WSO2 makes AI Workspace self-hostable for sovereign AI governance
WSO2 has made its AI Workspace control plane available as a fully self-managed deployment option, allowing regulated enterprises and governments to run their entire AI governance stack inside their own infrastructure. The release, announced in August 2026, means organisations can now operate AI Workspace on-premises, in a sovereign or national cloud, or on a hyperscaler of their choosing, in every case with the option to run fully air-gapped, with no outbound connection to WSO2's own infrastructure.
Prior to this release, WSO2 customers could already self-host the AI gateway layer responsible for routing model traffic. The control plane governing that gateway, called AI Workspace, was available only as WSO2-operated SaaS. That configuration left a residual dependency on vendor-managed infrastructure that was incompatible with stricter data-sovereignty mandates. The new release closes that gap by bringing the control plane into the same self-managed boundary.
What the platform governs
Self-managed AI Workspace allows organisations to control employee access to both external and internally hosted large language models, expose internal resources as Model Context Protocol (MCP) servers under consistent policy controls, and enforce cost caps, quotas and chargeback across all AI resource consumption. Audit trails, routing decisions and guardrail enforcement all remain within the boundary the customer controls.
AI Workspace launched in March 2026 with SaaS and hybrid deployment options. The fully self-managed tier is generally available now as part of WSO2 API Platform, deployable via quick-start installer, virtual machine, Docker or Kubernetes. WSO2 says the platform is built on a 100% open-source foundation, and customers can adopt the AI gateway, API management, identity and integration capabilities individually rather than deploying a full stack.
Derric Gilling, vice president and general manager for API Platform at WSO2, said: "Sovereignty requirements are showing up in most regulated conversations we have, from banks implementing DORA to governments writing open-source-first procurement rules. The launch of self-managed AI Workspace brings our SaaS capabilities to a 100% self-managed offering."
WSO2 says it serves 42 national government customers and more than 3,800 local government agencies, alongside regulated enterprises in financial services, healthcare and telecommunications.
Regulatory tailwinds
The timing is well-aligned with a tightening regulatory environment in Europe. The EU AI Act introduces obligations around transparency and auditability for AI systems, while DORA and NIS2 impose resilience and supply-chain requirements on financial services and critical-infrastructure operators respectively. The proposed EU Cloud and AI Development Act, still at draft stage, would add further expectations around where AI processing can occur and which vendors control the relevant infrastructure. Taken together, these frameworks are pushing regulated buyers to demonstrate control not merely over where data resides but over how AI decisions are made and logged.
The sovereign AI theme is generating a competitive response across the API management and AI gateway market. Vendors including Kong, Apigee (Google) and MuleSoft (Salesforce) have all extended their platforms toward AI traffic management in the past twelve months. WSO2's differentiation rests on the combination of an open-source foundation, a government-focused customer base and the completeness of its self-managed option, factors that may carry weight in public-sector procurement contexts where open-source-first and national-cloud requirements are increasingly explicit. Whether that positioning translates into measurable share gains in the enterprise segment will become clearer as regulated buyers complete AI governance procurement cycles through 2026 and into 2027.