24/08/2026
Local AI is not a security solution. It is a compliance cost.
Six months ago we started using agentic AI tools for legacy modernisation, and it means we now understand and rewrite undocumented codebases far faster. With human oversight, at the quality standard we always deliver.
But with every serious client, one question comes up: can the code leave its own environment at all? In most cases, it can, and then the cloud is a perfect solution. Where it cannot, local AI enters the picture, and this is where many get the decision wrong from the beginning.
Because it's not cloud versus local. It's a scale and there are four levels: managed cloud with a frontier model, sovereign Azure PaaS with EU data residency, on-prem on your own GPUs, and finally the fully isolated air-gapped environment. The stricter the level, the bigger the developer trade-off and the steeper the cost curve.
Two things are worth being clear about from the start:
First: the fact that the model runs locally does not mean the system is isolated. The entire chain needs auditing, the model alone is not enough.
Second: on-prem and air-gapped AI are a compliance cost. If you are moving it in-house to save money, you will almost certainly be worse off. If you are doing it because the code cannot leave its environment, this is the only route that works.
We test these on our own infrastructure so that what we recommend is a proven solution, not a promise.
Read the full article: https://glosterdigital.com/en/insights/ai-az-ugyfel-okoszisztemajan-belul
AI within the customer's ecosystem. When does it make sense to opt for sovereign or air-gapped development, and what does that look like in practice?