WAND AI adds ZEROPORT as an Agent Containment Layer to Enable Sovereign AI on Air-Gapped and Critical National Systems

WAND AI adds ZEROPORT as an Agent Containment Layer to Enable Sovereign AI on Air-Gapped and Critical National Systems

PR Newswire

Zeroport’s hardware-enforced, non-IP boundary and its on-device Moativ guardrail become an additional containment capability within Wand’s sovereign AI labor infrastructure.

PALO ALTO, Calif., Sept. 9, 2026 /PRNewswire/ — Wand AI today announced the addition of Zeroport to its Sovereign AI offering, giving sovereign programs a way to put AI labor to work on their most sensitive and most isolated systems without creating a network route into them. By incorporating Zeroport’s Fantom boundary and its Moativ enforcement layer into the Wand ecosystem, programs that elect it can let agents operate grid, water, defense, and core government systems the way a cleared human operator does—keystrokes in, pixels out—under guardrails held on hardware the agent cannot talk around.

A sovereign AI program eventually has to touch the systems it was built to run. The last mile is not a model problem — it is an access problem, and access is the vector.

National AI programs are moving from documents to operations. The value of AI labor climbs as agents get closer to the systems of record and systems of control a country actually runs on: grid and water, SCADA, defense estates, core banking and payments, case management, tax and registry systems. Those are also the estates a nation deliberately segments or air-gaps, because a route into them is a national risk before it is an IT risk.

However, connecting an agent to those systems today means building the very thing the segmentation was designed to prevent. The agent needs an interface, a credential, and a network path, and each of those is a route that did not previously exist. Remote access is not an edge case in the threat model; it is the dominant one. Zeroport cites roughly two-thirds of cyber-attacks as exploiting remote access tooling and 80 percent of breaches as involving stolen or compromised credentials. The agentic layer compounds it: software guardrails run on the same computational plane as the model they police, so a prompt injection carried in a tool result, a poisoned retrieved document, or ordinary goal drift can talk an agent around a rule that lives inside the agent’s own world.

The existing market does not resolve this. VPN, ZTNA, and PAM gateways narrow the route and log it, but they keep it—the path is still IP, still reachable, still something an adversary or a compromised agent can enumerate and exploit. Agent-governance frameworks and guardrail SDKs assert policy in software, on the same plane as the agent, where a sufficiently capable model can be argued into ignoring it. And keeping the estate offline removes the route, but removes the workload with it, which is the one outcome an operational AI program cannot accept. The result is a forced choice between sovereign AI that is safe and sovereign AI that is useful.

The addition of Zeroport closes that gap. Wand provides the sovereign agentic stack: country-level governance, a hybrid human and AI operating system, certified AI labor, and autonomous agents attached to the sovereign compute base. Zeroport provides the access boundary. Every session, human or agent, runs on its own sealed Fantom Core, bridging two isolated stations across a one-way hardware break built from the chip up—a partition that carries no IP packet and terminates no network session. What crosses it is keystrokes and mouse input inward and a display-only pixel stream outward. An agent therefore reaches a protected system the way a cleared operator does: no API into the network, no integration to secure, nothing for a compromised or drifting agent to pivot into. Inside the same appliance, Moativ—Zeroport’s on-device AI, running on NVIDIA Jetson Thor GPUs—reads every input and every frame at the content level on a single timeline, and alerts, blocks, or physically severs a session that strays from its sanctioned intent. The policy is held out of band on Moativ’s own hardware, where the governed agent cannot reach it, let alone talk around it. Zeroport is elective: the Wand backend runs against systems reachable through a program’s existing controls, and Zeroport is brought in where the target estate is segmented, air-gapped, or simply too consequential to put an IP route into.

“Every guardrail an AI can reach is a guardrail an AI can eventually argue with,” said Joseph Gertz, Co-Founder and CEO of Zeroport. “We moved the boundary into the physical layer: a break in the wire that cannot carry a packet, and an enforcement AI sitting on silicon the governed session has no address for. A ministry can put an agent to work on a control system and know that the agent’s authority ends at physics rather than at a line in a config file. Take away the route, take away the attack.”

“Sovereign AI is only as valuable as the systems it is allowed to touch, and the most valuable systems are the ones nations have spent a decade making unreachable. We are pleased to welcome Zeroport into Wand’s sovereign technology ecosystem, adding a containment capability that lets ministries, institutions, and agencies extend AI labor to segmented and air-gapped estates on a unified national stack without opening a route into them,” said Cristian Felix, Chief AI Architect of Wand AI.

How It Works

The joint reference architecture supports two deployment points. Governed agent access. Wand’s Adaptive Router reduces every model call to one dispatch seam, and Wand’s runtime dispatches an agent’s session to a Fantom Core rather than to an endpoint inside the protected network. Identity, authorization, objectives, and audit remain in Wand’s governance layer; the path itself becomes a physical object. No credential, API, or IP route into the protected estate is created, and revoking a user or an agent removes the path outright rather than closing a session on a path that still exists. Out-of-band enforcement. Wand defines what an agent is authorized to do; Moativ enforces it from hardware the agent cannot address. Rules are written in plain language, compiled into staged detectors—typed, executed, output visible—and dry-run against the program’s own session history before they are armed. Autonomy is set per group of users or agents on a five-step dial: observe, alert, investigate, terminate, self-tune. Every autonomous action lands in the audit log with the evidence attached: what was on screen, what was typed, what was done, and why.

Because the boundary is a physical object inside the program’s own facility, it scales the way hardware does rather than the way tunnels do. Capacity grows in Cores and then in appliances—hundreds of concurrent sessions per appliance, thousands per rack—with people and agents riding the same rails and no shared tunnel to bottleneck or harden. Dedicated hardware pathways target sub-50-millisecond latency, which is what makes the channel usable for live control work rather than only for after-the-fact review. All inspection happens on-premises: no session content leaves the rack, and Zeroport (or any exteranl party) sees none of it.

The capability is complementary to the inference privacy, confidential computing, model robustness, and storage efficiency layers already in Wand’s sovereign ecosystem. Those protect the data path around the model, the behavior of the model itself, and the economics of the infrastructure underneath it; Zeroport governs what the model can reach and what it is permitted to do once it gets there. The capabilities are independent—each can be adopted on its own, and none is a prerequisite for another—but together they set how much of a nation’s estate AI labor can safely be pointed at.

The Wand AI and Zeroport joint reference architecture is available to sovereign programs and enterprises now.

About Wand AI

Wand AI is building the sovereign infrastructure for AI labor. Wand’s operating system enables governments and enterprises to deploy, manage, govern and continuously evolve AI agents alongside humans as trusted members of the workforce, with identity, objectives, authority, security, governance and auditability built into the platform.

For nations, Wand provides a unified foundation through which ministries, public institutions, and critical national organizations can deploy AI labor while maintaining sovereign control over models, compute, data, policies and operations. Wand powers production-scale deployments with some of the world’s most consequential institutions, including leading banks, asset management firms, hedge funds, consulting firms, and system integrators. Wand exists to power the biggest transition in human history: infinite labor—so that everything humanity can imagine, we can finally build.

Founded in 2023 and headquartered in Palo Alto, California, with offices in Palo Alto, New York and Abu Dhabi, Wand is backed by a tier-one research team and world-class investors, including Shasta Ventures, Fusion Fund, Thiel Capital, and Palo Alto Growth Capital. Learn more at wand.ai.

About Zeroport

Zeroport delivers hardware-enforced, non-IP remote access for people and AI agents alike. Its patented Fantom platform places a physical break in the wire at the boundary of a protected environment: inbound flows are limited to human-interface signals and outbound flows to a display-only pixel stream, so no routable IP packet crosses the partition, no malware can infiltrate, and no data can exfiltrate. Each session runs on its own sealed Fantom Core with no shared kernel, no shared tunnel, and no lateral route between sessions. Fantom Edge serves distributed and OT perimeters; Fantom Enterprise carries hundreds of concurrent sessions per appliance and thousands per rack, consolidating VPN, ZTNA, PAM, VDI, and browser isolation into a single hardware-enforced platform.

Moativ, Zeroport’s on-device AI, runs on NVIDIA Jetson Thor GPUs inside the appliance and inspects every action going in and every pixel coming out, for human sessions and agent sessions alike, enforcing plain-language policy held out of band from the sessions it governs. Everything is processed on the customer’s own network and nothing leaves it.

Founded in 2024 and headquartered in Herzliya, Israel, with operations across North America, Europe, and Asia-Pacific, Zeroport was founded by security and military-intelligence veterans, holds multiple patents, and is deployed across critical infrastructure, energy, defense, financial services, and government environments. The company is backed by lool ventures, Clarim Ventures, CyberFuture, and Fusion Fund. Learn more at zeroport.com.

Cision View original content:https://www.prnewswire.com/news-releases/wand-ai-adds-zeroport-as-an-agent-containment-layer-to-enable-sovereign-ai-on-air-gapped-and-critical-national-systems-302873155.html

SOURCE Wand AI