Sovereign AI — Morocco
AI that never leaves the country
Sovereign AI in Morocco: models hosted on-premise or in a Moroccan data centre, compliant with Law 05-20, the DNSSI and DGSSI requirements for critical operators.
In brief
A sovereign AI is an artificial-intelligence infrastructure — open models, a RAG engine, agents — hosted on-premise or in a data centre located in Morocco, with no dependency on a foreign cloud. Hunter BI designs and deploys it for organisations subject to Law 05-20 and the DNSSI: government bodies, operators of vital importance, defence and security, banks. The capabilities of large models, with data under Moroccan jurisdiction.
For most companies, managed cloud is the right choice. But Morocco has a category of organisations for which the question is not framed in those terms: ministries and government bodies handling sovereign state data, operators of critical infrastructure designated under Law 05-20, players in national defence and security, and certain banking activities. For them, sending data to servers located outside the country is not an option — however good the contract may be.
The answer is not to give up on AI. The latest generation of open models, deployed on infrastructure you control, now delivers capabilities sufficient for the vast majority of internal use cases. Hunter BI designs, deploys and operates these sovereign architectures — from GPU sizing to document RAG — in line with the DGSSI framework.
Updated 14 July 2026
01
Sovereign AI in Morocco: for whom, and why
The word "sovereign" has become a marketing pitch; let us start by defining it seriously. A sovereign AI, in the sense we mean, brings together three conditions: the models run on infrastructure located in Morocco — your own servers or a qualified Moroccan data centre —, no data travels to a third-party service outside the jurisdiction, and the organisation holds the ability to audit and evolve the whole without depending on a single vendor.
Who genuinely needs it? First, the bodies whose regulatory framework requires it: critical infrastructure falling under Law 05-20, whose sensitive information systems answer to the DNSSI issued by the DGSSI. Next, those whose data by its very nature demands it: defence, internal security, sovereign state data, economic intelligence. Finally, those who make it a strategic choice: banks wishing to process customer data in-house without outsourcing, industrial groups protecting their intellectual property. For everyone else, a hybrid architecture — sovereign for the sensitive, cloud for the rest — is often more rational, and we say so plainly at the scoping stage.
02
Law 05-20, DGSSI, DNSSI: the framework that shapes the architecture
Law 05-20 on cybersecurity has given Morocco a demanding framework for protecting the information systems of government bodies and operators of vital importance. Under the authority of the DGSSI, the National Directive on Information Systems Security translates this framework into concrete rules: classification of systems, segregation, control over service providers, and accreditation of sensitive systems.
For an AI project, these requirements have direct architectural consequences. Hosting: sensitive information systems call for controlled infrastructure on national soil, which points towards on-premise or Moroccan data centres meeting the applicable requirements. Segregation: inference, document indexing and logs must respect the separation of classification levels — a "restricted distribution" corpus does not share its index with public documentation. The software supply chain: open models whose weights are verified, audited dependencies, and controlled rather than automatic updates. We design every deployment so that it can be defended before your CISO and, where applicable, in an accreditation file.
03
What we actually deploy: models, RAG, agents
A Hunter BI sovereign infrastructure assembles proven building blocks. The models: latest-generation open weights, selected according to your use cases and the French/Arabic/English trilingualism of your corpora, served by an inference engine optimised on GPUs sized to real load — we calibrate on your volumes, not on theoretical maxima. The RAG: indexing of your document repositories — regulatory texts, procedures, archives — with source citation, so that every answer is verifiable. The agents: tool-equipped automations via MCP on your internal systems, with full logging and human validation on sensitive actions.
The capability gap with cutting-edge proprietary models is real, but it narrows with each generation and, above all, it is rarely decisive for the internal uses being targeted: document search, summarisation, writing assistance, case-file analysis. An open model well equipped on your data beats a cutting-edge model that has no access to it. And the infrastructure stays adaptable: the weights can be swapped out, while the investment in indexing, connectors and governance remains.
04
Sovereign does not mean isolated
Air-gapped deployment — fully disconnected — remains the exception, reserved for classified environments. Most of the sovereign architectures we deploy are connected but controlled: model and software updates pass through a controlled gateway, outbound flows are non-existent or explicitly authorised, and monitoring stays local.
This nuance matters for ongoing operational upkeep. A sovereign AI is not a project you deliver and then forget: models evolve, corpora grow, uses shift. So we structure every deployment with a maintenance plan: monitoring of open models, a qualification procedure for new versions, regression tests on your reference use cases, and skills transfer to your teams — the aim being that your autonomy is real, not merely contractual. That, too, is sovereignty: not replacing a dependency on the American cloud with a dependency on your integrator.
Sectors
Where value shows up first
The Moroccan contexts where we most often step in — and what AI concretely changes there.
Government bodies and ministries
Search across statutes and circulars, writing assistance, correspondence handling: immediate gains on sovereign state corpora that cannot leave the country.
Defence and security
Segregated environments, up to air-gapping for classified systems: document analysis and summarisation on fully controlled infrastructure.
Operators of vital importance
Energy, water, transport, telecoms: technical documentation, HSE procedures and maintenance augmented, in compliance with the DNSSI and DGSSI requirements.
Banks and financial institutions
In-house processing of customer data without outsourcing: document scoring, compliance, case-file summarisation on dedicated infrastructure.
Frequently asked
What is a sovereign AI, in concrete terms?
It is a complete stack — open models, an inference engine, RAG, agents — that runs on infrastructure located in Morocco, without any data leaving for a service outside the jurisdiction. You control its hosting, its updates and its logs. It stands in contrast to managed cloud, where the model runs on the vendor's side, whatever the contractual guarantees.
Which Moroccan organisations are covered by the DNSSI?
The DNSSI, driven by the DGSSI, applies to government bodies, public organisations and operators of critical infrastructure designated under Law 05-20 — energy, water, transport, telecoms and finance, among others. For these organisations, any AI project must fit within the existing classification and information-systems security rules, which strongly points towards controlled architectures on national soil.
Can an open model hosted in Morocco rival ChatGPT?
On the internal uses that motivate a sovereign deployment — document search, summarisation, assisted writing, case-file analysis — yes: a recent open model, properly sized and connected to your repositories through a carefully built RAG, produces results that are fully usable in French and Arabic. The gap with cutting-edge proprietary models persists on the most complex reasoning, and we make it objective at the scoping stage through tests on your real cases.
What hardware investment should you plan for an on-premise AI?
It all depends on the number of concurrent users and the size of the models served. A departmental deployment runs on a handful of compute GPUs; an organisation-wide platform for several thousand public officials calls for a cluster sized accordingly, or hosting in a Moroccan data centre. Hardware is not, in fact, the largest line item: indexing the corpora, the connectors and governance often weigh more heavily in the full budget.
How are model updates handled in an air-gapped environment?
Through a qualification gateway: new model weights are verified (integrity, provenance), evaluated against your reference test sets in a pre-production environment, then introduced into the isolated environment through a controlled procedure. It is slower than a cloud, but perfectly workable — the key is to freeze the procedure at the design stage, not to improvise it at the first update.
Book a call in Casablanca or remotely.
Thirty minutes with a Hunter BI consultant: your context, your data, your compliance constraints and the use cases worth launching first.
- Réponse sous 24 h ouvrées, par un ingénieur
- Diagnostic gratuit, sans engagement
- Membre des réseaux partenaires OpenAI et Anthropic