Mumbai, Aug 25: WSO2 today has given enterprises a way to entirely self-host their AI governance infrastructure by making its AI control plane, AI Workspace, available as part of its fully self-managed API Platform offering. This latest release closes the final gap that was restricting regulated organizations from running AI governance entirely on their own terms. With this release, any organization can operate a complete, sovereign governance layer over its AI estate: every model, every agent, every MCP server, and every cost, enforced and audited inside a boundary they control, with no vendor-hosted component required.
With self-managed AI Workspace, that governance layer lets organizations govern employee access to both external and sovereign LLMs and MCP servers, expose internal resources as MCP servers under the same policy controls, and cap cost, enforce quota, and implement chargeback across internal and external AI resource access. All of these happen while applying guardrails consistently across every AI traffic flow deployed through the AI gateways that make it possible.
AI Workspace remains the central place to enforce these policies, and gives AI developers a dedicated workspace to find and get started with organizationally-approved models and services, now without any of it having to leave the customer’s own infrastructure.
In most enterprises, AI adoption has run ahead of AI governance. Teams connect LLMs, agents, and MCP servers faster than platform teams can secure them. Self managed AI Workspace closes that gap without asking regulated organizations to trade governance for sovereignty and they no longer have to choose between the two.
Regulated buyers in Europe are increasingly asked to prove control over how AI decisions get made, not only where data sits. That expectation runs through the EU AI Act, the proposed EU Cloud and AI Development Act, DORA, and NIS2. A vendor-hosted control plane puts policy enforcement, routing decisions, and audit trails outside the customer’s boundary of control.
“Sovereignty requirements are showing up in most regulated conversations we have, from banks implementing DORA to governments writing open-source-first procurement rules,” said Derric Gilling, vice president and general manager, API Platform, WSO2. “The launch of self-managed AI Workspace brings our SaaS capabilities to a 100% self-managed offering. With a 100% open-source foundation, our customers have the freedom to choose: SaaS, hybrid, or self-managed, without compromise.”
Prior to this, WSO2 customers could already run the AI gateway in their own environment. What they could not run there was the AI control plane governing it, which until today was available only as WSO2-operated SaaS. Both now deploy wherever the customer chooses, i.e. on-premises, in a national or sovereign cloud, or on a hyperscaler in every case with the option to run fully air-gapped, with no outbound connection to WSO2.
AI Workspace launched in March 2026 with SaaS and hybrid deployments. Today’s release adds the 100% self-managed option, allowing WSO2 users to fully self-host the entire AI offering available through the API Platform to support 100% sovereign AI initiatives. WSO2 serves 42 national government customers and more than 3,800 local government agencies, along with regulated enterprises in financial services, healthcare, and telecommunications.
The release also continues WSO2‘s unbundled platform strategy where customers can adopt the AI gateway, API management, identity, and integration capabilities and the individual components within each in whatever combination fits their needs, rather than deploying a full stack they don’t require. Customers who prefer a single deployment can still run the entire platform, including API Manager, as one binary.
Self-managed AI Workspace is generally available today as part of WSO2 API Platform, deployable via quick start installer, virtual machine, Docker, or Kubernetes. Documentation is available at wso2.com/api-platform/docs/