PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 30, 20260 citationsOpen Access

Sovereign, Air‑Gapped, and Attested AI Inference: A Compliance‑Enforced Architecture for Regulated Workloads

View Full Paper
CKChristian Kearney

Key Points

  • This work aims to propose an architecture for secure, compliant AI inference in regulated environments.
  • Developed an architecture that enforces loopback-only model binding and kernel-level egress denial.
  • Implemented a three-phase wipe protocol supervised by an autonomous watchdog.
  • Provided validation artifacts and operational guidance for deployment.
  • Achieved verified integrity for model weights and dependencies under a controlled execution pattern.
  • Demonstrated offline operation preventing data leakage and enforcing egress denial.
  • Established an audit model enabling third-party verification of compliance without exposing sensitive content.

Abstract

This work presents a deployable architecture for sovereign, air‑gapped, stateless, and attested AI inference designed for regulated, classified, and compliance‑bounded environments. The system enforces loopback‑only model binding, kernel‑level egress denial, dependency and model‑weight integrity verification, volatile‑memory‑only execution, and a three‑phase wipe protocol supervised by an autonomous watchdog capable of emergency buffer destruction. The manuscript provides the architectural overview, threat model, and evidence‑first control framework. The accompanying 73‑page dossier contains assessor‑grade validation artifacts, manifests, test harnesses, and operational guidance. Key Contributions Air‑gapped execution pattern — loopback‑only binding, kernel‑level egress denial, offline operation for regulated workloads. Evidence‑first audit model — metadata‑only, Merkle‑style evidence chain enabling third‑party verification without exposing content. Stateless, attested runtime — volatile‑memory sessions, explicit wipe semantics, autonomous watchdog. Operational validation — reproducible tests for binding, egress denial, dependency integrity, model‑weight verification, and retrieval isolation. Why This Matters Regulated organizations must prove where data went, what controls applied, and what evidence exists after execution. Cloud AI guardrails and confidential compute do not eliminate retention, do not enforce egress denial, and do not provide independently verifiable provenance. This architecture treats compliance as a runtime property, not a policy statement — a fundamental shift for healthcare, finance, defense, and legal workloads. Figures Included in the Manuscript Figure 1 — Four‑tier system architecture with air‑gap boundary Figure 2 — Six containment layers enforcing sovereign, stateless inference Figure 3 — Ordered request pipeline from ingress to post‑processing Figure 4 — Three‑phase stateless lifecycle with watchdog triggers Figure 5 — Routing matrix and offline transfer paths Recommended Use This page serves as the canonical web summary. For evaluation, audit posture, or deployment planning, begin with the manuscript PDF and use the dossier for evidence‑grade validation.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Christian Kearney (2026) studied this question.

synapsesocial.com/papers/6a1a82640307b78509434161https://doi.org/10.5281/zenodo.20422087
Ask AI
Helpful
Bookmark
Share
View Full Paper