SOVEREIGN AI · GOVERNMENT & PUBLIC SECTOR

Citizen data must never cross a border.

Every prompt sent to a foreign cloud LLM leaves national jurisdiction. VYROX builds sovereign AI on hardware your agency owns.

Government & public sector · sovereign AI

Why government agencies cannot send citizen data to a foreign cloud LLM.

Every prompt sent to ChatGPT, Claude or Gemini crosses a border, sits on infrastructure a foreign company controls, and is subject to a foreign country's laws - not yours. For a ministry, agency, GLC or law-enforcement body, that single fact turns a convenience tool into a data-governance liability. A local LLM removes the exposure entirely: citizen and state data never leaves government-owned infrastructure.

01 / DATA GOVERNANCE

Data never leaves your jurisdiction

Cloud LLM vendors process prompts on servers outside Malaysia, under U.S. or other foreign legal regimes (e.g. the U.S. CLOUD Act compels providers to hand over data on request, regardless of where it is stored). A local LLM runs entirely on hardware you own, inside your data centre or ministry building - data residency and chain of custody stay fully within your control, supporting PDPA 2010 and the Public Sector Data Classification & ICT policies you already answer to.

02 / DATA PRIVACY

Zero data leak by architecture, not policy

Cloud vendor privacy policies can change, accounts can be breached, and prompts can be retained for "safety" or "abuse monitoring" review by human staff you'll never meet. An air-gapped local LLM has no outbound path for citizen records, case files, immigration data or classified material to leak through - there is no vendor server to breach, log, subpoena or retrain on. Privacy becomes a physical fact, not a contractual promise.

03 / AI GOVERNANCE

Auditable, accountable, sovereign

National AI governance frameworks (Malaysia's National AI Roadmap and National Guidelines on AI Governance & Ethics, and equivalents across ASEAN) all converge on the same expectations: transparency, accountability, human oversight and auditability. A closed cloud API is a black box you cannot inspect, version-lock or audit end to end. A local, open-weight LLM gives your agency full model provenance, a fixed version under change control, complete audit logs, and the ability to prove exactly what data went in and what decision came out - to Parliament, an auditor-general, or a court.

Swipe to see all columns

Cross-border transfer riskCloud AI prompts routinely cross into US/EU/other jurisdictions - a compliance problem for any data classified Confidential, Secret or Restricted under public-sector data classification policy. Local AI never leaves the building.
Foreign legal reach (e.g. US CLOUD Act)Foreign statutes can compel a cloud AI vendor to disclose data it holds, even data belonging to a foreign government, without that government's consent. On-premise hardware you own is outside that reach.
Vendor training on your promptsEven with an "enterprise" no-training toggle, you are trusting a foreign vendor's policy and enforcement, not a technical guarantee. A local model only ever sees your data because you chose to show it.
National AI governance alignmentSupports the transparency, accountability and human-oversight principles in Malaysia's National AI Roadmap and National Guidelines on AI Governance & Ethics - full model provenance and change control, not a black-box API.
Continuity & availabilityA foreign vendor outage, API deprecation, price change or account suspension cannot take down a system that citizens depend on. A local system keeps running under your own operational control.
Procurement & cost sovereigntyOne-time, auditable capital expenditure on infrastructure the agency owns outright - not a recurring foreign-currency subscription subject to exchange-rate and pricing risk.
Self service kiosk terminal running a policy grounded citizen assistant
Citizen-service AI · grounded only in gazetted policy, never the open internet

Typical government & public-sector deployments: citizen-service chatbots grounded only in gazetted policy (RAG), internal knowledge assistants for civil servants, document and correspondence drafting, case-file summarisation for law enforcement and the judiciary, procurement and tender analysis, and translation across Bahasa Malaysia, English and Mandarin - every one of them air-gapped or on a private government network, with role-based access and full audit trails.

🏛 Built for agencies, ministries, GLCs, statutory bodies and law-enforcement units handling classified, restricted or citizen personal data. VYROX advises on architecture and controls; formal security clearance, classification handling and accreditation remain the responsibility of the agency and its appointed auditor.

Data Privacy & Sovereign AI for Government - the full briefing.

A self-guided, slide-by-slide walkthrough built for directors, CIOs and procurement committees: the cross-border data problem, the sovereign architecture that solves it, and what a deployment looks like in practice. Share it internally before your briefing with our engineers.

Open the full briefing deck Book a live briefing instead
What you get

What a sovereign deployment includes.

Every VYROX government build is engineered around one non-negotiable: citizen and state data stays on infrastructure the agency owns. Everything below follows from that principle.

On-premise hardware you own

The model runs entirely on hardware the agency owns outright - in your data centre or ministry building, not a vendor's cloud. A one-time, auditable capital expenditure instead of a recurring foreign-currency subscription. Build tiers from a single workstation to a datacenter node: see build tiers.

Air-gap capable by design

Deployments can run fully air-gapped or on a private government network. With no outbound path, there is no vendor server to breach, log, subpoena or retrain on - zero data leak becomes an architectural property, not a policy promise.

PDPA and classification alignment

Data residency and chain of custody stay fully within your control, supporting PDPA 2010 and the Public Sector Data Classification & ICT policies your agency already answers to - with role-based access and full audit trails.

No foreign jurisdiction exposure

Prompts never cross a border and never sit on infrastructure a foreign company controls, so foreign statutes such as the US CLOUD Act cannot compel disclosure. Hardware you own, inside Malaysia, is outside that reach.

Air-gapped government server rack in a locked data centre room, with no network cable running to the outside world
Air-gap capable · no outbound path, by architecture
Start with a free Local-AI Audit

A free 45-minute audit: we measure your current cloud spend, spec the exact build, and put the costed break-even date in writing - no obligation.

Ministries and agencies this fits.

Sovereign AI applies wherever an organisation is accountable to the public and handles data it cannot afford to expose to a foreign cloud vendor. These are the units VYROX builds for most often.

Public service counter screens showing a queue display and an assistant interface
Front-counter answers, grounded only in published policy.

Federal and state ministries

Correspondence drafting, minute-taking, internal policy Q&A and a citizen-service chatbot grounded only in gazetted policy, so it never invents an answer outside what has actually been published.

Law enforcement and judiciary

Case-file summarisation, evidence indexing and judgment drafting support on hardware that never leaves a secured facility, with full audit trails of every query and every document touched.

Statutory bodies and regulators

Tender and procurement document analysis, licence application review, and internal knowledge assistants for staff, without licence applicant data ever touching a third-party server.

Government-linked companies (GLCs)

Board paper drafting, contract review and internal reporting automation on infrastructure the GLC owns, keeping commercially sensitive and citizen-facing data under one roof.

Local councils and agencies

Public-enquiry triage, permit and licence correspondence, and translation across Bahasa Malaysia, English and Mandarin for front-counter and call-centre staff.

Defence and national security units

The strictest case: fully air-gapped, no network path in or out, deployed only with the unit's own accreditation and classification handling process governing every step.

Secure government briefing room screen showing a sovereign AI deployment diagram
Sovereign AI briefing · hardware the agency owns, not a vendor's cloud

What to check before you brief your procurement committee.

A plain-language checklist covering the questions a director, CIO or auditor will actually ask before signing off on an AI deployment for government use.

Data and jurisdiction
Data residency confirmed inside government-owned infrastructure
No prompt or document ever transmitted to a foreign cloud vendor
Not subject to foreign statutes such as the US CLOUD Act
Air-gap option available for classified or restricted material
PDPA and public-sector policy
Aligned with PDPA 2010, Malaysia's Personal Data Protection Act
Matches the agency's Data Classification & ICT security policy
Role-based access control and full request/response audit logs
Supports the National AI Roadmap's transparency and audit principles

Why a foreign cloud LLM is a data-sovereignty risk, not just a privacy nicety.

Every prompt typed into a foreign cloud chatbot leaves the country the instant it is sent. It is processed on hardware a foreign company controls, under that company's home country's laws, not Malaysia's. That single routing decision means citizen identity numbers, case files, immigration records or draft policy can become discoverable under a foreign legal process your agency has no visibility into and no say over. Moving the same model onto hardware the agency owns does not reduce what the AI can do; it only removes the one step where control of the data leaves your hands.

Map diagram showing data held on an in-country server instead of routing to a foreign cloud
Data sovereignty · the border prompts should never cross

Procurement and tender guidance.

Most agencies do not buy AI the way they buy software licences, because there is no licence to buy. What you are procuring is hardware, a deployment, and a support relationship. This section covers how that is usually structured, and how to write a specification that keeps you free to change vendor later.

How agencies typically buy this

1. Scoping before specification

Before anything is written into a tender, the unit that will actually use the system lists its first two or three tasks, the documents involved, and how many people will use it at once. That list drives the hardware size. Writing a specification before this step is the most common reason a public-sector AI purchase ends up over-sized or under-sized. VYROX runs a free 45-minute audit for exactly this stage.

2. Capital expenditure, not subscription

A sovereign deployment is a one-time purchase of infrastructure the agency owns outright, from the Desk AI tier at RM 9,000 for a small unit up to a multi-department datacenter node. That maps to a development or capital budget line rather than an annual operating subscription, and it removes exchange-rate exposure from future years. Budget separately for electricity, maintenance and an eventual hardware refresh.

3. Separate the hardware, the software stack and the services

Splitting the spec into three parts, hardware, open-weight model and serving stack, and integration plus training, lets the evaluation committee compare like with like. It also makes it obvious which parts you own permanently (the hardware and the model weights) and which are a service you can re-tender later (integration, support, training).

4. Pilot first, then scale under the same specification

A single-unit pilot proves the workflow and produces real usage numbers before a larger commitment. Where your procurement rules allow it, structuring the purchase so that the pilot's specification can be repeated for later units avoids re-running the whole evaluation for each department.

Tender specification documents and evaluation sheets laid out on a meeting table
Procurement · specify the outcome, not one vendor's product name

Writing a specification that is not vendor-locked

Vendor lock-in in AI usually arrives quietly, through a proprietary model you cannot export, a closed data format, or a hosted component that quietly moves your data off-site. These are the clauses that keep the agency in control.

Swipe to see all columns

Ask for thisAvoid thisWhy it matters
Open-weight models, weights stored on agency hardwareA proprietary model available only through the vendor's endpointIf the weights sit on your disk, the system keeps working whatever happens to the vendor.
Full administrative access to the server and the stackA sealed appliance only the vendor can log intoYour own ICT team must be able to patch, audit and restore without a service call.
Documented, exportable data and index formatsAn undocumented database only the vendor's tool can readMigration to another vendor should be a data copy, not a re-typing exercise.
Stated hardware make and model, owned by the agencyHardware leased, or hosted at the vendor's premisesOwnership is what puts the deployment outside a foreign vendor's control and outside foreign legal reach.
A written statement of every outbound network connection"Cloud-assisted" features described only in marketing termsOne hidden telemetry or fallback call is enough to break an air-gap claim.
Complete request and response audit logging, retained by youLogs held in the vendor's dashboardAn auditor needs to read the log without asking a supplier's permission.
Handover documentation and named-staff trainingSupport that exists only as a renewable retainerOperational knowledge should stay in the agency when contracts change.
A model-swap clause: newer open models can be installedA model version fixed for the life of the contractOpen models improve continuously. You should benefit without a new procurement cycle.

Evaluation criteria that actually predict success

Weight these heavily
  • Demonstration on the agency's own sample documents, not a generic demo
  • Named accuracy expectations for the specific tasks in the spec, and an honest statement of where a human must review the output
  • Data-flow diagram showing every place data is written or transmitted
  • Concurrent-user capacity at the specified hardware size
  • Local engineering presence and response time for on-site work
  • Training plan for the actual civil servants who will use it
Discount these
  • Benchmark scores that have nothing to do with your tasks
  • Feature lists nobody in the unit asked for
  • Claims of full automation for work that legally requires an officer's decision
  • Any privacy assurance that is a policy statement rather than an architectural fact
  • Model parameter counts quoted without the hardware to run them well

This is general buying guidance based on how these deployments are built, not legal or procurement advice. Your agency's own procurement rules, thresholds, approval routes and registration requirements govern, and should be confirmed with your procurement and legal units.

Matching the deployment mode to how sensitive the data is.

Not every workload needs the strictest posture, and applying the strictest posture everywhere makes the system harder to use than it needs to be. The practical approach is to match the deployment mode to the sensitivity of the material, in your agency's own classification terms, and to keep the strictest material on its own machine.

The table below describes sensitivity in general terms, from published material through to material whose exposure would cause serious harm. Map these rows onto whatever classification scheme your agency actually uses, and have your security officer confirm the mapping before deployment.

Swipe to see all columns

Sensitivity of the materialTypical examplesDeployment modeControls that usually come with it
Published or openGazetted policy, published circulars, public FAQs, forms and guidesPrivate government networkStandard authentication, role-based access, request logging. Can serve a public-facing citizen chatbot through a reverse proxy, with the model itself never exposed.
Internal useDraft correspondence, meeting minutes, internal SOPs, staff knowledge basePrivate government networkDepartment-scoped access, no public endpoint, audit logs retained by the agency, backups kept inside the agency's own estate.
Restricted, personal data of citizensApplication files, licence and permit records, case correspondence, HR filesIsolated segment, no internet routeSeparate network segment with no route to the internet, per-user identity on every request, retention rules on prompt and output logs, documented data-minimisation before documents are indexed.
Confidential or higherInvestigation material, security assessments, pre-decisional policy, anything whose exposure would cause serious harmFully air-gapped, dedicated machineNo network path in or out, physical access control, updates carried in on removable media under change control, logs reviewed in place, the unit's own accreditation process governing every step.

Do not mix tiers on one machine

A single server holding both open policy documents and investigation material inherits the stricter handling rules for everything on it, which usually makes the easy workloads unnecessarily hard to access. Separate machines for separate sensitivity tiers is normally cheaper in practice than one machine locked to the strictest rule.

Air-gapped changes how you update

With no network path, model updates, security patches and new document sets arrive on removable media under your change-control process. Plan a maintenance window and a named custodian for that media. This is an operational cost of the strictest tier, and it should be budgeted as staff time rather than discovered later.

Classify the source documents, not just the server

A retrieval system can only be as well governed as the document set behind it. Decide which documents may be indexed, who may retrieve from which collection, and what happens when a document is superseded or withdrawn, before the first index is built.

An officer still decides

The system drafts, summarises, translates and retrieves. It does not approve an application, sign a decision or determine an entitlement. Keep the human decision point explicit in the workflow and in the record, so accountability for every outcome remains with a named officer.

Layered security rings around a private AI server showing access, monitoring and audit controls
Security layers · isolation, identity, logging, review

Written in general terms on purpose. VYROX advises on architecture and technical controls; the authoritative mapping to your agency's classification scheme, and the accreditation of any system handling classified material, remain with the agency, its security officer and its appointed auditor.

From a single-unit pilot to a statewide rollout.

The failure mode in public-sector AI is not the technology, it is scaling a system nobody proved anyone would use. Each phase below should produce evidence before the next one is funded, so a committee is approving observed results rather than a projection.

Swipe to see all columns

PhaseScopeWhat it must prove before you continue
1. ScopingOne unit, two or three named tasks, a free 45-minute audit and a written build specThat there is a real, repeated task with a measurable current cost in officer hours. If nobody can name one, stop here.
2. PilotOne deployment, one unit, a small group of named users. A single-unit pilot can be live in 4 to 8 weeks.That the output is good enough for real work, that officers use it without being told to, and that the review step catches what it should.
3. HardenSame unit, now with access control, audit logging, backup and restore, and a documented operating procedureThat your ICT and security teams can operate, patch and restore it, and that an auditor can read the logs unaided.
4. WidenTwo to four more units or departments on the proven specificationThat the workflow survives contact with a different department's documents and habits, and that support load per added unit is known, not guessed.
5. StandardiseOne reference build, one document-governance procedure, one training package, one support modelThat a new site can be brought up from documentation rather than from the original project team's memory.
6. ScaleState or agency-wide rollout against the reference build, with a refresh horizon in the budgetThat capacity, electricity, floor space and staffing were planned for the final size, not for the pilot.
Diagram showing a deployment widening from a single unit to many across an organisation
Phased rollout · prove it in one unit before funding the next ten

What to measure at each phase

Worth measuring
  • Officer hours per task before and after, on the same task, counted the same way
  • Share of drafts accepted with only minor edits
  • Weekly active users among the named pilot group
  • Queue or backlog length for the specific process the system supports
  • Number of outputs sent back at the human review step, and why
Common mistakes at this stage
  • Rolling out to everyone at once, so nobody owns adoption anywhere
  • Indexing every document in the agency instead of the ones the task needs
  • Sizing the hardware for the pilot and then discovering the ceiling at phase 4
  • No named owner inside the agency once the deployment team leaves
  • Measuring nothing during the pilot, then having nothing to show the committee

Who is responsible for what, after handover.

Because the agency owns the hardware and the model, the agency also holds the operational and accountability duties. This is the split we put in writing before a deployment starts, so nothing sits in the gap between the two organisations.

Swipe to see all columns

AreaVYROXThe agency
HardwareSpecify, build, install and commission; advise on refresh timingOwns the equipment, provides power, cooling, rack or desk space and physical security
Model and stackSelect and install open-weight models, tune the serving configuration, advise on upgradesApproves model changes through its own change-control process
Data and documentsBuild the retrieval pipeline and indexing workflowDecides which documents may be indexed, keeps them current, and owns classification of every source
Access controlImplement role-based access against the agency's directory or user listOwns the user list, joiners and leavers, and periodic access reviews
Audit logsImplement complete request and response loggingHolds the logs, sets retention, and produces them to auditors, courts or a committee
Network postureDeliver the agreed posture: air-gapped, isolated segment or private networkOwns the surrounding network, firewall rules and any change to that posture
Security accreditationProvide architecture documentation and technical evidenceOwns clearance, classification handling and formal accreditation, with its appointed auditor
Decisions and outcomesBuild the human review step into the workflowA named officer remains accountable for every decision the output contributes to
Training and supportTrain named staff, hand over documentation, provide agreed ongoing supportNames an internal owner who keeps the operating knowledge in the agency
Request a sovereign AI briefing

We will walk your ICT, security and procurement leads through this split before anything is specified.

Sovereign AI for government, answered plainly.

What counts as sovereign AI for a government agency?
Sovereign AI means the model runs entirely on hardware your agency owns, inside your own building or a private government network, with citizen and state data never crossing a border or touching a foreign vendor's server. It is the opposite of typing a prompt into ChatGPT, Claude or Gemini, where the request leaves the country the moment you press enter.
What does air-gapped actually mean?
Air-gapped means the server has no physical or network connection to the public internet at all, so nothing can be sent out even by accident or malware. It is the strongest privacy posture and is what VYROX recommends by default for ministries, law enforcement and any unit handling classified or citizen personal data.
Why is the US CLOUD Act relevant to a Malaysian ministry?
The US CLOUD Act lets US authorities compel a US-headquartered cloud vendor to hand over data it holds, even data belonging to a foreign government, regardless of where that data is physically stored. Any ministry sending prompts to a US-owned cloud LLM is exposed to this reach. Hardware your agency owns inside Malaysia is outside it entirely.
Is this compliant with PDPA 2010 and public-sector data classification policy?
PDPA 2010 governs how personal data is handled, not a specific technology. Running the model on hardware you control removes the single biggest PDPA risk: sending citizen or state data to a third-party cloud vendor, often overseas. Data residency and chain of custody stay fully within your agency's control, supporting both PDPA 2010 and the Public Sector Data Classification and ICT policies you already answer to.
Which agencies is this built for?
Ministries, federal and state agencies, government-linked companies (GLCs), statutory bodies, regulators and law-enforcement units that handle classified, restricted or citizen personal data. VYROX advises on architecture and technical controls; formal security clearance, classification handling and accreditation remain the responsibility of the agency and its appointed auditor.
What can a sovereign AI deployment actually do for civil servants day to day?
Typical uses include citizen-service chatbots grounded only in gazetted policy (RAG, retrieval-augmented generation, meaning the model answers only from documents you feed it), internal knowledge assistants, correspondence and minute drafting, case-file summarisation for law enforcement and the judiciary, procurement and tender document analysis, and translation across Bahasa Malaysia, English and Mandarin.
How does procurement and cost work compared to a cloud AI subscription?
A sovereign deployment is a one-time, auditable capital expenditure on infrastructure the agency owns outright, from the Desk AI tier at RM 9,000 for a small unit up to a multi-department datacenter node. There is no recurring foreign-currency subscription and no exposure to a vendor's pricing or exchange-rate changes.
What happens if a newer, better open model is released next year?
You swap it in. Because the agency owns the hardware and the deployment stack, moving to a newer open-weight model is typically a download and a configuration change under your existing change-control process, not a new procurement cycle or a re-platforming project.
How is this audited and made accountable to Parliament or an auditor-general?
A closed cloud API is a black box: you cannot inspect it, freeze its version, or prove what happened inside it. A local, open-weight model gives full model provenance, a fixed version under change control, complete request and response audit logs, and the ability to demonstrate exactly what data went in and what output came out, to an auditor, a court or a parliamentary committee.
How long does a government deployment take?
A single-unit pilot can be live in 4 to 8 weeks from a free scoping session to a tuned, integrated system. Larger multi-department or whole-of-agency builds take longer, depending on your procurement cycle, security clearance requirements and integration scope.
How do we write a specification that does not lock us to one vendor?
Require open-weight models with the weights stored on hardware the agency owns, full administrative access to the server and stack, documented and exportable data and index formats, a written statement of every outbound network connection, audit logs retained by the agency, and a clause allowing newer open models to be installed. Avoid sealed appliances, hosted or leased hardware, and any privacy assurance that is a policy statement rather than an architectural fact. Your own procurement rules and approval routes still govern, so confirm the wording with your procurement and legal units.
Does every workload need to be fully air-gapped?
No, and applying the strictest posture everywhere usually makes the easy workloads harder to use than they need to be. Published and internal material is normally served on a private government network, restricted personal data on an isolated network segment with no internet route, and confidential or higher material on a dedicated, fully air-gapped machine. Keep sensitivity tiers on separate machines, because one server holding both inherits the stricter handling rules for everything on it.
What extra work does an air-gapped deployment create for our team?
With no network path in or out, model updates, security patches and new document sets have to be carried in on removable media under your change-control process. That means a planned maintenance window, a named custodian for the media, and logs reviewed in place rather than shipped out. It is a real operational cost of the strictest tier and should be budgeted as staff time from the start.
How should we phase a rollout from a pilot to agency-wide?
Six phases, each producing evidence before the next is funded: scoping to confirm a real repeated task, a pilot in one unit with named users, hardening with access control, logging, backup and a written operating procedure, widening to a few more departments on the proven specification, standardising a reference build and training package, then scaling with capacity, electricity, space and staffing planned for the final size rather than the pilot.
After handover, who is responsible for what?
VYROX specifies, builds, installs and tunes the system, implements access control, logging and the agreed network posture, trains named staff and hands over documentation. The agency owns the hardware, the user list, the document set and its classification, the audit logs and their retention, the surrounding network, and formal security accreditation with its appointed auditor. A named officer remains accountable for every decision the output contributes to.
Your move

Stop renting your AI. Own it by next quarter.

Book a free 45-minute Local-AI Audit. We measure your current cloud spend, spec the exact build, and give you the costed break-even date - in writing, no obligation.

  • Free, 45 minutes
  • Costed break-even date
  • No obligation

No deck pitch. Just engineers sizing your build.

Chat with VYROX AI on WhatsApp Free Local-AI audit