Air-Gapped AI for Manufacturing and Defense
Air-gapped AI runs source-cited LLMs on ITAR and EAR controlled drawings and specs inside a contractor's own OT/IT perimeter, so no controlled data leaves.
Air-gapped AI for manufacturing and defense is a large language model and retrieval system that runs entirely inside a company’s own controlled network, so engineering drawings, specifications, and export-controlled technical data are never sent to a hosted model API. For manufacturers, defense contractors, and their suppliers, this is the difference between an AI tool that is deployable under export-control scrutiny and one that is not: the controlled data stays inside the perimeter, foreign-person and cross-border exposure is removed by construction, and every answer can be traced to its source. This page explains why controlled technical data cannot flow through hosted LLMs, how on-premise AI respects the OT/IT air gap, and how retrieval works on engineering documents. It is general awareness, not legal or export-control advice.
Why can’t defense contractors send technical data to hosted LLMs?
Defense contractors and manufacturers of controlled hardware cannot route export-controlled technical data through a hosted LLM because doing so can transfer that data outside the company’s control, to a third-party operator whose staff and infrastructure the company never vetted. A single prompt containing a controlled drawing, a materials spec, or a design parameter can cross a network boundary where it may be logged, cached, or read by persons who are not authorized to receive it.
For a company handling controlled technical data, three specific risks make hosted LLMs unacceptable:
- Unauthorized disclosure. Sending controlled data to an external service can expose it to persons, including foreign persons, who are not cleared to access it.
- Cross-border transfer. The provider’s servers and support staff may sit in another country, creating a transfer the company never authorized.
- Loss of custody and proof. Once the data leaves the perimeter, the company cannot state with certainty where it was processed or who could read it, which is exactly what an auditor will ask.
The cleanest fix is architectural, not contractual: do not send the controlled data across the boundary at all. Teclops AI develops that reasoning in why your AI shouldn’t leave your walls.
What do ITAR and EAR mean for where AI can run?
ITAR (the International Traffic in Arms Regulations) and EAR (the Export Administration Regulations) are U.S. export-control regimes that restrict who may access controlled technical data and where it may be transferred, including access by foreign persons and transfers across national borders. Neither regime names AI specifically, but the shared principle is well established: controlled technical data must stay within an authorized boundary and an authorized set of people. Because a hosted LLM moves your prompt to someone else’s infrastructure and staff, it can create exactly the transfer these regimes are designed to control.
That principle is what pushes many manufacturers and defense suppliers toward on-premise or air-gapped AI: keeping the model, the index, and the inference inside a network the company governs means there is no external transfer to authorize, monitor, or defend. Export-control obligations are fact-specific and enforcement carries real penalties, so treat this as general awareness and confirm your own position with qualified export-control counsel. The related question of jurisdiction over data is covered in where your AI data lives and why sovereignty matters.
What is the OT/IT air gap, and where does AI fit?
The OT/IT air gap is the isolation boundary between operational technology (the plant-floor control systems, PLCs, and SCADA that run production and safety) and the enterprise IT network (email, ERP, and document systems). Industrial environments segment these deliberately, often along the layered model many plants use, so that an IT-side compromise cannot reach machinery or safety systems. This boundary is a constraint any AI deployment must respect rather than ignore.
For AI in a manufacturing setting, the OT/IT air gap has two implications:
- AI belongs where the data and the users are. A document assistant for engineers, quality, and procurement lives on the IT side, reading drawings, specs, work instructions, and supplier records, and needs no path into control systems.
- Any OT-adjacent use must honor segmentation. If AI reads exported plant or machine data, that data should cross the boundary through the same controlled, one-directional paths the plant already uses, not through a new outbound internet connection.
An air-gapped or on-premise AI system fits this model naturally because it introduces no outbound connectivity of its own. It runs inside the segment where it is deployed, so it neither weakens the OT/IT boundary nor depends on the internet the plant intentionally keeps out.
How do you run AI on engineering drawings and specs on-prem?
You run AI on engineering drawings and specifications on-premise by ingesting those documents into a local retrieval index on hardware the company controls, then serving a locally hosted model that answers questions strictly from that indexed content. Retrieval-augmented generation (RAG) means the system searches your own technical documents, pulls the relevant passages, and feeds them to a local model that answers from that text with citations. Nothing is sent to an external endpoint.
In an on-premise deployment for engineering and manufacturing, every hop stays internal:
- Local model serving. Open-weight model weights are loaded onto GPUs inside the controlled zone, so no prompt reaches a hosted API.
- Local document index. Drawings, specifications, standards, bills of materials, work instructions, and test reports are ingested and indexed inside the perimeter, and the source files never leave.
- Grounded answers with citations. An engineer or quality lead asks a question, retrieval finds the matching passages, and the local model answers, citing the exact source document.
- Offline updates. New model versions and patches are staged and verified separately, then carried in under change control, matching the configuration discipline regulated manufacturers already apply.
Model choice is a license and hardware decision, not a popularity contest. The ordered method is in how to choose an open-weight LLM for on-premise use.
Hosted LLM vs air-gapped AI for controlled technical data
The table below compares a hosted LLM API against air-gapped on-premise AI on the axes a manufacturer’s security, export-control, and engineering leads actually evaluate.
| Property | Hosted LLM API | Air-gapped on-prem AI |
|---|---|---|
| Where data is processed | Provider’s servers, possibly cross-border | Inside the company’s own network |
| Controlled data leaves perimeter | Yes, every request | No |
| Foreign-person access risk | Present and hard to bound | Controlled by the company |
| Used for model training | Depends on contract terms | No path to external training |
| OT/IT segmentation | New outbound path required | No outbound connectivity introduced |
| Answer traceability | Often none | Cited to the exact source document |
| Audit trail | Limited to provider exposure | Full, tamper-evident, internal |
| Operational effort | Low | Higher, but under your control |
The hosted API wins on convenience. The air-gapped deployment wins on every axis an export-control officer or an auditor cares about, which is why it is the default posture for controlled drawings, specifications, and anything touching defense programs.
How do you keep engineering AI accurate and auditable?
You keep on-premise engineering AI trustworthy by grounding every answer in retrieved source documents and logging every interaction. A raw LLM can produce fluent, confident, wrong statements, which is dangerous when the answer concerns a tolerance, a material grade, or a compliance clause. Three controls make output defensible:
- Source citation. The system answers only from the company’s own documents and cites the exact passage, so an engineer can verify it against the controlled drawing or spec.
- Refusal on absence. When the answer is not in the sources, the system says so plainly instead of guessing.
- Tamper-evident audit log. Every query and answer is recorded so a security or export-control reviewer can reconstruct who asked what, and where each answer came from.
Permission awareness at the role and row level ensures a user only receives answers drawn from documents they are cleared to access, which matters directly where program-level or need-to-know restrictions apply. Teclops AI treats these controls as the product, not an add-on. See the security and data-sovereignty model.
How do Samvad AI and Gist fit a manufacturing or defense deployment?
Samvad AI is a source-cited RAG assistant built for exactly this setting. It deploys on-premise, air-gapped, or hybrid, switchable by configuration, answers only from your own documents, cites the exact source passage for every answer, and says plainly when an answer is not in your sources. It is permission-aware at the role and row level, multilingual, and writes to a tamper-evident audit log, all inside a network the company controls, so engineers, quality, and procurement can query drawings, specs, standards, and supplier records without any controlled data leaving the perimeter.
For numbers rather than documents, Gist governed analytics lets business users ask questions in plain language and get trustworthy charts with no SQL, over a governed semantic layer with row- and column-level security. Both run inside the client’s own infrastructure, and a deployment can be scoped and served through Teclops AI’s AI product and consultancy services. Air-gapped, source-grounded AI is now a practical option for manufacturing and defense, not a research aspiration: keep the model and the controlled data inside your walls, cite every answer, and log every query.
Frequently asked questions
Can defense contractors use ChatGPT or hosted LLMs on ITAR-controlled technical data?
Generally no. Export-controlled technical data under ITAR is restricted in who may access it and where it may be sent, so routing it to a third-party hosted LLM can constitute an unauthorized export or disclosure. Air-gapped AI keeps both the model and the data inside the contractor’s own controlled network. This is general awareness, not legal or export-control advice.
What is the OT/IT air gap in a manufacturing plant?
The OT/IT air gap is the isolation boundary between operational technology (plant-floor control systems, PLCs, and SCADA) and the enterprise IT network. It protects production and safety systems from IT-side threats, which means any AI touching plant data must respect that segmentation rather than assume open connectivity.
How can AI read engineering drawings without sending them to the cloud?
An on-premise retrieval system ingests engineering drawings, specs, and technical documents into a local index on hardware the company controls, then a locally hosted model answers questions from those documents with citations. Because the drawings and the model both stay inside the perimeter, no controlled technical data is transmitted to an external service.
Does ITAR or EAR say where AI models and data can physically run?
ITAR and EAR do not name AI specifically, but both restrict who may access controlled technical data and where it may be transferred, including access by foreign persons and transfers across borders. In practice that pushes many contractors toward on-premise or air-gapped deployment. Confirm your obligations with qualified export-control counsel.
Is on-premise AI enough to satisfy export-control and CUI handling requirements?
On-premise or air-gapped AI removes the cross-boundary transfer that hosted APIs create, which addresses a major exposure, but full compliance also depends on access controls, personnel screening, physical security, and audit practices. The architecture is a foundation, not a complete compliance program, so validate the whole control set with counsel.