In short
Air-gapped AI runs entirely inside a facility, with no network connection to the outside: no cloud calls, no telemetry, nothing leaving the building. Semiconductor programs need it where data cannot cross a boundary — advanced-node design floors, ITAR work, and IP restricted by a foundry or customer NDA. It requires models that run locally and an audit chain kept on the device.
Which programs need air-gapped AI?
Those whose data may not leave the building:
- Design floors working at 3nm and below.
- ITAR and CMMC programs.
- IP restricted by a foundry or customer NDA.
- Programs that require US-person-only support.
- Fab and OSAT sites with a no-egress network policy.
- Trade-secret process development.
What does air-gapped actually require?
Three things. Inference has to run on local hardware, which means open-weight models rather than a cloud API. Identity has to work inside the enclave, through a local directory. And the audit trail has to be kept on the device, with chain of custody, because it cannot be exported to a cloud service.
Does it limit what the AI can do?
It should not. The point of an appliance is that the same platform runs locally: the same AI Employees, the same record, the same alarms and the same approvals. Models are updated on the customer's schedule, by physical media.
How does Tymeline do it?
Patrick runs the whole Tymeline platform on a sealed, tamper-resistant appliance built with Element 31. Nothing leaves the device; disconnect it and every AI Employee keeps working. An order takes four to eight weeks for configuration, hardening and shipment. Installation takes a day, and it is live the same day.