Skip to main content
Reading viewAll insights →
BLOG20 min read

Hosted In-Country Means Retrained In-Country: The Two Numbers Behind a Sovereign AI Claim

Hosted In-Country Means Retrained In-Country: The Two Numbers Behind a Sovereign AI Claim
Tarry Singhby Tarry SinghFounder & CEO · 7 Oct 2026
Share

In four weeks of August 2026, ADNOC and SLB said an AI platform developed in the UAE and hosted within ADNOC's cloud environment had gone live across more than 120 drilling rigs, Baker Hughes said it would build a research and technology development centre for Kuwait Oil Company inside the Ahmadi Innovation Valley, Aramco and Aramco Digital said they had signed agreements on localizing critical technologies and building national industrial capabilities, and Sinopec said its Great Wall large model had further improved and its Fenghuo industrial AI agent had launched. Every one of those is a statement about where models will live. None of them carries the two numbers that decide whether the models can be kept current there: how many are in production, and how often each one is retrained. Put a fixed bench behind those two numbers and the arithmetic is unforgiving in a way that is easy to miss. On the on-prem bench we specified for one operator, at an assumed one retrain slot and an assumed 12 hour retrain, the fleet can grow 436% between the point where 5% of retrains miss the overnight turnaround from an illustrative scenario we published and the point where half of them do. Take the same bench to eight slots and that warning band closes to 23%. A larger sovereign bench is safer at any given fleet and tells you far less before it stops clearing the window.

On 4 August 2026 ADNOC announced with SLB that a Real-Time Operations Center had been deployed across more than 120 of ADNOC Drilling's rigs, and described it as "developed in the UAE and hosted within ADNOC's cloud environment" [1]. A week later, on 11 August, Baker Hughes announced a multi-year contract with Kuwait Oil Company under which it "will build a dedicated research and technology development center in the Ahmadi Innovation Valley" and "build local expertise" [2]. At LEAP 2026 in Riyadh, which the release itself places between 31 August and 3 September, Aramco and Aramco Digital announced "a number of Memoranda of Understanding (MoUs) and agreements with leading technology companies" covering "cybersecurity, industrial AI and innovation, localizing critical technologies, and building national industrial capabilities" [3]. A week before that window opened, on 24 August, Aramco published a set of agreements with French companies including one MoU with Aramco Digital on "industrial AI, virtual twin/digital twin technologies" [4]. And on 23 August Sinopec's interim results said the company had launched "the industry's first digital expert, namely the 'Fenghuo' industrial AI agent", and that "the capabilities of the Great Wall large model further improved" [5].

Four operators, four statements about sovereignty, and not one of them says how much AI there will be to keep current inside the boundary. That is not a complaint about the releases. Two are deployment or contract announcements, one is a partnership roundup and one is a results statement, and none of them claims to be a capacity plan. It is the reason this piece exists. Where a model runs is a legal and political question with a clean answer. How often it can be rebuilt there is an arithmetic question with an answer that depends on two numbers none of these four publishes: the count of models in production, and how often each one is retrained.

Four claims, read to the letter

ADNOC's is the strongest of the four and the only deployment. The body copy is the operator's own: RTOC is "developed in the UAE and hosted within ADNOC's cloud environment", it "keeps critical operational data and workflows securely within the country", and it is running across more than 120 rigs, enabled by SLB's DrillOps [1]. The phrase "sovereign cloud environment" is not ADNOC's; it appears inside the quote from Rakesh Jaggi, President, Digital at SLB, in the same release [1]. That distinction matters here because the two phrases carry different commitments, and only one of them is the operator's own word.

The release also carries operating figures: engineering effort down 30% to 40%, engineers able to support two to three times more rigs, incident response times cut by 4 to 12 hours, and one to two days of rig downtime avoided [1]. Those are stated benefits of the RTOC deployment. They are not statements about model retraining, they do not imply a model count, and nothing below attaches them to one. No model, technique or training cadence is named anywhere in the release.

The Kuwait Oil Company item is a vendor account, and reading it as anything else would be a mistake. The release is Baker Hughes', on GlobeNewswire, and the quoted speaker is Baker Hughes' own chairman and chief executive [2]. It describes the Ahmadi Innovation Valley as "KOC's flagship initiative aimed at establishing an in-country research and innovation hub", and says the collaboration will focus on "digital and artificial intelligence (AI) automation solutions" for recovery, operating cost, water production and power consumption [2]. What is announced is a contract to build a centre. There is no live system, no model count, and no figure of any kind in the release.

The Aramco LEAP item is Aramco's own release text distributed on Zawya rather than an item on aramco.com, it carries no printed publication date, and it names no counterparty [3]. What it announces is intent: MoUs and agreements, in the plural, on cybersecurity, industrial AI and localizing critical technologies. Ahmad O. Al Khowaiter is quoted on building "secure cloud environments, resilient connectivity, digital ethics, and AI-enabled monitoring" [3]. The 24 August French release is first-party and is more specific, but the specificity runs the other way: its industrial AI item is an MoU with Aramco Digital establishing "a framework for potential collaboration" [4]. The $3.7 billion in that release is the potential combined value of three things together, a corporate procurement agreement for drilling equipment, a purchase agreement for oil country tubular goods, and that MoU [4]. It is not the value of the AI work, and it should never be quoted as if it were.

Sinopec names two systems and quantifies neither [5]. A launched agent and an improved large model are the company's own words for its own work, and they are the closest of the four to an operating AI estate. The release still does not say how many models are in service, on what hardware, or how often any of them is rebuilt.

What a sovereign bench actually is

We have built this. For a mid-sized Middle East carbonate operator, a single clause in a mutual non-disclosure agreement, requiring that confidential information be held only on local machines and "not stored on a remote server of any kind", removed the public cloud from the option set before a line of code was written [6]. The bench that followed was an on-prem research build centred on one Nvidia DGX A100 node, 4 to 8 A100 GPUs, up to 640 GB of GPU memory, 2.5 to 5 petaFLOPS, with a private DataOps server beside it so that data work did not compete with training for the same machine [6] [7].

At the close of that programme we handed over three costed hosting options rather than one recommendation, and the honest part of that document was the latency column [7]. Fully managed, on a footprint that never goes cold, retrains in minutes to hours. Operator plus vendor, on managed infrastructure, lands in the two to three week range. Operator only, in-house on the on-prem stack, is the slowest at first, because a freshly transferred team measures a retraining run in days while the muscle memory builds [7]. Ownership and latency trade against each other, and the trade is the whole of the decision.

The other half of the picture is what happens when a fleet of models is kept current rather than shipped once, and here we draw on an illustrative scenario we published, a composite case study rather than a client record. In it, an agentic MLOps loop runs across dozens of models on about 40 producing assets: a monitoring agent watches production feeds and log ingestion, a reconciliation agent version-stamps and QCs the inputs, a retraining agent rebuilds the model and back-tests it, and a validation agent runs physics checks before a geoscientist approves promotion [8]. The loop cuts the retrain cycle from six weeks to overnight, about 40 times faster, and its monitoring agent flags and requeues 18 models that would otherwise have drifted quietly into the next quarterly review [8].

One detail of that scenario is the hinge of this piece. The retraining agent "spins up a containerised environment on the client's GPU cloud" [8]. It can take what it needs when drift fires. A bench inside a national boundary cannot. It has a fixed number of slots, and a retrain that arrives when they are all busy waits.

The arithmetic

Take NN models in production, each raising a drift-triggered retrain rr times a month. Each retrain holds one of the bench's cc slots for SS hours. With HH hours in a mean month, the offered load in erlangs and the utilisation are

Offered load and utilisation on a bench that cannot burst
a  =  N r SH,ρ  =  aca \;=\; \frac{N\,r\,S}{H}, \qquad \rho \;=\; \frac{a}{c}

Treat drift as independent across models, so retrains arrive as a Poisson process, and take slot times as exponential and the queue as first come, first served. That is an M/M/c queue, and its waiting time has an exact tail: with C(c,a)C(c,a) the Erlang C probability that every slot is busy on arrival,

The share of retrains whose wait exceeds t
P(wait>t)  =  C(c,a) exp⁡ ⁣(−(c−a) tS)P(\text{wait} > t) \;=\; C(c,a)\,\exp\!\left(-\frac{(c-a)\,t}{S}\right)

The deadline comes from the illustrative scenario. It puts the retrain cycle at six weeks before the loop and about 40 times faster after it, and six weeks is 1,008 hours, so the turnaround the loop achieves is 1,008 divided by 40, or 25.2 hours [8]. A retrain that holds its slot for SS hours can therefore absorb a wait of at most t=25.2−St = 25.2 - S and still land inside it. Above that, the overnight property is gone.

Now rewrite the exponent with u=a/cu = a/c, the utilisation, and solve for the utilisation at which a miss share pp is reached:

How far below saturation a given miss share sits
1−u  =  Sc t ln⁡ ⁣C(c,a)p1 - u \;=\; \frac{S}{c\,t}\,\ln\!\frac{C(c,a)}{p}

The bracket S/(c t)S/(c\,t) is the retrain duration measured against the bench's whole wait budget, and it multiplies the distance in utilisation between any two miss shares. Grow the bench and that distance shrinks in proportion. The bench becomes safe at a much higher utilisation, and the gap between comfortable and failing becomes much narrower. Both of those are the same fact, and only one of them is the one procurement usually hears.

The bench

The exhibit computes that surface rather than drawing it. Left to right is models in production, 5 to 60. Back to front is drift-triggered retrains per model per month, 0.2 to 8 on a log scale. Height is the share of retrains whose wait for a slot exceeds the overnight budget. The amber sheet is half of the retrains; the aqua ribbon is the fleet at which 5% miss and the amber ribbon the fleet at which half do, and the white curtain is your cadence.

One of the four opening values comes from the illustrative scenario. The cursor opens at 18 models, the count its monitoring agent flags and requeues [8]. The deadline the surface is measured against comes from the same scenario, although it is not a control: the overnight turnaround of 25.2 hours is derived on the plate from its two figures, six weeks and 40 times [8]. The other three opening values are assumptions, and the plate labels all three.

The retrain duration of 12 hours and the cadence of one a month are the easy two. The illustrative scenario puts the whole loop, reconcile through validate, at an overnight job, and our record puts full-model training alone at minutes to hours on that node [6] [8], but neither publishes an occupied-slot time, and the scenario says drift surfaces in days rather than months without publishing a per-model cadence [8]. Those two controls are where your own figures go, and they are precisely the two numbers the four releases at the top of this piece do not carry.

The slot count needs saying plainly, because our record does carry a concurrency figure for that node and it is far above one. The bench was sized against a peak of "60 to 90 concurrent runs", packed onto the cards by "slicing one A100 into many hardware-isolated instances" [6]. Those are research runs: variants of one training job differing by a hyperparameter or a data split. A retrain in the illustrative loop this piece takes its deadline from is reconcile, retrain, back-test and validate in sequence [8], and neither source says how many of those slices one of them occupies. So the exhibit opens at one slot, which is the conservative end of a range our sources do not close, and the slot control is where your own number goes. It is also the control the finding lives on.

RETRAIN SLOT WAIT SURFACE13.6%OF RETRAINS MISS THE OVERNIGHT WINDOW AT 18.0 MODELS, 1.00 A MONTHhalf missed42.5 models18.0 models, 1.00 a month13.6% of retrains miss the window5.0% missed7.9 modelsmodels in production, 5 left to 60 rightretrains a model a month, 0.2 at the back to 8 at the frontshare of retrains that miss the window, 0 to 1BENCH UTILISATION29.6%FLEET AT 5.0% MISSED7.9 modelsFLEET AT HALF MISSED42.5 modelsWARNING BAND+436%share that miss the windowhalf of the retrainsyour cadence5.0% missedhalf missedOvernight turnaround 25.2 h = 6 weeks (1,008 h) over the illustrative 40x. Wait budget = that less the retrain duration, 13.2 h.Cursor opens at the 18 models the illustrative loop requeues. Retrain 12.0 h, cadence 1.00 a month, 1 slot: assumed. P(wait > budget) = C(c,a) exp(-(c-a) budget / retrain).
The surface is the share of drift-triggered retrains that wait longer for a slot than the overnight turnaround allows, over every fleet of models in production (left to right) and every retrain cadence (back to front, logarithmic). Height is computed from an M/M/c queue: retrains arrive from the fleet on independent clocks, each holds one of the bench's slots for the retrain duration, and the wait budget is the overnight turnaround less that duration. The amber sheet is half of the retrains. The aqua ribbon is the fleet at which 5% of them miss and the amber ribbon the fleet at which half do; the white curtain is your cadence, and both fleet readouts are taken on it. The models control does not move the two fleet readouts or the warning band: it is a coordinate of the surface, not a parameter of it. Drag the bench control from 1 slot to 8 and watch the warning band close while both fleet readouts move right. The overnight turnaround and the opening fleet come from an illustrative scenario; the bench, the retrain duration and the cadence are assumptions, and every value is yours. Drag or use the arrow keys to orbit, Home to reset.

What the bench shows

At the opening settings the bench is at 29.6% utilisation and 13.6% of retrains already miss the overnight window. One slot holding a retrain for 12 hours can clear 60.88 retrains a month, which is 730.5 hours over 12, so an estate of 18 models at one retrain a month is using well under a third of it. A capacity plan built on that ratio would report plenty of headroom. One retrain in seven is already late.

Now read the two fleet numbers on the same section. At one slot, 5% of retrains miss at a fleet of 7.9 models, and half of them miss at 42.5 models. The warning band readout prints the gap between those two as fleet growth: +436%. That is the room a planner has. The estate can more than quintuple between the first symptom and the point where the overnight property has gone for half the fleet, and the whole of that range sits under a utilisation of 70%.

Drag the bench control from 1 slot to 8 and watch three readouts at once. The fleet at 5% missed goes from 7.9 models to 373. The fleet at half missed goes from 42.5 to 459. And the warning band closes from +436% to +23%. The eight-slot bench is by every measure the better machine: it carries 47 times the fleet before the first symptom appears. It also gives roughly a nineteenth of the warning. On the eight-slot bench the estate goes from 5% missed to half missed while growing by less than a quarter, which for a portfolio adding models every quarter is one or two planning cycles.

That is the finding, and it is a property of the expression above rather than of our numbers. The distance in utilisation between two miss shares is S/(c t)S/(c\,t) times a fixed logarithm. Raise the slot count and both the safe utilisation rises and the interval between service levels contracts. The retrain duration and the wait budget move the same bracket, which is why the same control sweep tells the same story from the other end: hold the bench at one slot and drop the retrain duration from 12 hours to 6, and the band narrows from +436% to +125% while the fleet at 5% missed climbs from 7.9 models to 45.3. Push the retrain out to 24 hours instead and the band widens to +877% while the fleet at 5% missed collapses to 1.6 models. A slower retrain is a worse bench with more warning; a faster one is a better bench with less.

Two controls deliberately do not move that readout, and the code says why. The models slider moves the cursor, the hero and the utilisation, and leaves the two fleet readouts and the warning band exactly where they are, because it is a coordinate of the surface rather than a parameter of it: fleetForMiss and warningBand take no models argument. The cadence slider moves both fleet readouts, because fleetForMiss divides by it, but it leaves the band where it is, because the band is a ratio of two fleets and the cadence cancels. Drag the cadence from 0.20 to 8.00 and the fleet at 5% missed runs from 39.6 models down to 1.0, while the band reads +436% at every point.

What this model is, and what it is not

Both distributional assumptions are stated because both are contestable. Poisson arrivals are the independent-clocks case: models drifting on their own schedules, which is what a per-model drift monitor produces. Real drift is correlated, because a quarterly data drop or a reprocessed seismic volume flags several models on the same day, and correlated arrivals queue worse than independent ones at the same mean. Exponential slot times are the variable end: a retrain pipeline whose duration is nearly deterministic queues better than this model says. The two assumptions push in opposite directions, and neither touches the shape of the result, which comes from the exponent and not from the distributions.

The bench is also modelled as a homogeneous pool of interchangeable slots, one retrain to a slot. A real retrain of a subsurface model may want the whole node, and a real bench may be sliced into partitions, which is the right choice for a research sweep and a different question from the one here. The slot control is where that decision lands: set it to the number of retrains the bench can genuinely run at once.

And the four operators are not being scored against this surface. Nothing in the releases at the top of this piece supplies a model count, a cadence, a retrain duration or a slot count, which is the point of the piece rather than a gap in it. The numbers on the plate that are ours are labelled ours, the 18 models and the six weeks and 40 times come from an illustrative scenario rather than a client record, the derivation from six weeks and 40 times to 25.2 hours is printed, and the two assumptions are named on the plate as assumptions.

Three questions for a hosted-in-country claim

How many models will be in production inside the boundary, and how often is each one rebuilt? Not petabytes, not rig counts, not the value of the agreements. The product of those two numbers, times the retrain duration, is the entire load on the bench, and none of the four releases carries either factor. ADNOC's release is the one that comes closest to an operating system, and it names no model at all [1].

How many retrains can the bench run at once, and what happens to the ones that arrive when it is full? A sovereign bench cannot spill. The illustrative loop we published takes what it needs from the client's GPU cloud when drift fires [8]; a bench inside a national data centre queues instead, and the queue is where the overnight property is lost.

What is the warning band, and who is watching it? This is the question the surface exists to raise. A well-sized bench crosses from 5% of retrains late to half of them late over a narrower band of fleet growth than a small one, which means the better the bench, the earlier the fleet count has to be forecast rather than observed. The instrument prints that band for any bench, and the number it prints at eight slots is the one worth arguing about before the hardware is ordered.

Key takeaways

  1. ADNOC with SLB says an AI platform developed in the UAE and hosted within ADNOC's cloud environment is live across more than 120 rigs; Baker Hughes says it will build an in-country research and technology development centre for Kuwait Oil Company; Aramco and Aramco Digital announce MoUs on industrial AI and localizing critical technologies; Sinopec says its Fenghuo agent launched and its Great Wall large model further improved. One deployment, three statements of intent, and no model count or retrain cadence in any of them.
  2. Read the attributions exactly. The Kuwait Oil Company item is Baker Hughes speaking, not the operator. The phrase 'sovereign cloud environment' is SLB's in ADNOC's release; ADNOC's own words are 'hosted within ADNOC's cloud environment'. The $3.7 billion in Aramco's French release is the combined potential value of a drilling equipment agreement, an OCTG purchase agreement and the industrial AI MoU together, not of the AI work.
  3. Sovereign hosting turns a retrain into a queue. The illustrative loop we published takes slots from the client's GPU cloud when drift fires; a bench inside a boundary has a fixed slot count, so the question stops being flops and becomes whether a retrain gets a slot before the overnight turnaround runs out.
  4. At the opening settings, 18 models as the illustrative loop requeues and an assumed one slot holding a retrain for an assumed 12 hours, the bench sits at 29.6% utilisation and 13.6% of retrains already miss the 25.2 hour turnaround derived from the illustrative six weeks and 40 times. The slot count is an assumption and not a measurement: our record for that DGX A100 node carries 60 to 90 concurrent research runs, not a count of concurrent production retrains.
  5. The warning band is the finding. At one slot the fleet can grow 436% between the point where 5% of retrains miss and the point where half do. At eight slots the same band is 23%, while the fleet at the first symptom moves from 7.9 models to 373. A larger sovereign bench is safer at any fleet and gives roughly a nineteenth of the warning.
  6. The two numbers to ask a hosted-in-country claim for are models in production and retrains per model per month. Their product times the retrain duration is the whole load on the bench, and neither factor appears in any of the four releases.

Limitations

The queue is an M/M/c model with Poisson arrivals and exponential slot times, and both assumptions are approximations that err in opposite directions: correlated drift queues worse than Poisson, near-deterministic retrain durations queue better than exponential. The bench is a homogeneous pool of interchangeable slots, so a bench where retrains contend for different resources, or where one retrain spans several nodes, needs the slot control set to the number of retrains it can genuinely run at once rather than to a GPU count. The overnight turnaround of 25.2 hours is derived from two figures in one illustrative scenario, a six week manual baseline and a roughly 40 times speed-up, and it is neither a client measurement nor an industry norm. The slot count, the retrain duration and the cadence that open the exhibit are stated assumptions, not measurements: our record for that DGX A100 node carries 60 to 90 concurrent research runs, and it does not say how many concurrent production retrains that is. Nothing here is a statement about the capacity, model estate or retrain cadence of ADNOC, Kuwait Oil Company, Saudi Aramco or Sinopec: none of the four releases cited supplies any of those, which is the argument of the piece.

References

[1] ADNOC. ADNOC and SLB Deploy AI Platform Across Over 120 Drilling Rigs to Strengthen Upstream Performance. 4 August 2026. https://adnoc.ae/en/news-and-media/press-releases/2026/adnoc-and-slb-deploy-ai-platform-across-over-120-drilling-rigs-to-strengthen-upstream-performance

[2] Baker Hughes. Baker Hughes Awarded Multi-Year Contract by Kuwait Oil Company for Ahmadi Innovation Valley Project. GlobeNewswire, 11 August 2026. https://www.globenewswire.com/news-release/2026/08/11/3342544/0/en/baker-hughes-awarded-multi-year-contract-by-kuwait-oil-company-for-ahmadi-innovation-valley-project.html This is the vendor's release about the operator, not the operator's own.

[3] Aramco. Aramco advances technology collaboration and innovation at LEAP 2026. Aramco release text distributed on Zawya, not an item on aramco.com; the release carries no printed publication date and places LEAP 2026 between 31 August and 3 September 2026 in Riyadh. https://www.zawya.com/en/press-release/companies-news/aramco-advances-technology-collaboration-and-innovation-at-leap-2026-474170

[4] Aramco. Aramco enhances its global partnership ecosystem through collaboration with French companies. 24 August 2026. https://www.aramco.com/en/news-media/news/2026/aramco-enhances-its-global-partnership-ecosystem-through-collaboration-with-french-companies

[5] China Petroleum and Chemical Corporation (Sinopec Corp). Press Release: Sinopec FY2026 Interim Results. EQS Newswire, 23 August 2026. https://www.eqs-news.com/news/corporate-news/en-press-release-sinopec-fy2026-interim-results/514ef82e-238a-4aa2-9f2d-32f1161d68b0_en

[6] EarthScan. The DGX A100 Stack: Standing Up an On-Prem Research Bench for a Confidential Programme. https://earthscan.io/case-studies/dgx-a100-stack-on-prem-research-bench-confidential-programme

[7] EarthScan. Handing Over the Keys: An ICT Transition and Capability-Transfer Plan That Left a National Operator Running Its Own AI. https://earthscan.io/case-studies/ict-handover-omanization-capability-transfer-milestone

[8] EarthScan. Illustrative scenario: Agentic MLOps: From 6-week retrains to overnight. A composite case study, not a client engagement. https://earthscan.io/case-studies/agentic-mlops-six-week-retrains-to-overnight

Tarry Singh
Tarry Singh

Founder & CEO

More from EarthScan

Related research

All insights →
Public Cloud vs On-Prem vs Hybrid for Confidential Subsurface AI
Insight

Public Cloud vs On-Prem vs Hybrid for Confidential Subsurface AI

Productizing a Paper: Turning a Borehole Transformer Into AutoFrac, AutoVug, and Well-to-Well
Insight

Productizing a Paper: Turning a Borehole Transformer Into AutoFrac, AutoVug, and Well-to-Well

Why Energy Companies Keep Their Models On-Premises
Insight

Why Energy Companies Keep Their Models On-Premises

Stay ahead

EarthScan insights, in your inbox.

Field-tested research on subsurface and energy-transition AI. About twice a month. No noise.

We use your email only for this newsletter. Unsubscribe anytime Privacy.