankers refine results. Learn how these three retrieval layers differ and work together in RAG.","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":2460,"slug":2461,"title":1471,"excerpt":2462,"featuredImage":2463,"publishedAt":2464},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","Agent memory, RAG, state, and context are often used as if they were interchangeable. They are not. This practical architecture model separates the four layers, shows where each belongs, and explains what breaks when systems collapse them into one.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":2466,"slug":2467,"title":2468,"excerpt":2469,"featuredImage":2470,"publishedAt":2471},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP Explained: What It Connects, What It Does Not Do and Where It Fits","Model Context Protocol connects AI applications to external tools, resources and prompts through a standard client-server boundary. Learn what MCP does, what it does not do, and where it fits in agent architecture.","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":2473,"slug":2474,"title":2475,"excerpt":2476,"featuredImage":2477,"publishedAt":2478},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","Where Does an LLM Get Its Data? RAG Data Sources in Python","An LLM does not magically know your files, databases or APIs. This practical continuation of the RAG series shows, with simple Python, how external data becomes retrievable evidence: from text files and SQL to full-text search, embeddings, context assembly and the final LLM call.","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":2480,"slug":2481,"title":2482,"excerpt":2483,"featuredImage":2484,"publishedAt":2485},"381","enterprise-grade-multi-tenant-architecture-for-an-international-platform","Enterprise-Grade Multi-Tenant Architecture for an International Platform","Loving Rocks is an enterprise-grade wedding platform designed with a true multi-tenant architecture, isolated databases per tenant, and built-in internationalization for global scalability, security, and long-term operational stability.","\u002Fuploads\u002F2026\u002F01\u002Fenterprise-grade-multi-tenant-architecture-for-an-international-platform-1769789121298-b6v7ak.webp","2026-01-30T12:04:00.000Z",{"id":2487,"slug":2488,"title":2489,"excerpt":2490,"featuredImage":2491,"publishedAt":2492},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","What Should an AI Agent Remember, Forget, Recompute or Retrieve Again?","Long-running agents should not remember everything. This article provides a practical lifecycle model for deciding what belongs in durable memory, what should be retrieved again, what is safer to recompute, and what should expire or be superseded.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":2494,"slug":2495,"title":2496,"excerpt":2497,"featuredImage":2498,"publishedAt":2499},"486","source-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from","Source of Truth in AI Systems: Where Reliable Knowledge Actually Comes From","A Source of Truth defines which source is authoritative for a specific fact or state. Learn how it differs from RAG, provenance, memory, context, vector databases and systems of record.","\u002Fuploads\u002F2026\u002F10\u002Fsource-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from-1791479103235-6bq9em.webp","2026-10-08T13:02:00.000Z",{"id":2501,"slug":2502,"title":2503,"excerpt":2504,"featuredImage":2505,"publishedAt":2506},"467","the-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","A source can be relevant, authoritative and still be wrong for the question being asked. The missing layer is applicability: the conditions under which an answer holds, and the changes that force it to be reconsidered. This article introduces the Answer Validity Boundary as a source-design pattern for humans, AI search and RAG systems.","\u002Fuploads\u002F2026\u002F09\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers-1790272901306-1g5jly.webp","2026-09-24T11:59:00.000Z",{"id":2508,"slug":2509,"title":2510,"excerpt":2511,"featuredImage":2512,"publishedAt":2513},"485","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","Enterprise AI Architecture: What Changes When AI Enters a Company","Enterprise AI architecture explains how AI changes company systems across data authority, identity, permissions, providers, risk, governance, evaluation, compliance and operations.","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","2026-10-08T10:48:00.000Z",{"id":2515,"slug":2516,"title":2517,"excerpt":2518,"featuredImage":2519,"publishedAt":2520},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","What Is an AI Solution Architect? System Boundaries, Responsibilities and Trade-offs","An AI Solution Architect turns business requirements into a production-ready AI system across data, models, tools, security, runtime, evaluation and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":2522,"slug":2523,"title":658,"excerpt":2524,"featuredImage":2525,"publishedAt":2526},"478","what-is-rag-the-simplest-explanation-of-how-it-works","RAG sounds complicated, but the idea is simple: before an AI answers, it first looks up useful information from a knowledge source and gives that information to the language model. This guide explains RAG, LLMs, state, memory and tools using one simple mental model.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works-1790377492124-khjagt.webp","2026-09-25T19:03:00.000Z","fallback",[],[]]