Sovereignty & Data Residency
Sovereign AI in Defence vs Civilian Departments
· 9 minute read
Civilian departments live under DPDP and sector circulars. Defence and security organisations add classification, need-to-know and air-gap habits this article will not pretend to quote.
A civilian ministry and a defence-adjacent organisation sat in the same industry-day hall and heard the same pitch. Sovereign, air-gapped, Indian company. After the hall emptied, their problems diverged. The ministry needed a DPDP role map and a residency schedule for a pension helpdesk. The defence-adjacent organisation needed to know whether a model that had ever seen a restricted drawing could live on a network that also ran mail.
Those are not the same purchase. Collapsing them into one sovereign AI category is how civilian departments over-classify a chatbot and how sensitive organisations under-specify a vendor who only understands DPDP decks.
This comparison stays on the public side of the line. It will not invent Ministry of Defence circulars, service instructions, or classification guides. Where an overlay exists, the only honest sentence is: get counsel and the relevant security wing in the room before you issue the RFP.
Two floors, not two planets
| Question | Typical civilian department | Defence / security organisation (public description only) |
|---|---|---|
| Primary public law for personal data | DPDP Act and Rules, plus IT Act / SPDI until duties commence; sector circulars | Those may still be relevant for personal data; additional official-secrets, classification and organisation-specific rules can dominate. Counsel must say which. |
| Default network posture | On-prem or private cloud with an egress allow-list | Often air-gapped or highly partitioned estates; sometimes a separate internet-connected estate for open work |
| Who can see a prompt | Need-to-know plus DPO / audit | Need-to-know in the security sense; foreign support staff are often a non-starter |
| Model updates | Signed pull to an internal registry | Media-controlled promotion through a guard station; longer evaluation |
| Failure mode to avoid | Undeclared transfer of citizen data | That, plus leakage of restricted operational information into a civilian or foreign model |
Section 7 of DPDP includes legitimate uses related to the sovereignty and integrity of India and the security of the State, among other limbs. That is not a general exemption from being careful. It is a basis question for specific processing. A canteen-pass chatbot does not inherit a security exemption because the same campus has a sensitive wing.
What civilian teams should not copy blindly
Air-gap as costume. Defence organisations air-gap because the residual risk of any outbound path is unacceptable for a class of information. A commercial-tax department that air-gaps a public FAQ will pay the operations tax and still leak through a clerk's phone. Match the posture to the class.
Foreigners-out as a slide. A defence file may require Indian staff and no offshore support. A civilian file may accept documented Indian processor staff and still forbid offshore prompt review. Write the actual rule. Do not paste a services-board paragraph into a university RFP.
Classification of the model itself. Sensitive organisations may treat a fine-tune as a controlled artefact because of what it saw. Civilian departments should still custody adapters, but they should not invent a secret marking for a scheme-FAQ LoRA.
Vendors who sell one stack to both worlds
A product that can run air-gapped and also run as a connected SaaS is not automatically fit for both. Ask whether the code path that phones home is compiled out or merely switched off. Switched off is how a patch turns it back on. Compiled out, or at least absent from the artefact that crosses the media guard, is the only answer a sensitive estate should like.
Ask who the support staff are, by nationality and by employer, for each estate. A civilian pension desk may accept documented Indian processor staff. A defence-adjacent shop floor may not accept the same company’s foreign L2 even for a crash dump. If the vendor cannot staff the stricter estate without opening a tunnel, they should not bid that estate.
Shared training of a foundation model across civilian and sensitive corpora is an obvious failure. Shared evaluation sets are the quiet one. A golden question that still contains a drawing number or a village coordinate does not belong in a vendor’s multi-tenant eval bucket. Split the sets the way you split the networks.
Objections
Tell us the circular. If it is not public, a vendor blog cannot tell you. Your security wing can. If they cannot produce a written rule, you are in a grey zone that needs a written risk acceptance, not a rumour.
DPDP does not apply to us, we are government. That is not a sentence to use without counsel. Government bodies have specific legitimate uses and some exemptions. They also process enormous amounts of ordinary personal data.
One accredited product can serve both worlds. Maybe. Only after the stricter estate's handling rules are written and the product is shown not to open a path between estates.
Civilian lessons worth stealing, and no more
Need-to-know as a habit, not as a costume. Civilian teams can steal the idea that a vendor engineer does not get a standing view of production just because the ticket is open. They should not steal markings they cannot explain.
Estate splitting. A defence-adjacent campus that already keeps a connected canteen network away from a restricted shop floor is teaching a networking lesson civilian SDCs need. Copy the split. Do not copy the handling manual you have not been given.
Patience on updates. Sensitive organisations accept that a model can be a month old if the alternative is a live pull. Civilian teams that insist on daily hosted updates for a scheme FAQ are often chasing freshness they do not use. A weekly inward bundle of circulars is enough for many desks.
The reverse lesson matters too. Defence-adjacent teams should not ignore DPDP maps for ordinary personal data — payroll, medical, canteen, veterans’ welfare — because the rest of the campus is sensitive. Ordinary personal data still has principals. The overlay, if any, is additional, not a licence to be sloppy on the easy estate.
A 60-day split workshop
- Days 1–15: list workflows. Tag each as open-personal, restricted-personal, or potentially classified / official-secret. If the third tag appears, stop and call the security wing.
- Days 16–35: apply the civilian DPDP map to the first two tags. Do not wait.
- Days 36–60: for the third tag, write questions, not architecture. Who marks? Which network? Which nationality of support? Which update path? Let the internal authority answer before a vendor does.
What goes in the file
The workflow tags, the counsel note on whether DPDP and which overlays apply, the estate split, and a sentence that this purchase did not rely on an unpublished circular quoted from memory. If an internal instruction is used, file the instruction or a redacted extract, not a rumour.
Prcept AI works with civilian institutions on-prem and air-gapped. Defence and security buyers should run us through their own handling rules. We will not invent those rules in a proposal.
How to defend this in the file
A P1 CIO/CTO will be asked to explain “Sovereign AI in Defence vs Civilian Departments” to a secretary who has ten minutes. Do not start with the model. Start with the store, the hop, the clause, or the residual risk. “defence AI data rules India” is a search phrase. The file needs a decision.
Civilian departments live under DPDP and sector circulars. Defence and security organisations add classification, need-to-know and air-gap habits this article will not pretend to quote. DPDP does not define sovereign AI. Transfers can be lawful and still be a bad idea. Sector circulars can be stricter than DPDP. Write which instrument you are using.
If you cannot name the Data Fiduciary, the processor, the location of traces, and the erasure method, you are not ready for production personal data — whatever the architecture PDF says.
- One sentence on lawful basis or the procurement rule you are invoking.
- One sentence on where prompts, embeddings and logs live.
- One sentence on who can compel the operator.
- One artefact: packet capture, DPA schedule, or deletion certificate template.
Close this loop before the next CAB
Put “Sovereign AI in Defence vs Civilian Departments” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “defence AI data rules India” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Does DPDP apply to defence organisations?
- The Act has a government-and-security texture, including legitimate uses and exemptions that counsel must read against the specific body and the specific processing. Do not take a blog's word for a blanket exemption or a blanket application. Ask counsel.
- Is there a public MoD circular that defines sovereign AI for the services?
- This article will not invent one. If your organisation has classified or internal instructions, those govern. If you do not have them in the file, you cannot cite them in an RFP.
- Can a civilian department copy a defence air-gap?
- It can copy the habit of fail-closed and media control for a high-risk workflow. It should not copy classified handling rules it cannot see, and it should not air-gap a public FAQ to look serious.
- Are veterans' welfare records defence data?
- They are often personal data about identifiable people held by a government body. They may also pick up additional handling rules. Split the question: DPDP map first, then any overlay counsel identifies.
- Can we use the same vendor in both estates?
- Only if the vendor can operate at the stricter estate's standard without opening a path from that estate into a civilian collector. Many vendors cannot. That is a useful filter.