Overview

Who it is for. CIOs, CISOs, CTOs and compliance leads in the public sector, financial services, healthcare, critical infrastructure and any organisation whose data, intellectual property or jurisdiction rules out sending everything to a public API.

The problem. Sovereignty is often reduced to "the data stays in the EU". That is residency. Control also depends on who operates the platform, who holds the keys, which models you can inspect and move, and whether you can leave. The rulebook is still forming: the Commission's Cloud and AI Development Act, proposed on 3 June 2026, would introduce four sovereignty assurance levels for public-sector cloud and AI purchases. It is a proposal, not law. Meanwhile teams buy GPUs before they know the workload, or assume an open-weight model matches a frontier model on every task.

What we do. We classify data and AI workloads into sovereignty tiers and map each tier to an eligible platform: a managed API, an EU sovereign cloud region, private cloud, on-prem or a fully disconnected environment. We design and build the serving layer on open-source building blocks - containers, Kubernetes, vLLM-based serving - with a curated catalogue of open-weight models, including Polish-language models such as Bielik and PLLuM where the content calls for them. Every choice is tested on your own evaluation set.

What you get. An architecture you can defend to a regulator, a platform your teams can run, key management under your control and an exit plan for every provider.

How we work

At Keter AI, every engagement moves through the same four layers, in the order of our mark: strategy, architecture, delivery, governance. Each layer ends in something you can inspect and keep: a decision, a design, a working system, a set of controls. The depth changes with the service; the order does not.

Strategy

01

We start from the business problem: which decisions and workflows AI should improve, what that is worth and what must be true first.

Architecture

02

We design the system around your constraints: data boundaries, model strategy, integrations, evaluation and where it will run.

Delivery

03

We build with real data and real users, in short increments, until the system passes its evaluation set and is ready for production.

Governance

04

We leave controls that last: named owners, monitoring, an audit trail, documentation and a clear view of AI Act duties.

Deliverables

Sovereign AI work ends in infrastructure, not in a position paper. The outputs below cover the decision (which workload needs which level of control), the build (a platform that serves models privately) and the proof (measured quality, cost and a tested way out). Each can be commissioned separately.

01

Sovereignty requirements map

Legal, contractual and security requirements for data, models and operators, translated into concrete design constraints.

01

Sovereignty requirements map

Legal, contractual and security requirements for data, models and operators, translated into concrete design constraints.

02

Workload sovereignty tiers

Each AI workload classified by sensitivity and mapped to an eligible platform, from a managed API to an air-gapped cluster.

02

Workload sovereignty tiers

Each AI workload classified by sensitivity and mapped to an eligible platform, from a managed API to an air-gapped cluster.

03

Model strategy and licences

Open-weight and proprietary models compared on your evaluation set, with licence terms checked before anything ships.

03

Model strategy and licences

Open-weight and proprietary models compared on your evaluation set, with licence terms checked before anything ships.

04

Private serving platform

A serving layer on Kubernetes with an API gateway, per-team keys and quotas, central logging and a curated model catalogue.

04

Private serving platform

A serving layer on Kubernetes with an API gateway, per-team keys and quotas, central logging and a curated model catalogue.

05

Air-gapped deployment design

Offline model and package mirrors, signed artefacts, local identity and an update procedure for fully disconnected sites.

05

Air-gapped deployment design

Offline model and package mirrors, signed artefacts, local identity and an update procedure for fully disconnected sites.

06

Exit and portability plan

A portable baseline of containers, open model formats and infrastructure as code, with a tested exit route per provider.

06

Exit and portability plan

A portable baseline of containers, open model formats and infrastructure as code, with a tested exit route per provider.

Technologies we work with

Docker

Containers

Portable, reproducible packaging, so the same AI workload can move between EU cloud, private cloud and on-prem.

AWS

Cloud platform

Managed AI services and EU regions, including the AWS European Sovereign Cloud for workloads with stricter sovereignty needs.

AWS

Cloud platform

Managed AI services and EU regions, including the AWS European Sovereign Cloud for workloads with stricter sovereignty needs.

Microsoft Azure

Enterprise cloud

Azure AI services for enterprise estates, and Azure Local disconnected operations where systems have to run offline.

Cursor

AI code editor

Agentic coding in the editor. We add the repository rules, review gates and metrics that make it safe at team scale.

Cursor

AI code editor

Agentic coding in the editor. We add the repository rules, review gates and metrics that make it safe at team scale.

GitHub

Code and CI

Repositories, pull-request review and CI pipelines: the place where agent-written changes are tested and approved.

Google Cloud

Data and AI cloud

Data, analytics and Gemini models, used where the client's estate and data classification allow a managed platform.

Google Cloud

Data and AI cloud

Data, analytics and Gemini models, used where the client's estate and data classification allow a managed platform.

Hugging Face

Open-weight model hub

Hub for open-weight models and datasets. We evaluate, adapt and serve selected models inside private environments.

Kubernetes

Orchestration

The base layer for private model serving: GPU scheduling, scaling of inference and portable deployments.

Kubernetes

Orchestration

The base layer for private model serving: GPU scheduling, scaling of inference and portable deployments.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.