Enterprise AI's new controls: region choice, air gaps, and a self-hosted gateway
Mistral makes inference regions selectable, GitHub brings the Copilot command line into air-gapped networks, and AWS documents a Claude apps gateway running inside an organization's own cloud environment.
Artificial Intelligence··Night
Mistral turns inference region into a product choice
Mistral AI has made Regional Endpoints generally available, giving customers a choice between running inference in Europe or the US. The company also placed Mistral Priority Tier in public preview, offering custom rate limits and an uptime commitment for mission-critical workloads. Regional control is intended to extend beyond Mistral's own models. Starting with Z.ai's GLM-5.2, the platform says it will run third-party open-weight models under the same infrastructure, regional controls, and service commitments. Mistral is also assembling a coalition that pools multi-year enterprise commitments. Units called European Compute Units are meant to turn those commitments into access to infrastructure the company will build. Within this package, inference location moves from a background implementation detail to a feature a customer can select. The generally available region choice and the preview priority tier sit at different stages of maturity, yet both make the location and service conditions of enterprise workloads more visible.[1]
Copilot enters the air gap, and a Claude gateway enters the private cloud
The GitHub Enterprise Server 3.22 release candidate introduces a technical preview for running the Copilot command-line tool in disconnected or air-gapped environments without access to GitHub Cloud. After an administrator configures a model provider, users across the enterprise can access the tool with their own credentials. A separate reference deployment on the AWS Machine Learning Blog describes a self-hosted gateway linking Claude Code and Claude Desktop to Amazon Bedrock or Claude Platform on AWS. In that example, the container runs on AWS Fargate inside the organization's virtual private cloud, while the same image can also run on Amazon EKS or Amazon EC2. Sign-in state, per-user spend counters, and audit logs are held in Amazon RDS for PostgreSQL. The gateway authenticates to Amazon Bedrock with its own identity and access management role, keeping upstream credentials off developer machines. The two approaches offer different ways to keep development tools within an organization's network and identity boundaries.[2], [3]
Three boundaries at three stages of availability
The three announcements do not repeat the same control; they address different boundaries in the placement chain for enterprise AI. Mistral offers a choice between Europe and the US at the hosted inference layer. GitHub moves the Copilot command line into an Enterprise Server environment without cloud connectivity. The AWS example places an organization-managed gateway between the application and the model service, concentrating sign-in state, spend counters, audit logs, and upstream identity at that layer. Their availability also differs: Mistral's regional endpoints are generally available, GitHub's air-gapped capability is a technical preview, and the AWS post describes a production reference deployment. Those distinctions prevent the three items from becoming one ready-made solution. Their shared direction is the addition of workload location, network connectivity, and identity flow to the model choice. For enterprise teams, an AI service is increasingly described by where a request is processed and which organizational control it passes through, alongside the model that produces the response.[1], [2], [3]