Blog

Read our posts about the world of AI and public tenders

IGI 1300 and AI: which architecture for defense tenders?

16 September 2026

IGI 1300 and AI: which architecture for defense tenders?

IGI 1300 does not prohibit artificial intelligence. For defence tenders, the main question is what information is processed, in which information system, and with what flows. An AI therefore does not become “IGI 1300-compliant” solely by choosing French hosting, a qualified cloud, or an on-premise installation.

For an industrial company, a buyer, or a CISO, the challenge is to verify the entire processing chain: language model, embeddings, OCR, storage, logs, access rights, maintenance, and any external services.

IGI 1300, Restricted Distribution: what are we talking about?

IGI 1300 (Interministerial General Instruction No. 1300 of 9 November 2021) governs the protection of national defense secrecy and the information systems that handle classified information. Since the 2021 reform, only two classification levels remain: Secret and Top Secret. The marking “Diffusion Restreinte” protects sensitive information but is not a classification level within the meaning of national defense secrecy.

For Restricted Distribution, the protection rules fall in particular under II 901 and the accreditation process for the system concerned. In both cases, the reasoning remains the same for AI: you have to look at the host system, the data actually processed, and the flows created by the tool.

Why hosting in France is not enough

A server located in France does not guarantee that all data stays within the same perimeter. A platform can be hosted in France while, during processing, calling a model or service running elsewhere.

Before using AI on a sensitive file, five questions help quickly assess the architecture:

  1. Where does the model run? Does the language model run within the organization’s perimeter or behind a third-party API?
  2. Where are the embeddings computed? Are the documents’ vector representations created and stored locally?
  3. Which ancillary services are used? OCR, translation, summarization, or search may also call an external service.
  4. Where do the logs go? Are requests, document excerpts, or technical data stored with a service provider?
  5. How are updates and maintenance handled? Permanent remote access does not have the same implications as an update delivered as a controlled package.

If any of these steps falls outside the authorized perimeter, the location of the main server is no longer enough to guarantee control over the entire processing chain.

On-premises or air-gapped: what does the architecture change?

An on-premises AI runs the platform, models, and processing within the organization’s infrastructure. It keeps AI data and operations within the internal information system, without relying on an external AI API.

An air-gapped architecture goes further: the network is isolated from the outside. Models, software, and updates are introduced according to the organization’s transfer procedures, with no direct connection to the Internet.

None of these architectures is “IGI 1300-compliant” by nature. Local deployment makes it easier to control flows, but it is the complete information system, with the AI integrated, that must meet the applicable requirements and be subject to the necessary accreditation.

What should you check before using AI on a defense tender?

The technical architecture is only part of the issue. Before authorizing the use of AI on sensitive documents, you also need to check:

  1. The nature of the information. Identify whether the file contains commercial, Restricted Distribution, or classified information.
  2. The document scope. The AI must access only the knowledge necessary for the use case.
  3. Access rights. Existing authorizations and restrictions must remain applicable to the AI’s searches and answers.
  4. Traceability. Requests, access, and processing needed for auditing must be able to be logged in accordance with the organization’s rules.
  5. Flows and interfaces. Any communication with a provider, an external service, or another system must be identified and analyzed.

How does Specgen handle defense tenders?

Specgen is a French artificial intelligence platform for complex technical tenders. It analyzes tender documents, extracts and structures requirements, searches for response elements in internal knowledge that the user is authorized to access, assists with drafting, and checks the compliance of the response.

For sensitive environments, Specgen can be deployed on-premises or air-gapped. The platform, language models, embeddings, OCR, and document processing then run within the organization’s perimeter, with no external AI API and no imposed outbound traffic. The architecture is defined with the IT and information security teams to integrate with the existing information system and its accreditation process.

→ Discover Specgen for Defense & Naval tenders

FAQ: IGI 1300, AI and defence tenders

Does IGI 1300 prohibit artificial intelligence?

No. IGI 1300 does not prohibit any particular technology. It requires protecting the relevant information and systems according to their level of sensitivity. The use of AI must therefore be assessed based on its data, architecture, and flows.

Is SecNumCloud hosting sufficient to use AI on Restricted Distribution documents?

No. Hosting qualification does not guarantee that all application processing remains within the same perimeter. You must also check where the models, embeddings, OCR, logs, and any third-party APIs run.

Is an on-premises AI compliant with IGI 1300?

No, not by nature. An on-premise installation makes it possible to better control processing and flows, but compliance and accreditation concern the information system into which the AI is integrated.

Can an AI operate without an Internet connection?

Yes. A platform designed for an air-gapped environment can run models, embeddings, OCR and document processing locally. Updates are then introduced in packages according to the organisation’s procedures.

Key takeaways

For an AI used in defense tenders, the right question is not simply “cloud or on-premises.” You need to determine what information is processed, in which system, by which components, and with which flows.

Hosting in France is not sufficient if part of the processing chain calls an external service. On-premises allows processing to be kept within the organization’s infrastructure; air-gapped adds an additional level of isolation. In all cases, the accreditation remains that of the information system into which the AI is integrated.

Sources

IGI 1300: General Interministerial Instruction No. 1300/SGDSN/PSE/PSD of 9 November 2021 (Légifrance)

II 901: Interministerial Instruction No. 901/SGDSN/ANSSI on the protection of sensitive information systems

ANSSI: security accreditation framework for information systems