Artificial Intelligence is becoming part of everyday business. Across sectors, organisations are exploring how AI can help people find information faster, generate content, analyse data, summarise documents and support decision-making.
For many organisations, that journey begins with publicly available tools or cloud-based assistants. These can be extremely useful, but they are not always suitable for environments where security, assurance and control are fundamental requirements.
For organisations operating in defence, government and other high-assurance settings, AI adoption requires a different approach. It is not simply about adopting the latest tool, but understanding where data is held, how it is processed, how outputs are generated, and whether the system can be trusted within the operational environment.
At ITSUS, our core focus remains on secure networks, communications, infrastructure and cyber security. However, as AI becomes increasingly relevant across these domains, we have been exploring how it can be applied safely within controlled environments. This has included internal research, experimentation and the development of practical approaches to using AI in a way that aligns with the same security and assurance principles that underpin our wider work.
Why High-Assurance AI Is Different
In high-assurance environments, AI systems must often operate within strict technical, procedural and security constraints. These may include classified or sensitive information, limited connectivity, controlled infrastructure, accreditation requirements and a need for clear auditability.
This creates a different set of challenges from those faced in typical commercial AI adoption. Organisations need to ask questions such as:
- Where is the data being processed?
- Can information leave the controlled environment?
- How can outputs be checked against trusted sources?
- How do we prevent accidental disclosure of sensitive information?
- Can the system operate where internet connectivity is restricted or unavailable?
- How do we govern how staff use AI in day-to-day work?
These questions help shape whether an AI solution can be safely used at all. For this reason, AI in high-assurance environments needs to be designed with security, architecture, governance and operational context in mind from the outset.
Moving Beyond Experimentation
Many organisations are currently experimenting with AI. This is a positive first step, but experimentation alone does not create operational capability.
A proof of concept may show that an AI system can answer questions, summarise documents or assist with a process. However, moving from a promising demonstration to something that can be trusted in real use requires much more.
The system needs to be reliable. The data needs to be prepared properly. Users need to understand what the tool can and cannot do. Outputs need to be traceable. Governance needs to be in place. The solution must also fit the organisation’s technical environment, rather than assuming unrestricted access to cloud services or external platforms.
As part of our internal R&D activity, ITSUS has been exploring these challenges directly. This has included developing AI-assisted approaches to knowledge retrieval, experimenting with secure chatbot architectures and assessing how AI can operate within constrained or offline environments.
This work is helping to shape our understanding of how AI can be applied in a way that is consistent with the types of secure environments in which we typically operate.
The Importance of AI-Ready Data
One of the most common misconceptions about AI is that the model is the main issue. In practice, the quality of the underlying information is often just as important.
If organisational data is inconsistent, duplicated, ambiguous or poorly structured, an AI system will struggle to produce reliable outputs. This is particularly true when using AI to answer questions from internal policies, technical documentation or project information.
Preparing data for AI use requires deliberate effort. It involves cleaning content, normalising terminology, reducing ambiguity and structuring information so that it can be retrieved effectively.
Through internal experimentation, ITSUS has seen how much difference this makes. By restructuring and consolidating internal information into a more consistent form, it becomes far easier for AI systems to return useful and reliable results.
This reinforces an important point: effective AI adoption is not just about selecting a tool, but about ensuring the underlying information is fit for purpose.
Using Retrieval-Augmented Approaches for Trusted Outputs
One approach that is particularly relevant to secure environments is Retrieval-Augmented Generation (RAG).
Rather than relying only on a model’s general knowledge, a RAG-based system retrieves relevant information from approved source documents and uses that material to support the response. This allows the system to provide answers that are grounded in organisational content rather than generated in isolation.
For high-assurance environments, this is important because it supports:
- Better control over the source material used
- More consistent answers to repeated questions
- Clearer links between outputs and trusted documents
- Greater confidence for users and reviewers
- A stronger foundation for auditability
As part of our internal work, ITSUS has been experimenting with this type of approach through the development of secure AI assistants working against controlled data. This has provided useful insight into how such systems can be designed to balance usability with security and traceability.
Designing for Offline and Controlled Environments
In some settings, AI systems may need to operate without persistent internet connectivity. In others, they may need to remain fully within an air-gapped or otherwise controlled environment.
This has significant implications for design. The model, data, indexing approach, user interface and supporting infrastructure all need to be considered as part of a secure system. Updates, monitoring and access control must also be managed within the constraints of the environment.
Through internal investigation and collaboration, ITSUS has been assessing how locally hosted models and controlled architectures can be applied in these scenarios. While there is no single solution that fits all use cases, it is clear that AI can be adapted to operate within constrained environments when designed appropriately.
This aligns closely with our broader experience in designing and delivering secure infrastructure within defence and government contexts.
Governance and Safe Use Are Essential
Technical architecture is only one part of secure AI adoption. People also need clear guidance on how to use AI responsibly.
Without policy and training, organisations risk inconsistent usage, accidental data exposure and poor-quality outputs.
As part of our internal enablement activity, ITSUS has developed an initial AI governance and usage framework aligned to our working environment. This includes defining acceptable use, providing practical guidance and helping colleagues understand how to apply AI safely in day-to-day tasks.
This has highlighted that one of the biggest barriers to adoption is uncertainty. Clear guidance helps give people the confidence to use AI appropriately, without introducing unnecessary risk.
From AI Tooling to Practical Capability
The real value of AI comes when it supports practical, repeatable tasks.
Through internal use, ITSUS has been exploring how AI can assist with knowledge discovery, internal information retrieval and content development. These are areas where AI can reduce time spent searching for information and improve consistency in outputs.
For organisations in high-assurance environments, similar opportunities exist, but they must always be balanced against security, governance and operational requirements. The key is to start with realistic use cases, understand the constraints, and build capability incrementally.
Key Takeaways
AI has significant potential in defence, government and other high-assurance environments, but it must be adopted carefully.
The most effective approaches are those that combine technical innovation with strong governance, secure architecture and disciplined data preparation.
For organisations operating in controlled environments, this means:
- AI should be designed around security and assurance requirements
- Data preparation is critical to achieving reliable outputs
- Retrieval-based approaches can help ground responses in trusted material
- Locally controlled solutions may be needed where connectivity is restricted
- Traceability and auditability are essential for confidence and compliance
- Governance and user guidance play a key role in safe adoption
AI is becoming a practical capability across the industry. The challenge is to adopt it in a way that aligns with the environments in which organisations operate.
For ITSUS, this is an area of active exploration, applying our experience in secure systems, networking, communications and cyber security to understand how AI can be used effectively without compromising the principles that matter most.
Steve is a Senior Consultant and ITSUS’ resident AI expert with over 20 years’ experience across software engineering, automation, secure systems, data science, machine learning and AI.


