Institutional AI Sovereignty Through Gateway Architecture: Implementation Report from Fontys ICT

📅 2025-12-04
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Commercial AI subscription tools compromise institutional data sovereignty, entail GDPR compliance risks, and exacerbate service inequities in higher education. This study proposes an AI Sovereignty Gateway Platform tailored for applied universities, featuring a three-tier architecture: (1) an identity-authenticated frontend, (2) a policy-driven gateway core enabling EU-default routing and granular budget control, and (3) a Model Card Provider layer encapsulating both commercial and open-source models to ensure unified model governance and full-chain auditability. The work introduces the first institution-level AI gateway paradigm, elevating AI from a technical utility to a strategic function, and establishes an AI Director role integrating technical, governance, and pedagogical responsibilities. A six-month empirical pilot with 300 users achieved zero privacy incidents, 100% EU-hosted infrastructure, complete model transparency and selection, and high user adoption—validating a sovereign, compliant, controllable, and equitable AI service framework for higher education.

Technology Category

Application Category

📝 Abstract
To counter fragmented, high-risk adoption of commercial AI tools, we built and ran an institutional AI platform in a six-month, 300-user pilot, showing that a university of applied sciences can offer advanced AI with fair access, transparent risks, controlled costs, and alignment with European law. Commercial AI subscriptions create unequal access and compliance risks through opaque processing and non-EU hosting, yet banning them is neither realistic nor useful. Institutions need a way to provide powerful AI in a sovereign, accountable form. Our solution is a governed gateway platform with three layers: a ChatGPT-style frontend linked to institutional identity that makes model choice explicit; a gateway core enforcing policy, controlling access and budgets, and routing traffic to EU infrastructure by default; and a provider layer wrapping commercial and open-source models in institutional model cards that consolidate vendor documentation into one governance interface. The pilot ran reliably with no privacy incidents and strong adoption, enabling EU-default routing, managed spending, and transparent model choices. Only the gateway pattern combines model diversity and rapid innovation with institutional control. The central insight: AI is not a support function but strategy, demanding dedicated leadership. Sustainable operation requires governance beyond traditional boundaries. We recommend establishing a formal AI Officer role combining technical literacy, governance authority, and educational responsibility. Without it, AI decisions stay ad-hoc and institutional exposure grows. With it, higher-education institutions can realistically operate their own multi-provider AI platform, provided they govern AI as seriously as they teach it.
Problem

Research questions and friction points this paper is trying to address.

Commercial AI tools create unequal access and compliance risks for institutions
Institutions need sovereign AI platforms with transparent governance and EU compliance
Current AI adoption lacks institutional control over costs, access and legal alignment
Innovation

Methods, ideas, or system contributions that make the work stand out.

Gateway platform with three layers for controlled AI access
EU-default routing and policy enforcement for compliance
Institutional model cards to unify vendor governance interface
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
R
Ruud Huijts
Fontys ICT
K
Koen Suilen
Fontys ICT