AI that never leaves the UK
Sovereign AI for UK defence, central government and regulated organisations. Built and governed on infrastructure you control, up to fully air-gapped, with the evidence your accreditor will ask for.
Fixed fees, published. No proprietary runtime. No licence on work you paid us to build.
- Service 01
AI readiness assessment
Where AI pays off, and where it will not.
Assessment - Service 02
Private, self-hosted & air-gapped AI
Open-weight models on hardware you control, up to air-gapped.
Private AI - Service 03
AI implementation
Retrieval, agents and automation, built in your repository.
Implementation - Service 04
AI governance & compliance
The policy, register and evidence that get AI approved.
Governance
The problem
Where AI projects get stuck
The pilot works. The board likes it. Then it reaches information governance, the DPO or a procurement panel. Where does the data go? Who trains on it? What if the vendor changes its terms? Where is the evidence?
Fair questions, and hard to answer for a system built on someone else's API. By then the money is spent.
We settle them in the first week, before any architecture is chosen.
Deployment tiers
Air-gapped.
Private.
Contracted.
Three tiers of sovereign AI. The term covers everything from an air-gapped network to a hosted API with a US parent and a promise. We recommend the cheapest tier your data classification permits.
Air-gapped.
Open-weight models on machines you own, with no internet egress. Every dependency mirrored inside the boundary. The strongest position, and the heaviest to run.
Private AI 02Private UK.
Dedicated model instances in a UK cloud region, under a data processing agreement you already hold. Data stays in the UK, out of shared inference pools.
What sovereign means 03Contracted hosted.
A frontier model under enterprise terms, for data that is not sensitive. Only with zero retention and residency in writing.
Self-hosted or hosted- 2 Air-gapped platforms delivered
- 0 Internet egress on either platform
- £4.5k Fixed-fee starting point
- 5 Named standards on every build
Sectors
Where the data cannot leave
-
Defence
Inference inside your perimeter, with no egress path. Hosts hardened to STIG and CIS Level 2, plus the Secure by Design evidence your accreditor expects.
MOD Secure by Design, JSP 604 and Def Stan 05-138 Discover -
Central government
Departmental AI that stands up to GovAssure, Secure by Design and ATRS, on infrastructure the department controls.
GovAssure against the NCSC CAF, and Secure by Design Discover -
Financial services
Model risk documentation, explainability and Consumer Duty evidence, with customer data kept in a controlled environment.
SS1/23 model risk expectations and Consumer Duty evidence Discover -
Healthcare & NHS
Patient data cannot go to an offshore API. We build inside your boundary, with the DPIA and information governance evidence approval needs.
DSPT, DTAC and information governance sign-off Discover -
Legal & professional services
Privilege and client confidentiality rule out most hosted AI. Private retrieval over your matter files keeps them inside the firm.
Legal professional privilege and SRA supervision duties Discover -
Public sector
Councils, NDPBs and wider public services. Transparency duties and public scrutiny set a high evidence bar. We build to the standards your assurance team already uses.
ATRS entries, AIME self-assessment and procurement scrutiny Discover
Delivered work
Two air-gapped platforms. No internet egress. Built to DISA STIG and CIS Level 2.
NVIDIA DGX B300 for a central government department, NVIDIA HGX B300 for a defence organisation. Clients are not named; the architecture and assurance pattern are the parts worth publishing.
Central government.
An on-premise AI platform on NVIDIA DGX B300 with no internet egress. Hardened to DISA STIG and CIS Benchmarks Level 2, and mapped onto the NCSC Cyber Assessment Framework as it was built.
- Air-gapped
- NVIDIA DGX B300
- NVIDIA AI Enterprise
- NCSC CAF
Defence.
An NVIDIA HGX B300 platform inside a defence perimeter with no egress path of any kind. Delivered under MOD Secure by Design: a live security case, DISA STIG and CIS Level 2 hardening, every artefact provenance-checked at the transfer boundary.
- Air-gapped
- NVIDIA HGX B300
- NVIDIA AI Enterprise
- Secure by Design
How we work
Four commitments in the contract
Your data stays in the UK
Every engagement starts by drawing the line your data must not cross. Everything we design sits inside it. Where a hosted model suits a low-classification workload, its residency and retention terms go in the evidence pack.
You own what we build
No proprietary runtime, no per-seat middleware licence, nothing that stops working if we part company. Open weights and open standards where they do the job, in a repository with tests and documentation your team can run.
Every build ships with its evidence
An evaluation set from your own material, measured results, a risk register entry and the documents an auditor or procurement panel will ask for. Produced during the build, while the people who made the decisions can still explain them.
We will tell you when not to build
A fair share of proposed AI projects should not go ahead. If the answer is a database query, a fixed rule or a better process, we say so in writing, with reasoning you can take to your board.
Latest insights
For the people who sign AI off
UK AI regulation in 2026: what you have to do
There is still no UK AI Act, but that does not mean no obligations. What binds UK organisations using AI in 2026, and what to put in place.
SovereigntySovereign AI: what it means in a UK context
A working definition of sovereign AI, the four questions that separate real data sovereignty from a residency claim, and where each deployment tier fits.
Buying AIWhat AI consultancy costs in the UK
Real UK market rates for AI consulting in 2026: day rates, fixed-fee audits, project costs and retainers, plus where the money usually gets wasted.
Common questions
Before you get in touch
What is a sovereign AI consultancy?
One that designs around your data boundary first and picks vendors second. In practice: open-weight models on infrastructure you control, either your own servers or a UK cloud region on a contract you hold. Prompts, documents and outputs stay in your jurisdiction and never train someone else’s model.
Do I have to self-host to keep data in the UK?
No. There are three workable positions: self-hosted on your own hardware, private deployment in a UK cloud region you control, or a hosted model under enterprise terms with UK residency and no training on your inputs. Each suits a different class of data. We place each workload in a tier and record the reasoning for audit.
How much does AI consultancy cost in the UK?
Our readiness assessment starts at £4,500, fixed fee, over two to three weeks. Governance starts at £7,500, private deployment at £18,000 and implementation at £25,000. The pricing page lists what each includes.
Are you an AI consultancy or a development agency?
Both. Advice that has never survived production tends to be wrong. A build without governance tends to stall at the assurance gate. We assess, build, produce the evidence and hand it all to your team.
Can you deliver AI that runs fully air-gapped?
Yes. We have delivered air-gapped platforms on NVIDIA DGX B300 and HGX B300 for central government and defence. Every dependency is mirrored inside the boundary: container images pinned by digest, operating system and language packages, GPU drivers and firmware, licensing served locally, model weights imported as hashed artefacts, and vulnerability feeds brought in on a set cadence. The first deployment is the easy half. We design first for keeping it current in year three.
What security standards do you build to?
Hosts, container runtimes and orchestration are built in code from DISA STIG baselines reconciled against CIS Benchmarks Level 2, and scanned before handover. Every deviation is documented with its compensating control. Platforms are mapped to the NCSC Cyber Assessment Framework and the NCSC Guidelines for Secure AI System Development, and traced to NIST SP 800-53 and the NIST AI Risk Management Framework where a partner or supply chain expects that vocabulary.
Next step
Start with a 30-minute call
No deck. Tell us the problem. We will say whether AI is the right tool, what it would take and roughly what it would cost.