Back to Insights

The Router: One Component Decides What Stays Private and What Doesn't

**Policy can be ignored. Architecture cannot. Here's the SIA component that turns AI governance from aspiration into infrastructure.** --- Every AI query your employees send is a decision about...

The Router One component decides what stays private. "Architecture prevents what policy can only promise." SAMSUNG INCIDENT — April 2023 3 incidents in 1 month: source code, test sequences, meeting notes pasted to ChatGPT. A policy existed. Architecture did not. Every AI query is an unmanaged routing decision. The Router makes it managed — automatically. HOW THE ROUTER WORKS Employee AI Query THE ROUTER Classifies by sensitivity level SENSITIVE Routes to local infrastructure NON-SENSITIVE Routes to cloud model safely No employee makes routing decisions. Classification is automatic and invisible. CLOUD Act (2018): US agencies can compel any American company to produce data globally The Sovereign Institute thesovereigninstitute.org

Every AI Query Your Employees Send Is an Unmanaged Routing Decision

Policy can be ignored. Architecture cannot. Here's the SIA component that turns AI governance from aspiration into infrastructure.

---

Every AI query your employees send is a decision about what leaves your organization. Most organizations make that decision zero times — it happens automatically, invisibly, by default. The default is the cloud provider's infrastructure.

Consider what that means in practice. When a lawyer asks an AI model to summarize a contract, the summary request and the contract's context travel to a server owned by a company headquartered in the US, processed under US legal jurisdiction, subject to the CLOUD Act — the 2018 law that lets federal agencies compel any American company to produce data stored anywhere in the world. The lawyer didn't make a routing decision. No one did. The query just left.

In April 2023, three Samsung engineers made the same kind of unmanaged routing decision three times in a single month. They pasted semiconductor source code, test sequences, and internal meeting notes into ChatGPT. There was no routing layer to intercept the queries. There was no classification system to identify the content as sensitive. There was a policy that said, approximately, don't share sensitive data with external AI tools. The policy didn't stop the queries. Architecture would have. (Bloomberg, April 2023.)

---

Policy is the wrong tool for a routing problem

The corporate AI acceptable use policy is a document. It lives on an intranet. It describes, in general language, what employees should not do. It has no mechanism to enforce itself.

Consider the parallel: organizations don't manage email data security through policies that ask employees to decide, at the moment of sending, whether each attachment is sensitive enough to require review. They deploy email filtering systems — DLP tools — that inspect outgoing messages automatically, classify content against defined sensitivity rules, and route accordingly. No one thinks this is unusual. It's standard security infrastructure in every regulated organization.

The Router is the equivalent for AI queries. Think of it as a mail room that reads the sensitivity label on every envelope before deciding which courier to use. A query about your acquisition target gets the private, internal courier — your on-premise model. A query about general market trends gets the public courier — a cloud model. The user submits the query. The Router classifies it. The right model answers. The user gets a response. Nobody fills out a form or remembers a rule.

The absence of this architecture is not a neutral position. An organization that has an AI governance policy and no classification layer has created the false impression that AI data flows are managed — which may be worse than knowing they aren't. The policy doesn't protect data; it protects the organization from accountability when data leaves unexpectedly, until an auditor asks to see the logs.

---

How the Router works

The Router sits between every AI interaction and every model that might answer it. Before any model processes a query, the Router classifies the query against sensitivity rules the organization defines. Those rules typically map to data categories that are meaningful for the organization's regulatory context: personal data (GDPR), protected health information (HIPAA), financial data (SOX, MiFID II), strategic documents (competitive sensitivity), and regulated data categories specific to the organization's sector.

Classification happens in milliseconds — faster than the user perceives any latency. The Router then routes based on the classification result: sensitive content to a locally deployed model running on the organization's own infrastructure, non-sensitive content to the appropriate cloud model. The Recorder — a separate SIA component — logs every routing decision: who submitted the query, what classification it received, which model answered, what data was accessed.

The SIA standard defines Hybrid Intelligence — smart routing between local and cloud models by sensitivity level — as one of its seven non-negotiables. Organizations claiming SIA compliance without a functional classification layer haven't met the standard. The Router isn't an optional enhancement; it's the architectural component that makes Hybrid Intelligence real rather than theoretical.

LayerX's 2025 research found that 89% of enterprise AI usage is invisible to IT teams — no logs, no authentication, no routing control. That 89% represents every query that bypassed the organization's approved tools and went directly to external AI services. The Router doesn't address what happens on personal devices through personal accounts — that's a different challenge. It addresses what happens on organizational infrastructure, which is where the scalable exposure lives and where audit logs matter.

---

What the Router makes possible — not just what it prevents

The Router is most often framed as a restriction tool. That framing misses its primary value.

Without a Router, the only safe answer to "should we allow employees to use AI on sensitive work?" is no — because there's no way to ensure sensitive content stays on controlled infrastructure. The result is either a prohibition that employees circumvent (creating the invisible 89% usage problem) or an acceptance of exposure that doesn't have a principled boundary.

With a Router, the answer changes: employees can use AI without restriction, on any content, because the architecture ensures sensitive content automatically routes to models that don't cross the perimeter. The Router doesn't reduce AI use — it extends it to sensitive work that organizations wouldn't otherwise allow. A healthcare provider whose employees can ask AI about patient care questions without that data leaving HIPAA-compliant infrastructure gets more productivity from AI, not less.

The second-order effect matters: once a Router is in place, organizations find they can use cloud AI more confidently for appropriate tasks — because the classification infrastructure that keeps sensitive queries local also provides clear evidence that non-sensitive queries are fine to route externally. The Router creates the audit trail that makes both paths defensible.

---

The regulatory case for architectural classification

The CLOUD Act is not a hypothetical risk. It's active legal authority that applies to every query reaching American AI infrastructure. If your employees use OpenAI, Microsoft Azure AI, Google Vertex, or any major US AI provider, the data those queries contain is subject to federal compulsion. The legal basis exists regardless of what the provider's privacy policy says. The provider's policy is a contract. The CLOUD Act is a federal statute. Statutes supersede contracts.

GDPR makes the data protection case explicit: organizations that process personal data through AI systems are data controllers under GDPR. The accountability requirement means they must be able to demonstrate, for each processing activity, the legal basis, the data categories processed, and the controls in place. "Our employees sometimes use AI tools and we have a policy" is not a GDPR accountability response. "Every AI query is classified before processing; personal data routes to on-premise infrastructure; every decision is logged" is.

EU AI Act Article 26 — which enters enforcement in August 2026 and carries penalties up to €35 million or 7% of global revenue — makes the deploying organization responsible for compliance, not the model provider. An organization that cannot document which queries processed personal data, which model processed them, under what governance framework, and at what time has an Article 26 problem that no vendor privacy commitment can resolve.

Under a regulatory audit, an organization without routing logs cannot answer the auditor's primary question: "show us every AI interaction that touched personal data." Organizations with a Router and a Recorder can answer that question precisely, for any time period, for any query type, within minutes of the request. That's not a compliance convenience — it's the difference between a finding and a fine.

---

The asymmetry of unmanaged defaults

Netskope's January 2026 analysis found 223 sensitive data incidents per company per month, growing at 6% monthly. Each of those incidents represents a query that reached a destination it shouldn't have. In organizations without a Router, the monitoring infrastructure doesn't exist to detect most of those incidents — they're invisible in the same way that 89% of AI usage is invisible.

The asymmetry is stark: the harm from a sensitive query reaching cloud infrastructure often materializes only later, when the data is used in ways the organization didn't anticipate, when a legal proceeding creates discovery obligations the organization didn't know it had, or when an auditor asks for logs that don't exist. The cost of deploying a Router is immediate and quantifiable. The cost of not deploying one is deferred and larger — IBM's 2025 analysis puts the average shadow AI breach cost at $4.88 million.

The Router doesn't eliminate AI data risk. An on-premise model running on poorly secured infrastructure creates its own exposure. The classification rules have to be maintained as data categories and regulatory requirements evolve. The architecture requires configuration that matches the organization's actual sensitivity landscape. These are manageable engineering problems. They're substantially more manageable than the alternative: unmanaged routing decisions made by default, at volume, continuously.

---

Building to the standard

SIA-compliant Router deployment follows six implementation phases: Discovery and Data Audit (mapping data categories and sensitivity rules), Architecture Design (specifying the Router's classification logic against the SIA standard), Governance Layer (integrating with the Recorder for audit logging), Integration and Legacy (connecting to existing AI tools and workflows), Deployment, and Evolution (maintaining classification rules as requirements change).

The technical specification for the Router — the classification categories, the routing logic, the fallback behavior, the latency requirements — is documented in the SIA standard and deployed by TSI-certified practitioners who have demonstrated competency against that specification. Organizations that deploy the Router without certification are building to their own interpretation of the requirement, which may or may not meet what EU AI Act auditors will expect.

The Hybrid Intelligence non-negotiable exists precisely because binary choices — block all cloud AI, or allow all cloud AI — produce worse outcomes than principled, classification-based routing. Level 1 of the SIA standard (Hybrid Sovereign) uses cloud AI deliberately, for non-sensitive tasks, through a Router that enforces the boundary. Level 2 (Data Sovereign) routes all queries to on-premise infrastructure. The Router is present at both levels — the classification logic and routing destinations differ; the architectural requirement to classify every query before routing does not.

---

Policy can be ignored. Architecture cannot.

The organizations that understand this distinction are deploying Routers now, before EU AI Act enforcement creates urgency that compresses timelines and exhausts the certified practitioner pool. The organizations that haven't understood it yet are operating with governance documents that describe what should happen, without the architectural infrastructure that makes it happen.

When a query arrives — and they arrive continuously, from every department, on every device, about every topic — the Router makes the routing decision deliberately, consistently, and in a way that produces an audit record. Policy, by the time the query is submitted, has already failed or succeeded at the point of employee judgment. Architecture doesn't depend on judgment. It doesn't depend on memory, training, or intention. It routes.

The question isn't whether sovereign AI architecture requires a Router. The SIA standard settled that: Hybrid Intelligence is non-negotiable. The question is whether the organization builds to the standard before enforcement arrives, or discovers the requirement in the context of an audit that has already begun.

---

The SIA Router specification and the Hybrid Intelligence non-negotiable are documented at thesovereigninstitute.org. TSI-certified practitioners are available through the practitioner registry for Router deployment engagements.

← Previous Four Levels of AI Sovereignty Certification. Where Does Your Team Stand? Next → Level 1, 2, or 3: Choosing the Right Sovereignty for Your Organization

Full SIA methodology documentation and certification programs at thesovereigninstitute.org