# Cisco IQ: Engineering Sovereignty in the AI Era

> Source: <https://blogs.cisco.com/customerexperience/cisco-iq-engineering-sovereignty-in-the-ai-era>
> Published: 2026-08-26 15:00:44+00:00

When we introduced Cisco IQ, we made a commitment to our customers: deliver unified, AI-powered lifecycle intelligence, wherever your infrastructure and data reside.

In April 2026, we made the [Cisco IQ SaaS deployment](https://blogs.cisco.com/customerexperience/from-vision-to-reality-intelligence-in-action-with-cisco-iq) generally available, hosted in three regions. Since then, over 11,000 customers have experienced the power of its agentic intelligence engine firsthand.

Today, we are taking the next step in executing that vision: **the Cisco IQ Air-gapped Virtual Appliance for on-premises deployments is now generally available.**

With this release, organizations operating under the strictest data sovereignty, regulatory, and security requirements can bring lifecycle intelligence, proactive security assessment, and AI-powered infrastructure insights entirely inside their own network boundaries, a capability already validated by early-adopter customers.

**1. ****Intelligence Without Tradeoffs**

For government agencies, financial institutions, healthcare organizations, defense environments, and other highly regulated enterprises, data sovereignty is not a preference. It is a mandate. Yet these are often the environments that stand to benefit most from advanced infrastructure intelligence.

That has historically created a difficult tradeoff: maintain strict network isolation **or** access the latest cloud-powered intelligence. Cisco IQ now provides organizations a choice, without that tradeoff.

Cisco IQ Air-gapped Virtual Appliance brings the intelligence of Cisco IQ into the customer’s own data center, running as a software-defined virtual appliance on standard virtualization infrastructure.

Network telemetry, device configurations, operational data, and assessment results remain within the customer’s environment. Discovery, correlation, assessment, and analysis are performed locally. Absolutely no data travels outside the isolated network.

The result is a new model for infrastructure intelligence: **AI-powered insights without surrendering data sovereignty.**

**2. ****Engineered for Absolute Isolation**

Air-gapped environments demand more than taking a cloud application and moving it behind a firewall. From the design phase, Cisco IQ was engineered to support operation as a self-contained intelligence platform, with the data ingestion, processing, assessment, and management capabilities required to function without external connectivity at runtime.

Customers can connect their Cisco IQ Air-gapped Virtual Appliance to on-premises controllers or establish direct connections to their network devices using standard secure management protocols. We implemented flexible connectivity and authentication methods while maintaining strict administrative control.

To support enterprise growth, the architecture also supports multi-node deployments, allowing customers to scale their analytical capacity horizontally as their infrastructure footprints expand.

Once connectivity is established, Cisco IQ builds a unified view of the infrastructure by connecting inventory, lifecycle, configuration, security, and operational context. This includes capabilities such as Last Date of Support (LDOS) tracking, security hardening assessments, configuration assessments, and infrastructure risk analysis to run entirely within the customer’s air-gapped environment.

**The data stays local. The intelligence stays local. **

**3. ****Bringing AI to Where the Data Lives**

One of the biggest engineering challenges was bringing generative AI into environments where external generative AI services are not an option. Our answer was to bring intelligence to the data.

Cisco IQ Air-gapped Virtual Appliance includes a local Small Language Model (SLM) architecture that enables capabilities such as “Ask AI” and AI-powered analysis of inventory and risk exposure without requiring external LLM APIs.

We also recognized a practical reality: not every customer has GPU infrastructure available on day one. So, we designed the AI architecture to be modular.

Organizations can deploy the core virtual appliance using CPU-only infrastructure and immediately access lifecycle intelligence, predictive asset insights, and infrastructure assessments.

For environments with a modest GPU footprint, the AI Inference Infrastructure can be a modular add-on to the base system to enable localized AI inference. Customers can establish their operational intelligence foundation today and seamlessly add local AI capabilities as their infrastructure, policies, and requirements evolve.

**AI readiness no longer has to be an all-or-nothing decision.**

**4. ****Staying Current, Even When You’re Disconnected**

Standing still even in an air-gapped environment is not an option.

Security intelligence is only valuable when it reflects the latest guidance, advisories, and assessment requirements. That is why we designed Cisco IQ with independent release cycles for application capabilities, assessment rules, and feature entitlements.

Administrators can securely transfer updated assessment artifacts into the appliance without reconnecting the environment to the internet or upgrading the entire platform.

That means new Cisco Security Advisories, hardening guidance, Field Notices, and assessment rules can be introduced independently as they become available.

**Your network remains securely air-gapped, without ever falling behind the evolving threat landscape.**

**5. ****Security and Control by Design**

For mission-critical environments, sovereignty extends beyond where data is stored. It also means controlling who can access the system, how they authenticate, and how activity is governed.

Cisco IQ Air-gapped Virtual Appliance supports enterprise identity and access-control requirements, including SAML-based integrations with identity providers such as Okta, ADFS, and Microsoft Entra ID. For enterprise identities requiring stronger authentication controls, the platform also supports Public Key Infrastructure (PKI) and Certificate-Based Authentication (CBA), along with external audit logging.

Beyond strict access control, it is engineered to meet the rigorous compliance mandates of the public sector and defense industries. Cisco IQ Air-gapped Virtual Appliance aligns with the Federal Information Processing Standard (FIPS) 140-3 for cryptographic security, and adheres to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) requirements.

These capabilities and compliance standards are not afterthoughts. They are part of the architecture required to make AI-powered infrastructure intelligence viable in the world’s most controlled environments.

**Coming Soon: Cisco IQ Tethered Virtual Appliance for On-Premises Deployments**

Air-gapped deployment is the answer when an environment must remain completely disconnected. But many organizations want their data and intelligence processing to remain on-premises, while reducing the operational burden of manually transferring software updates and new assessment content. Tethered mode will retain localized data processing and AI inference while establishing a secure, outbound-only connection to Cisco.

Because the appliance initiates this connection, it never needs to be exposed to the internet for incoming traffic. This connection will enable automated delivery of software updates and new assessment artifacts while transmitting only limited, structured information such as Virtual Appliance identity and health statistics. Customer network data, device configurations, and assessment findings remain on-premises.

It is another step toward the same goal: **giving customers control over where their data lives without giving up the intelligence they need.**

**The Foundation for Sovereign Intelligence**

The future of lifecycle intelligence is not defined by where your infrastructure resides. It is defined by your ability to understand it, proactively protect it, and make insight-driven decisions with absolute confidence.

By engineering Cisco IQ to operate within the strictest data sovereignty boundaries, we are ensuring that every customer, no matter their regulatory environment, is equipped to close the defense velocity gap in the frontier AI model era and transition to a proactive operational reality.

For too long, the most restrictive environments had to choose between security and feature velocity, sovereignty and intelligence, isolation and AI. We believe they should not have to compromise. The AI era does not require organizations to give up control of their data. It requires us to engineer AI differently.

That is engineering sovereignty in the AI era.** **

**Get Started**

- Learn more: Explore the
[Cisco IQ documentation](https://www.cisco.com/c/en/us/support/cx/cisco-iq.html#~tab-cisco-iq-virtual-appliance) - Deploy: Contact your Cisco account team to discuss entitlement and deployment
