What is this course about?
Some agency work cannot touch a network that reaches the internet, and the AI conversation usually stops there. This course covers what sovereignty means concretely, open-weight model selection for a disconnected environment, the capability you trade away, update paths across an air gap, and monitoring without cloud telemetry.
Who is this course for?
- Agency infrastructure and platform engineers
- Security architects in classified environments
- Mission system owners
- Defense and intelligence technical staff
What do I need before starting?
- Experience operating in restricted network environments
- Infrastructure and systems background
What will I be able to do afterwards?
- Define sovereignty concretely across code, weights, data, and operations
- Select open-weight models appropriate to a disconnected environment
- Size hardware and state the capability trade-off honestly
- Design update and patch paths across an air gap
- Monitor and respond to incidents without cloud telemetry
What does each module cover?
What does sovereignty actually mean here?
45 minCode, weights, data, and operations as four separate questions vendors answer selectively.
Objectives
- Decompose sovereignty into its four components
- Assess a vendor claim against all four
- Determine which components your mission requires
Topics
Activity. Assess three vendor sovereignty claims against the four-component framework.
Which models can you run disconnected?
55 minOpen-weight model selection, licensing, and what is actually deployable without a callback.
Objectives
- Evaluate open-weight models for disconnected deployment
- Assess licence terms for government use
- Verify no runtime external dependency
Topics
Activity. Verify one candidate model runs with network egress fully blocked.
What capability do you give up?
55 minThe honest gap between frontier hosted models and what you can run on agency hardware.
Objectives
- Quantify the capability gap for your workloads
- Determine whether the gap matters for the mission
- Design around the limitations
Topics
Activity. Benchmark a deployable model against your actual mission tasks.
How do you size the hardware?
50 minGPU sizing, concurrency, and the capacity planning a disconnected deployment requires up front.
Objectives
- Size hardware for expected concurrency
- Plan for peak versus sustained load
- Budget for growth without a cloud escape valve
Topics
Activity. Size hardware for a stated concurrency requirement and validate under load.
How do updates cross the air gap?
50 minPatching, model updates, and content refresh through a controlled transfer process.
Objectives
- Design a controlled update transfer process
- Verify integrity of transferred artifacts
- Plan update cadence realistically
Topics
Activity. Design the update path and verify artifact integrity end to end.
How do you monitor without cloud telemetry?
50 minObservability and incident response when nothing can phone home.
Objectives
- Build monitoring entirely inside the enclave
- Design incident response without vendor support
- Retain enough evidence for after-action review
Topics
Activity. Build the monitoring stack inside the enclave and run an incident tabletop.
How do you buy sovereignty rather than a promise?
45 minProcurement terms that make sovereignty an enforceable deliverable.
Objectives
- Write contract terms delivering actual sovereignty
- Require source code and weight delivery
- Specify what happens if the vendor disappears
Topics
Activity. Draft the sovereignty clauses for a solicitation.
Building the air-gapped reference architecture
60 minThe workshop module: a complete architecture with a threat model.
Objectives
- Produce a complete air-gapped architecture
- Document the threat model
- Identify the residual risks
Topics
Activity. Complete the architecture and threat model, then peer review it.
What is the capstone project?
Air-gapped AI reference architecture with a threat model
Produce a complete disconnected deployment design: sovereignty assessment, model selection with verified no-egress operation, hardware sizing validated under load, update transfer path, in-enclave monitoring, and a documented threat model with residual risks.
Deliverable: A reference architecture with verified no-egress operation and a peer-reviewed threat model.
How are learners assessed?
- No-egress operation verified with network monitoring, not configuration review
- Capability benchmark run against real mission tasks
- Threat model peer-reviewed for completeness
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for government.
Where does the course material come from?
Every module is grounded in primary sources โ the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Artificial Intelligence
CISA
Federal guidance on securing AI in restricted environments.
- NIST SP 800-53 Rev. 5
NIST
Control requirements for the enclave design.
- NIST SP 800-171 Rev. 3
NIST
Controlled unclassified information requirements.
- Transformers documentation
Hugging Face
Technical reference for self-hosted open-weight model deployment.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 3 must be honest about the capability gap. Overstating what runs on agency hardware sets up a failed deployment and destroys credibility for the next one.
- Verification in Module 2 must be empirical โ block egress and observe. Vendor claims about offline operation are frequently wrong in ways only testing reveals.
- Do not include any classified content or examples. Build the course at the unclassified level so it can be delivered widely, and note where classified guidance would apply.
- Module 7's continuity clause matters more than agencies expect. A sovereign deployment whose vendor vanishes is only sovereign if the source and weights were actually delivered.
- Re-verify the open-weight model landscape at every revision โ licences and capability change fast, and a stale model recommendation is actively harmful.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter โ you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM โ Claude, GPT, Llama, Gemini, Command โ and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped โ including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Sovereign and Air-Gapped AI for Public Agencies course cover?
Some agency work cannot touch a network that reaches the internet, and the AI conversation usually stops there. This course covers what sovereignty means concretely, open-weight model selection for a disconnected environment, the capability you trade away, update paths across an air gap, and monitoring without cloud telemetry. It runs 6.5 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Air-gapped AI reference architecture with a threat model.
Who should take Sovereign and Air-Gapped AI for Public Agencies?
It is written for Agency infrastructure and platform engineers, Security architects in classified environments, Mission system owners, Defense and intelligence technical staff. Prerequisites: Experience operating in restricted network environments; Infrastructure and systems background.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere โ cloud, private VPC, on-premise, or fully air-gapped โ and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for government teams that cannot send work to a public AI tool.
How do we get access to Sovereign and Air-Gapped AI for Public Agencies?
Request access and we will set it up for your cohort โ hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for government cost on ibl.ai?
There is no per-seat pricing โ you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.