AI that never leaves the UK

Flowing Mind is a sovereign AI consultancy for UK defence, central government and regulated organisations. We design, build and govern AI on infrastructure you control, up to fully air-gapped, and we produce the evidence your accreditor will ask for.

Fixed fees, published. No proprietary runtime and no licence on work you paid us to build.

The problem

Where AI projects in regulated organisations get stuck

The pilot works and the board likes it. Then it reaches information governance, the DPO or a procurement panel, and the questions start. Where does the data go? Who trains on it? What happens when the vendor changes its terms? Can you show us the evidence?

Those are fair questions. They are also very hard to answer about a system built around someone else's API, and by that point the money has been spent.

We settle them in the first week, before any architecture is chosen.

Deployment tiers

Three tiers of sovereign AI, and what each one buys you

The word gets used for everything from an air-gapped network to a hosted API with a US parent company and a promise. These are the three tiers we use with clients.

Tier 1

Air-gapped & self-hosted

Your hardware, your network, your control plane.

Open-weight models on machines you own, up to a network with no internet egress at all. Every dependency is mirrored inside the boundary: images, packages, drivers, licensing, model weights. The strongest position, and the heaviest to operate.

Right for: defence, segregated government networks, patient records, privileged material.

Tier 2

Private UK deployment

A UK region, on a contract you hold.

Dedicated model instances in a UK region of a cloud you already hold a data processing agreement with. Data stays in the country and out of shared inference pools, at a fraction of the operational cost of running your own accelerators.

Right for: most regulated production workloads, where the constraint is residency and physical control is not required.

Tier 3

Contracted hosted

A frontier model under enterprise terms.

Sometimes the best model is a hosted one and the data is not sensitive. That is a reasonable choice if you have written zero-retention and no-training terms, a documented residency position, and an accurate classification of what goes in.

Right for: public information, marketing, internal drafting, low-classification workloads.

We recommend Tier 3 where it fits. Most engagements end with a mix of tiers, routed by data classification.

How we work

Four commitments, written into the contract

01

Your data stays in the UK

Every engagement starts by drawing the line your data must not cross. Everything we design sits inside it. Where a hosted model is the right call for a low-classification workload, we document the residency and retention terms and put them in the evidence pack.

02

You own what we build

No proprietary runtime of ours, no per-seat licence on middleware, nothing that stops working if we part company. Open weights and open standards where they do the job, and a repository with tests and documentation your own team can run.

03

Every build ships with its evidence

An evaluation set built from your own material, measured results, a risk register entry and the documents an auditor or procurement panel will ask for. These are produced during the build, while the people who made the decisions can still explain them.

04

We will tell you when not to build

A fair share of proposed AI projects should not go ahead. Where the answer is a database query, a fixed rule or a better process, that is the recommendation, and it is written down with the reasoning so you can take it to your board.

See the full method

Common questions

Before you get in touch

What is a sovereign AI consultancy?

One that designs AI systems around your data boundary first and chooses vendors second. In practice it means open-weight models on infrastructure you control, either your own servers or a UK cloud region on a contract you hold, so prompts, documents and outputs stay in your jurisdiction and are never used to train someone else’s model.

Do I have to self-host to keep data in the UK?

No. There are three workable positions: self-hosted on your own hardware, private deployment in a UK cloud region you control, or a hosted model under enterprise terms with UK residency and no training on your inputs. Each suits a different class of data. We work out which of your workloads belongs in which tier and write down the reasoning for audit.

How much does AI consultancy cost in the UK?

Our readiness assessment starts at £4,500, fixed fee, over two to three weeks. Governance starts at £7,500, private deployment at £18,000 and implementation at £25,000. All four are on the pricing page with what is included.

Are you an AI consultancy or a development agency?

Both. Advice that has never had to survive production tends to be wrong, and a build without governance tends to be blocked at the assurance gate. We assess, we build, we produce the evidence, and we hand the lot over to your team.

Can you deliver AI that runs fully air-gapped?

Yes. We have delivered air-gapped platforms on NVIDIA DGX B300 and HGX B300 for central government and defence. Every dependency is mirrored inside the boundary: container images pinned by digest, operating system and language packages, GPU drivers and firmware, licensing served locally, model weights imported as hashed artefacts, and vulnerability feeds brought in on a set cadence. The first deployment is the easy half. Keeping the platform current in year three is the half we design for first.

What security standards do you build to?

Hosts, container runtimes and orchestration are built from DISA STIG baselines reconciled against CIS Benchmarks Level 2, in code, and scanned before handover. Every deviation is documented with its compensating control. Platforms are mapped onto the NCSC Cyber Assessment Framework and the NCSC Guidelines for Secure AI System Development, and traced to NIST SP 800-53 and the NIST AI Risk Management Framework where a partner or supply chain expects that vocabulary.

Start with a 30-minute call

No deck. Tell us what you are trying to do and we will tell you whether AI is the right tool, roughly what it would take, and roughly what it would cost.