Deployment
Air-gapped AI and data sovereignty for UAE audit teams
Why where your documents live is the first question UAE audit and risk teams ask of any AI vendor, and how deployment choices answer it.
When an audit or risk team in the UAE evaluates an AI tool, the workflow demo is rarely the sticking point. The sticking point is a shorter question, usually from IT or security: where do our documents go? Audit corpora are among the most sensitive material an organisation holds (contracts, controls, findings, the map of what could go wrong), and the answer to that one question decides whether a tool is even in the running.
Why the question is sharper here
Organisations operating in the UAE answer to sector regulators and to their own internal policies, on top of data-residency expectations, and all of those treat where data is processed as a first-order concern. For government-linked entities, banks and other regulated bodies, "it sits in a vendor’s cloud somewhere" is not an acceptable answer. A credible AI vendor lets the customer decide the answer instead of asking them to accept a default.
Three deployment models, three answers
It helps to think of it as a spectrum, running from convenience to full isolation:
- On your infrastructure. The software runs on your servers or private cloud, connected only to the AI endpoints you approve. No vendor cloud sits in the path of your documents.
- Managed. We host and operate it for teams that want the outcome without running the infrastructure, and your configuration still governs which endpoints are used.
- Fully air-gapped. For classified and disconnected environments: entirely self-hosted models, with no internet connection at any point.
The point of offering all three is that data sovereignty stops being a promise and becomes a configuration. You choose which AI services may be used, and you can change that choice. Our approach to each model is set out on the deployment & trust page.
What "air-gapped" actually requires
Air-gapped is a strong word and worth being precise about. A genuinely air-gapped deployment means the models themselves are self-hosted inside your perimeter. No call goes out to an external service to complete a task, because there is no connection to make that call over. That has trade-offs: you operate the environment, and model updates become a deliberate act rather than something that happens invisibly. For the environments that need it, that control is the entire point.
Sovereignty is more than location
Where the data sits is necessary but not sufficient. Two things sit alongside it:
- Access and traceability. Role-based access, and a record of who did what and how the system responded. A reviewer, internal or external, can follow the trail.
- Confidentiality by design. Your documents stay in your environment, under your jurisdiction and your control, and are not used to train models.
Bring your security team to the first meeting. The questions they ask (where does the data live, who can see it, what happens when we leave) are the right ones.
Where to go next
If you are scoping a tool for a UAE team, deployment and workflow are two halves of the same decision. See how the workflow is structured in AI in internal audit: what actually changes, the full selection criteria in how to evaluate internal audit software, or read about Litmus for internal audit teams in the UAE.