TL;DR · 30-second read
The Short Version
Artificial intelligence programs are starting to touch the systems that actually run a country: power grids, water utilities, defence networks, government records. Those systems are deliberately kept off the internet so nothing outside can reach them.
Wand AI and Zeroport say they have a way to let automated software workers operate them anyway. The software gets no connection at all. It sends keystrokes down a wire built so that data physically cannot travel back, and receives only a moving picture of the screen, like looking through a window.
A separate computer watches every frame and can cut the session off mid-task.
Wand AI said in a September 9 announcement distributed over PR Newswire that it has added Zeroport to its Sovereign AI offering, incorporating Zeroport’s Fantom hardware boundary and its Moativ enforcement layer into Wand’s agent platform. The stated goal is to let government programs point autonomous AI agents at segmented and air-gapped estates, including grid, water, SCADA, defence, banking and registry systems, without creating a network route into them.
Under the joint reference architecture, Wand’s runtime dispatches an agent session to a dedicated Fantom Core rather than to an endpoint inside the protected network. Only keystroke and mouse input travels inward across a one-way hardware break, and only a display-only pixel stream travels outward. Moativ, an on-device model running on NVIDIA Jetson Thor accelerators inside the same appliance, inspects every input and every frame and can alert, block or physically sever the session. The companies say the architecture is available to sovereign programs and enterprises now, and that adopting Zeroport is elective rather than required.
Executive Summary
The announcement addresses a real and specific bottleneck. National AI programs are moving past document summarisation toward operating systems of record and systems of control, and those are precisely the estates that security teams spent a decade making unreachable. Connecting an agent to them the conventional way means provisioning an interface, a credential and a network path, which recreates the exposure the segmentation was designed to eliminate. Zeroport’s argument is that the route itself should be removed rather than narrowed.
The technical claim has two halves, and they deserve separate treatment. The first is that the access path is physical: a partition built from the chip up that carries no IP packet and terminates no network session, so an agent reaches the protected system the way a cleared human operator does, keystrokes in and pixels out. The second is that the policy governing the agent lives out of band, on hardware the governed session has no address for, which answers a genuine weakness in software guardrails that run on the same computational plane as the model they police.
What the companies have described is an architecture and a reference design, not a deployment record. No sovereign customer, contract value, pilot result or third-party certification accompanies the announcement, and the performance figures are stated as targets and capacities rather than measured production results. The architectural idea is coherent and the problem is well framed; the evidence that it works at national scale is still forthcoming.
The Last Mile of Sovereign AI Is an Access Problem, Not a Model Problem
Sovereign AI has largely been discussed as a question of ownership: whose chips, whose weights, whose data centre, whose law. That framing gets a country to a capable model sitting on domestic compute. It does not get the model anywhere near the substation control interface, the water treatment historian, or the case management system where the work actually is. Air-gapping means a network is physically or logically isolated with no routable connection to the outside, and organisations do it precisely because a path into those estates is a national risk before it is an IT risk.
Wand’s positioning treats that last mile as the binding constraint on the value of AI labour, and the logic holds. An agent restricted to systems already reachable through ordinary enterprise controls is confined to the least consequential half of a ministry’s estate. The alternatives on offer today all involve a trade the release characterises fairly: virtual private networks, zero-trust network access and privileged access management gateways narrow and log the route but preserve it, so it remains enumerable and exploitable; guardrail software asserts policy on the same plane as the model, where a sufficiently capable model can be argued out of it; and leaving the estate offline removes the route by removing the workload.
Zeroport cites roughly two-thirds of cyber-attacks as exploiting remote access tooling and 80 percent of breaches as involving stolen or compromised credentials. Neither figure is sourced in the announcement, and both are the kind of round number that circulates widely in vendor material, so they should be read as framing rather than evidence. The underlying point survives the caveat regardless: remote access is the dominant vector in most credible threat models, and an agentic layer multiplies the number of sessions requesting it.
Physics Governs the Route; Software Still Governs the Judgment
The strongest part of this architecture is also the most conventional. A one-way hardware break that admits only human-interface signals and emits only pixels is a descendant of the unidirectional gateway and data diode designs that have protected operational technology perimeters for years, combined with the display-only principle behind remote desktop and browser isolation. Applying that lineage to agent sessions is a sensible extension rather than an invention, and it inherits the property that matters: there is no packet to smuggle a payload inside, and nothing for a compromised or drifting agent to pivot into. Revoking an agent removes the path outright rather than closing a session on a path that persists.
The second claim needs more care. Moativ enforces policy from silicon the governed session cannot address, which genuinely defeats the prompt-injection and goal-drift failure modes where an agent talks its way past a rule that lives in its own context. But Moativ is itself a model making content-level judgments about what is on screen and what was typed. Physics secures the channel; a classifier decides intent. That classifier can produce false negatives, in which a harmful action reads as sanctioned, and false positives, in which legitimate work is severed. On a control system, a wrongly terminated session mid-action is not a neutral outcome.
The controls around that risk are described more concretely than most vendors manage. Rules are written in plain language and compiled into staged detectors, dry-run against a program’s own session history before they are armed, with autonomy set per group on a five-step dial running from observe through alert, investigate and terminate to self-tune. Dry-running policy against real historical sessions is the right way to calibrate an enforcement model, and the audit trail attaches screen content, keystrokes and rationale to every autonomous action. What is absent is any published figure for detection accuracy or intervention rate.
Pixels In, Pixels Out: What the Agent Gives Up
Routing an agent through a screen rather than an application programming interface is a security gain purchased with capability. Agents that drive graphical interfaces are measurably less reliable than agents calling structured interfaces, because they must locate controls visually, tolerate rendering variation, and recover from states no schema describes. Every task must be expressible as keystrokes and mouse movement against a live display, and nothing structured comes back, only pixels. For supervisory control work performed by a human operator today, that is a natural fit. For bulk data extraction, batch reconciliation or anything requiring high-volume structured output, it is a poor one, and it is worth noting that the pixel-only return path is exactly what makes exfiltration hard.
The economics scale in a way network overlays do not. Capacity grows in Cores and then in appliances, with hundreds of concurrent sessions per appliance and thousands per rack, and humans and agents riding the same rails with no shared tunnel to bottleneck. That converts a licensing question into a hardware procurement question, which is familiar territory for defence and utility buyers and appears in a capital budget rather than an operating one. The dedicated pathways target sub-50-millisecond latency, stated as a design target, which is the threshold that separates a channel usable for live control from one fit only for after-the-fact review. All inspection happens on-premises and no session content leaves the rack, a claim that matters more to sovereign buyers than almost anything else in the architecture.
An Ecosystem Assembled Layer by Layer
This is the third such addition Wand has announced in the same pattern, following a storage efficiency layer and a model robustness layer, and alongside existing inference privacy and confidential computing capabilities. The construction is deliberate: a sovereign platform assembled from independently adoptable components, none a prerequisite for another, each addressing a distinct objection a national buyer might raise. It is a credible route to breadth for a company founded in 2023, and it lets Wand answer a procurement checklist without building every layer itself.
It also leaves the commercial substance of each addition undefined. The announcement describes a joint reference architecture and mutual technical fit, but not whether Zeroport hardware is resold by Wand, jointly supported, revenue-shared, or merely certified as compatible. Buyers evaluating an integration care about which entity holds the support contract when an appliance severs a session on a live grid system. It is also worth recording plainly that Fusion Fund appears as an investor in both companies, which is unremarkable in a specialised market but relevant context for how ecosystem partnerships form.
For Zeroport, founded in 2024 in Herzliya by security and military-intelligence veterans, the partnership offers distribution into national programs that a two-year-old hardware company would otherwise reach slowly. For Wand, whose offices include Abu Dhabi and whose stated customer base spans banks, asset managers and system integrators, it supplies an answer to the question sovereign buyers ask last and hardest: what happens when the agent has to touch the thing that matters.
Background
Sovereign AI describes a country’s effort to run artificial intelligence on domestic compute, under domestic law, with control over the models, data and policies involved. The first wave of national programs concentrated on procuring accelerators and building data centres. The second, now underway, tries to convert that capacity into operational work inside ministries, utilities and defence estates, which raises a problem the first wave never had to solve: the highest-value systems are the ones deliberately made unreachable.
Wand AI, founded in 2023 and headquartered in Palo Alto with offices in New York and Abu Dhabi, sells an operating system for deploying and governing AI agents alongside humans, with identity, authority, audit and governance built in. It is backed by Shasta Ventures, Fusion Fund, Thiel Capital and Palo Alto Growth Capital, and has been assembling its sovereign offering as a series of independently adoptable layers covering inference privacy, confidential computing, model robustness and storage efficiency. Zeroport, founded in 2024 in Herzliya, Israel, holds multiple patents on its Fantom platform and says it is deployed across critical infrastructure, energy, defence, financial services and government environments, with backing from lool ventures, Clarim Ventures, CyberFuture and Fusion Fund. Source: WAND AI adds ZEROPORT as an Agent Containment Layer to Enable Sovereign AI on Air-Gapped and Critical National Systems — the September 9, 2026 announcement describing the joint reference architecture, the Fantom hardware boundary, the Moativ on-device enforcement layer, and the two deployment points the companies support.Sources

