Vibe Coding Behind the Firewall: Self-Hosted, Air-Gapped and Sovereign AI Development
🎯 Who this is for: CIOs, CISOs, architects and developers in banks, utilities, defence, healthcare and government — anyone who's been told "no code leaves the building."
Series: Part 7 of 13 — Enterprise Vibe Coding | Read time: 6 minutes
A developer at a European utility watches a colleague at a startup build a feature in an afternoon with a cloud AI agent. He asks his security team if he can try the same thing.
The answer comes back in one line: "Our grid control code does not leave our network. Ever."
He isn't being blocked by a grumpy security team. He's being blocked by regulators, contracts, national rules on critical infrastructure and a very reasonable fear of what happens if the wrong code ends up in the wrong place.
For a long time, that one line ended the conversation. In 2026, it's starting one.
🌍 Sovereignty Is Now a Board Topic
This isn't a niche worry. In June 2026 the IBM Institute for Business Value published a survey of 1,000 senior executives (with Oxford Economics). Among the findings, as IBM reports them:
- 68% say meeting data residency and sovereignty requirements across geographies is challenging.
- 71% say switching their primary AI vendor or model would be difficult.
- 91% don't fully understand their AI dependencies across vendors, models and infrastructure.
- 81% say a seven-day vendor outage would cause severe or critical disruption.
Yes, IBM sells sovereignty products, so read it with that in mind. But the pattern rings true in any regulated backyard: AI has moved from experiment to dependency, and dependencies get audited.
🔐 Four Questions Your Security Team Will Ask
Before any AI coding tool gets near sensitive code, expect these:
- Where does our code go? Is it sent to a vendor cloud? Which region? Is it retained?
- Where does the model run? Vendor cloud, our cloud tenancy, our data centre, or a sealed network?
- Who can see the logs? Prompts, outputs and activity logs are sensitive too. Can we pipe them to our own SIEM?
- Can we switch? If the vendor changes terms, raises prices or goes down for a week, what happens?
💡 Key insight: "Cloud vs. on-prem" is the wrong framing. The real questions are about code, model, logs and exit. A cloud tool with regional hosting and zero retention may satisfy one regulator; another will demand a sealed network. Answer the four questions per system, not per company.
🏗️ Your Real Options in 2026
| Deployment model | Code leaves your network? | Model quality | Typical fit |
|---|---|---|---|
| Vendor SaaS (Copilot, Cursor, Claude Code, Bob SaaS) | Yes, to vendor regions | Frontier models | Most internal apps, non-sensitive code |
| Your cloud tenancy (commercial models via your own cloud account) | Into your cloud contract | Frontier or near-frontier | Teams with an established cloud estate |
| Self-hosted hybrid | Partly — some model calls go out | Mix of local and frontier | Sensitive code, some flexibility |
| Fully air-gapped | No | Open models only | Defence, critical infrastructure, classified work |
IBM Bob is a useful concrete example of where vendors are heading. Bob SaaS runs in US East, Frankfurt and Tokyo regions — IBM added the regional deployment options in Europe and Japan in July 2026 — and IBM says prompts are not used as training data, with SaaS effectively zero-retention. At Bob's GA in April 2026, IBM also said an on-premises deployment option is planned for organizations with data residency or regulatory needs.
That's a roadmap commitment, not a shipped product, so treat it the way you'd treat any "planned" line: useful for planning, not for signing. When a self-hosted option does arrive — from IBM or anyone else — the questions below are the ones to put to it. Which models can run fully sealed? Which need an outbound connection? How does the hybrid split actually work?
Bob's August 2026 updates are also relevant here: group policies via MDM/GPO for central control and Splunk SIEM forwarding so activity logs land in your security tooling, not just the vendor's.
⚖️ The Capability Trade-Off
Here's the part that rarely makes the press release.
The further behind the firewall you go, the further you usually are from the strongest models. Fully air-gapped means open models you can host yourself. They've improved enormously, but on hard, multi-step agentic work they generally don't match the cloud frontier.
Watch the routing, too. SaaS Bob automatically routes work across Claude, Mistral, Granite and fine-tuned models. A self-hosted setup typically starts with one core model that you chose and sized, and multi-model routing is something you have to build or wait for. That matters more than it sounds — Part 8 is all about why one model doesn't fit every task.
And you take on the operations: GPUs, Kubernetes clusters, inference servers like vLLM, model upgrades, capacity planning. "Self-hosted" means you are now partly the vendor.
None of this makes air-gapped wrong. For a grid control system or a classified workload, it may be the only acceptable answer. Just make the trade consciously: you're buying control with capability and ops effort.
🧭 A Practical Way to Decide
- Classify your code, not your company. Customer-facing marketing site? SaaS is probably fine. SCADA integration or payment rails? Different conversation.
- Start hybrid where you can. Keep the most sensitive repos local; let less-sensitive work use frontier models.
- Insist on your own logs. Whatever the deployment, audit trails should flow into your SIEM (more in Part 9).
- Plan your exit on day one. Prefer open standards — MCP for tool access, AGENTS.md-style rule files — so your house rules and integrations survive a vendor switch.
- Pilot with real code. A model that's great on demo repos may struggle with your 20-year-old internals. Test before you sign.
Key Takeaways
- Sovereignty is mainstream: IBM's IBV reports 68% of surveyed executives find data residency and sovereignty challenging.
- Ask the four questions — code, model, logs, exit — per system, not per company.
- Vendors are moving: IBM Bob added EU and Japan regions in July 2026, and IBM says an on-premises option is planned — evaluate it against the four questions when it lands.
- Air-gapped trades capability for control; expect open models, your own ops, and often a single core model without automatic routing.
- Hybrid is the realistic middle ground for most regulated organizations.
References
- Introducing IBM Bob: AI development partner that takes enterprises from AI-assisted coding to production-ready software — IBM Newsroom
- IBM Study: Limited Control and Rising Dependencies Leave Enterprises Exposed in the Age of AI — IBM Newsroom
- IBM Bob expands with premium packages, new architecture and greater enterprise control — IBM
🧰 From TheMaximoGuys toolbox: Running Maximo on-prem or in a sovereign cloud? Max_mcp — available on npm and GitHub — runs in Docker inside your own network with multi-environment support, so a self-hosted agent (Bob, Claude, Copilot, Cursor — any MCP-capable agent) can reach Maximo without your data leaving the building.
Series Navigation
| Previous: | Part 6 — Your Legacy Code Is AI's Best Job |
|---|---|
| Next: | Part 8 — One Model Doesn't Fit All |
Published by TheMaximoGuys | September 2026



