AI

WSO2 Brings AI Governance Under Customer Control

Bakhtawar Majid

By: Bakhtawar Majid

3 min read

Self-managed AI Workspace gives regulated organizations greater control over the infrastructure used to manage their AI services, including in fully air gapped environments. 

[For more news, click here]

WSO2 is removing a deployment constraint that could leave part of an enterprise's AI infrastructure outside its own environment. The company has made AI Workspace, its control plane for managing AI Gateway runtimes, available as a fully self-managed option within its API Platform. Customers can now run the control plane themselves rather than relying on the company's hosted service, including in environments that are completely disconnected from WSO2. The option is aimed particularly at organizations where infrastructure control is closely tied to security, regulatory or sovereignty requirements. 

Until now, customers could already deploy the AI Gateway within their own infrastructure. The gateway handles AI traffic, while AI Workspace provides the central management layer for configuring providers and proxies, applying policies and managing deployments across connected gateways. An organization could therefore keep the runtime on its own network while having the control plane operated externally. The new self-managed deployment brings that second layer into the same environment, with support for on premises infrastructure, sovereign or national clouds, hyperscalers and fully air gapped deployments. AI Workspace can also manage connections to model providers and MCP proxies, giving platform teams a central point for controlling how applications reach models and external tools. 

“Sovereignty requirements are showing up in most regulated conversations we have, from banks implementing DORA to governments writing open-source-first procurement rules,” said Derric Gilling, vice president and general manager, API Platform, WSO2. "The launch of self-managed AI Workspace brings our SaaS capabilities to a 100% self-managed offering. With a 100% open source foundation, our customers have the freedom to choose: SaaS, hybrid, or self-managed, without compromise.” 

AI Workspace launched in March 2026 with SaaS and hybrid deployment models, making the latest release an extension of an existing product rather than a new governance platform. WSO2 says it has 42 national government customers and more than 3,800 local government agencies, as well as customers in regulated sectors including financial services, healthcare and telecommunications. Those figures are provided by the company, but they help explain the focus on deployment control. In these environments, where infrastructure can be subject to internal security rules or national requirements, the location of a management service can be as relevant to an architecture decision as the location of the underlying workload. European regulation provides some context for that concern. DORA and NIS2 have increased requirements around operational resilience and cybersecurity, while the European Commission's proposed Cloud and AI Development Act addresses sovereignty and strategic dependencies in cloud and AI infrastructure. Neither creates a general requirement to self host an AI control plane, but the direction of policy helps explain why organizations are paying closer attention to where critical technology services are operated and who ultimately controls them. 

The significance of the release is in giving organizations with stricter infrastructure requirements another deployment choice. A company can continue using external AI services where its policies allow, while keeping the management layer for those connections inside its own environment. For customers that already run the gateway themselves, the change removes the need to maintain a separate boundary between the infrastructure handling AI traffic and the system used to manage it. 


Related Articles 

AI Agent Governance Is Falling Behind Enterprise Adoption, Optro Research Finds 

Exclusive: Emma Cloney Says Europe’s Sovereign AI Push Is No Longer Theoretical 

Cequence Security Launches Agent Personas to Automate AI Agent Governance Across the Enterprise 

Share this article

Related Articles