See It Work
See It Work
SYSTEM: OPERATIONAL OT/IT CONNECTORS: 150+ AUTONOMOUS OPERATION: 15+ DAYS GOVERNED AUTONOMY: ENFORCED AUDIT TRAIL: IMMUTABLE INDUSTRIES: ASSET-INTENSIVE & MISSION-CRITICAL DEPLOYMENT: 3-6 MONTHS VIA APEX CONTROL LOOPS: 3,400+ SYSTEM: OPERATIONAL OT/IT CONNECTORS: 150+ AUTONOMOUS OPERATION: 15+ DAYS GOVERNED AUTONOMY: ENFORCED AUDIT TRAIL: IMMUTABLE INDUSTRIES: ASSET-INTENSIVE & MISSION-CRITICAL DEPLOYMENT: 3-6 MONTHS VIA APEX CONTROL LOOPS: 3,400+

SOVEREIGN INDUSTRIAL AI · REFERENCE ARCHITECTURE

The reference architecture for sovereign industrial AI.

The full stack that runs inside your plant, air-gapped, from OT data to governed action. Hardware-agnostic, model-agnostic, and entirely under your control.

THE STACK

Five layers, one boundary.

From the silicon to the decision, every layer runs inside your fence line. Nothing depends on an outside service.

05

Decision

MAGS

Cognitive decision teams that detect, decide, coordinate, and execute the next best action, with humans in governance.

04

Model engine

AI Flow

The industrial-grade agentic harness. Runs and governs the models you choose, with guardrails and provenance.

03

Context

Digital Twins

The operational model of the asset: physics, constraints, and topology, so agents reason about the real plant.

02

Data

Data Streams

Real-time OT/IT ingest from SCADA, historians, sensors, and control systems, on site.

01

Infrastructure

Your hardware

Customer-controlled compute: NVIDIA-accelerated, AMD, or your own silicon, from the edge to an industrial data centre.

Runs on the accelerators you already have — NVIDIA-accelerated, AMD, or your own silicon — from the edge to an industrial data centre.

THE MODEL ENGINE

Run and govern any model, on your own hardware.

AI Flow is the industrial-grade harness that puts models to work in operations, without sending anything out.

Model choice

Open-source, NVIDIA NeMo and Nemotron-class, or small right-sized models. Swap models without re-architecting.

No data egress

Prompts, context, and operational data never leave the boundary. Inference happens where the data lives.

Governance & guardrails

Stage gates, policies, and the Human Agency Scale keep autonomy inside defined limits.

Provenance & audit

Every recommendation and action is traceable, with an immutable audit trail for regulated operations.

Right-model routing

Route each decision to the model that fits it, balancing capability, latency, and cost on your own hardware.

Runs offline

Full autonomy continues when the site is disconnected or permanently air-gapped.

DEPLOYMENT SIZES

Sized to the operation, from one asset to the enterprise.

The same architecture scales down to an edge node and up to an air-gapped data centre. Start where the value is.

EDGE

At the asset

Footprint
A single node on the line or at the asset
Hardware
Edge accelerators (e.g. AMD Ryzen™ AI) or CPU
Models
Small, right-sized models
Best for
Low-latency local inference, intermittent connectivity
PLANT

Across the site

Footprint
Site servers running the full loop for a facility
Hardware
On-prem servers, optional GPUs
Models
Right-sized to open, mid-size models
Best for
Site-wide agentic operations, central governance, local execution
INDUSTRIAL DATA CENTRE

Across the operation

Footprint
A GPU cluster for larger models and multi-site operations
Hardware
NVIDIA-accelerated, AMD, or your own silicon
Models
Open and NeMo-class models
Best for
Fully air-gapped, multi-site, larger reasoning workloads

Configurations are confirmed with a solution architect against your connectivity, latency, and governance requirements.

SECURITY POSTURE

Air-gapped by design.

Security isn’t a setting bolted on afterwards. The architecture assumes no outside access from the start.

No external access

Nothing calls out. There is no path from the control network to the public internet, so there is nothing to breach from outside.

Data stays on site

Operational data, IP, and models remain inside the plant boundary. Sovereignty is physical, not policy.

OT-safe integration

Reads and writes to control systems happen through governed, auditable interfaces, not ad-hoc connections.

Governed autonomy

Agents act only within defined boundaries, with human oversight calibrated on the Human Agency Scale.

Full auditability

Every decision carries its provenance. The immutable trail supports authority-to-operate and regulated missions.

HOW IT DEPLOYS

From your infrastructure to governed action.

1

Install on your infrastructure

Deploy onto customer-controlled compute, from an edge node to an air-gapped data centre.

2

Connect OT data

Data Streams ingest live signal from SCADA, historians, sensors, and control systems, on site.

3

Model the operation

Digital Twins capture the physics, constraints, and context of the real asset.

4

Bring your models

AI Flow runs and governs the models you choose, entirely on-premise.

5

Deploy decision teams

MAGS agents detect, decide, and coordinate the next best action.

6

Govern every action

Execution stays within boundaries, with provenance and an immutable audit trail.

Design your sovereign deployment.

Walk through the reference architecture with a solution architect and map it to your plant, your hardware, and your models.