Home Engage Articles Contact
← Back to Articles
• Case August 4, 2026

Defense Contractor Runs Air-Gapped AI Without Compromise

Sixteen weeks before delivery on a €15M defense systems contract, a program manager had a requirement her team couldn't meet on time: searching and cross-referencing 8,000 controlled technical...

Leeloo Research & Analysis
7 min read

Defense Contractor Runs Air-Gapped AI Without Compromise

Sixteen weeks before delivery on a €15M defense systems contract, a program manager had a requirement her team couldn't meet on time: searching and cross-referencing 8,000 controlled technical documents from three prior programs to identify reusable specifications. Six engineers working manually would need twelve weeks to complete it. The program manager needed AI. The facility security officer needed assurance that the AI would never touch a network with any external connections. The requirement was both simultaneously.

Searching those 8,000 documents included ITAR-controlled technical data — specifications subject to International Traffic in Arms Regulations, the US law governing defense-related exports. Sending that data to any AI system running on vendor infrastructure, even a vendor with US government cloud authorization, would constitute an unauthorized export under ITAR. The exposure is not theoretical. DDTC — the Directorate of Defense Trade Controls — reported 47 ITAR voluntary disclosures involving digital systems and AI in fiscal year 2024, a 62% increase from 2022, attributed directly to cloud-based AI adoption in defense contractor environments.

Cloud AI wasn't an option. Building AI from scratch wasn't compatible with the 16-week timeline. The commercial path to air-gapped sovereign AI — on-premise hardware, no external network connections, full foundation model capability inside the facility perimeter — resolved both constraints.

---

Why "Government Cloud Authorized" Isn't the Answer

Most cleared facility discussions about AI security start and end with cloud authorization tiers — FedRAMP High, AWS GovCloud, Azure Government. Those designations certify that the vendor's cloud infrastructure meets federal security baselines. They do not address what happens when ITAR-controlled technical data travels across a network to reach those servers.

ITAR's definition of export is broader than most engineers realize. Transmitting ITAR-controlled technical data to a foreign national — even one working in the same facility — is an export. Sending that same data to an AI system running on vendor-operated servers, regardless of where those servers are located, is also an export unless the specific data transmission is covered by a license or exemption. Defense contractors using cloud AI for any work touching controlled technical data are potentially in violation of export control law regardless of the AI vendor's authorization level.

Defense AI vendors marketing FedRAMP High certification as their security credential are offering something real and insufficient at the same time. FedRAMP covers the vendor's infrastructure. It does not cover the contractor's ITAR obligations when controlled technical data leaves the facility's physical perimeter to be processed.

Sovereign AI at SL3 — Sovereignty Level 3, meaning full air-gap with physical isolation — eliminates this exposure entirely. No data leaves the building. No export occurs. The ITAR compliance question becomes: was this data accessed only by cleared personnel with need-to-know, on isolated hardware, with a complete access log? When the answer to all three is yes, the ITAR risk disappears.

---

Air-Gapped AI Isn't a Compromise

Cleared AI deployment isn't a capability limitation — it's the right architectural choice for defense use cases. The AI capabilities that defense contractors need most (technical document search, specification comparison, compliance checking, proposal drafting from institutional knowledge) don't require real-time internet data feeds or continuous model updates. They require access to controlled documents that live on the facility's own systems.

Foundation models capable of these tasks can run entirely on on-premise hardware. No API calls to external servers. No model queries that cross a network boundary. The model itself is deployed inside the facility, running on hardware the contractor owns and operates. What changes compared to cloud AI: the update path is slower (periodic updates from cleared media rather than continuous cloud retraining) and the data universe is exactly the institutional knowledge in the facility, which is precisely the data the engineers need.

Leeloo's SL3 deployment for this program manager included six components: a foundation model package deployed on facility hardware (no API calls required, no external model updates during operation), a cleared network architecture specification compatible with NIPRNet separation requirements, program-level access controls that restrict each engineer's AI queries to the programs they're cleared for, a DCSA-compliant audit log schema recording every query and access event, a facility security officer authorization package, and an ITAR processing attestation document. All six delivered within the 16-week timeline.

Week 16: engineers searching 8,000 controlled technical documents in seconds. The program manager delivered on schedule. The facility security officer had a complete documentation package for DCSA review.

---

The Regulatory Timing for Defense Contractors

Three regulatory deadlines converge for defense contractors in 2025-2026, and addressing them separately adds months to each effort. Addressed together through a structured AI deployment, they become one project.

CMMC Level 3 certification — the Cybersecurity Maturity Model Certification requirement for contractors handling Controlled Unclassified Information — is rolling out enforcement in 2025 and 2026. AI systems operating in cleared facilities must be documented as part of the CMMC program: access controls, audit logging, and system authorization all fall within CMMC's scope. A DCSA-compliant AI governance deployment satisfies the AI-specific CMMC controls simultaneously with the deployment itself.

Prime contractors increasingly require AI governance documentation from subcontractors as part of their own CMMC compliance programs. Subcontractors that can demonstrate cleared, air-gapped AI operations — facility security officer authorization, program-level access controls, ITAR processing attestation — become preferred vendors in competitive bids. Subcontractors that cannot demonstrate AI governance face supply chain disqualification by prime contractors who need to certify their entire supplier base for their own CMMC requirements.

According to DCSA's fiscal year 2024 industrial security report, 34% of cleared facilities reviewed in AI governance spot checks had AI systems operating without documented facility security officer authorization. Of those facilities, 67% were processing data at or above the controlled unclassified information sensitivity level. DCSA described this as the industry's most rapidly growing compliance gap.

---

What Engineers Can Do on Day 113

Once the SL3 system is running, the document search capability that took the program manager's six engineers twelve weeks to complete manually takes hours. Specifications from the three prior programs are indexed, searchable, and returnable to engineers who have program-level clearance for them — with every query logged, every access controlled, and every response traceable to the specific documents it drew from.

Booz Allen Hamilton's classified AI infrastructure program, documented in their 2024 public affairs materials, uses air-gapped deployment as the baseline for any AI touching classified program data — a standard that followed from their experience with how quickly AI access expands once deployed. Leidos' AI governance framework, cited in their 2024 sustainability report, requires facility security officer authorization for all AI systems in cleared facilities before any data connection is established. Both firms reached the same architecture through institutional experience. The 16-week commercial path reaches the same destination without requiring a government program or an acquisition cycle.

Air-gapped AI isn't a capability tradeoff. It's AI that operates exactly as needed for defense work — with full model capability and zero data that ever leaves the building.

Proposals written with access to ten years of prior program knowledge are more competitive than proposals written from memory and recent contracts. Technical documentation that can reference the full specification history of a program is more accurate and requires fewer engineering cycles to verify. The institutional knowledge compiled across a decade of cleared work becomes an AI-accessible asset rather than a collection of PDFs that nobody has time to search.

---

What Needs to Happen This Quarter

Forty-seven ITAR voluntary disclosures involving AI in fiscal year 2024 is not the full picture — it is only the disclosures that contractors chose to make or were caught in. DDTC's October 2024 AI advisory specifically names cloud-based AI as a potential unauthorized export pathway for ITAR-controlled technical data. The per-violation penalty starts at $25,000, carries no statutory ceiling, and is assessed on the empowered official personally, not only on the contractor organization.

Six steps, 16 weeks, cleared AI operational: foundation model deployed on facility hardware, program-level access controls configured, DCSA audit logs running, ITAR processing attestation signed, facility security officer authorization documented, and engineers searching controlled technical data with AI that never touches a network.

Read the ITAR advisory. Ask the facility security officer how many AI tools currently operating in the cleared facility have formal authorization. Ask whether any of them have processed ITAR-controlled technical data without that authorization. The answers to those questions define the urgency and scope of what comes next — and 16 weeks is enough time to close the gap before the next quarterly DCSA review cycle.

← Previous How a Manufacturer Locked Down Trade Secrets Through Sovereign AI Next → Sports Team Kept Competitive Edge Private With Sovereign AI