AI & LLMs

Air-gapped AI architecture for industrial safety in Pakistan

An oil and gas operator in Pakistan deployed a fully self-hosted AI stack to predict safety incidents without sending data to the cloud.

DocBento preview

An oil and gas operator in Pakistan has implemented a fully air-gapped artificial intelligence system to predict health, safety, and environment incidents before they occur. The project, detailed in a reference architecture published on October 3, 2026, relies entirely on self-hosted models and local infrastructure to ensure no sensitive operational data leaves the company’s control. This approach demonstrates how heavy industry can leverage advanced AI while adhering to strict data sovereignty requirements.

What happened

The operator aimed to transform its safety department from reactive reporting to proactive warning. Data for this initiative already existed but was siloed across SAP EHS systems, SCADA networks, fire-and-gas historians, camera feeds, and scanned investigation files. The primary constraint was that none of this information could be sent to third-party AI APIs or cloud services. Every component of the serving path had to remain within the operator's own physical infrastructure.

To meet these needs, the engineering team selected models based on open licenses that allowed internal use without external dependencies. The central reasoning engine uses GLM 5.3, a 753 billion parameter mixture-of-experts model running at FP8 precision. For time-series anomaly detection, the system employs Amazon Chronos-2, while Roboflow’s RF-DETR-Large handles vision detection. Optical character recognition is managed by PaddlePaddle’s PaddleOCR-VL-1.6, and multilingual retrieval supports English, Urdu, and Roman Urdu via BAAI’s bge-m3 model.

Hardware sizing was calculated based on model weights rather than marketing specifications. The GLM 5.3 model requires approximately 904 GB of memory with headroom, which fits on a single node equipped with eight 141 GB accelerator cards. This configuration leaves sufficient memory for key-value caches and concurrent users. Edge nodes handle real-time detection and forecasting locally, ensuring operations continue even if the link to the central tier is interrupted.

Key details

  • The system uses GLM 5.3 open weights for reasoning, licensed for purely internal use without managed-service review.
  • Hardware costs for owning the setup over three years are estimated at $670,000, significantly lower than renting equivalent cloud GPUs.
  • All data sources connect via read-only adapters that tag provenance and map to a unified object model.
  • Apache Kafka on KRaft orders events per equipment key to maintain chronological accuracy for incident analysis.
  • Time synchronization is handled by Chrony with a GNSS grandmaster to prevent timestamp drift between sensors and servers.
  • The design avoids RF-DETR checkpoints larger than Large due to licensing restrictions on bigger versions.

Background

Air-gapped systems are isolated from unsecured networks, such as the public internet, to protect sensitive data. In industrial settings, this isolation is critical for operational technology that controls physical processes. Running AI in such environments requires self-hosting all models, as calling external APIs would break the air gap. This means the organization must manage the entire lifecycle of the software, including inference engines, vector databases, and model updates.

Sizing hardware for large language models involves calculating the memory required for model weights and the additional space needed for activations and key-value caches during inference. Precision formats like FP8 reduce memory usage compared to FP16 or FP32, allowing larger models to fit on available hardware. However, this requires specific accelerator support and careful planning to ensure performance does not suffer under load.

Why it matters

For teams running their own software, this architecture highlights the tangible cost benefits of self-hosting over cloud rentals for steady, high-volume workloads. The three-year cost of owning the hardware was less than half the cost of renting equivalent resources from a major cloud provider in the UAE region. Additionally, using closed frontier models by the token would have cost between $1.04 million and $2.95 million for fifty users, making self-hosting the most economical option for long-term deployment.

Data sovereignty is another critical factor. Since no hyperscaler operates a region inside Pakistan, any cloud-based solution would require moving data abroad, violating the operator’s security constraints. By keeping all processing local, the operator maintains full control over its intellectual property and operational data. This approach also eliminates dependency on external API availability, ensuring continuous operation regardless of internet connectivity or third-party service status.

The use of open-source models with permissive licenses allows the operator to fine-tune and modify the weights as needed. This flexibility is essential for adapting generic models to specific industrial contexts, such as recognizing unique equipment configurations or understanding localized safety protocols. It also ensures that the organization owns the AI capabilities it builds, rather than leasing them from a vendor.

What you can do

  • Audit your current data sources to identify siloed information that could benefit from unified AI analysis.
  • Evaluate open-weight models that permit internal use without requiring external API calls or managed services.
  • Calculate hardware requirements based on model parameter counts and precision formats rather than vendor recommendations.
  • Implement read-only adapters for existing systems to ensure data integrity and provenance tracking.
  • Use precise time synchronization protocols like Chrony with GNSS sources to correlate events across distributed sensors.
  • Compare total cost of ownership for self-hosted hardware against cloud rental and token-based pricing for your specific workload.

More news

All news