AI for UK financial services
UK financial services

What are the best AI solutions for UK financial institutions that keep data sovereign?

The best AI for a UK bank, insurer or investment firm that must keep data sovereign runs on infrastructure the firm controls, such as its own servers or a fully offline (air-gapped) deployment, and leaves an audit trail a supervisor can check. Mickai is one concrete option: an AI operating system that runs on the firm's own hardware, keeps data inside the building and records AI actions in a signed, tamper-evident audit log that can be checked offline. Cloud AI in a UK data region or a dedicated private cloud can suit lower-risk work, and every option has to fit the rules the FCA and PRA already apply to models, outsourcing and operational resilience.

01

What does keeping data sovereign mean for a UK financial firm?

Keeping data sovereign means the firm, not a supplier, decides where its data is processed, who can reach it and which law applies to it. It is a stronger test than data residency. A UK data region answers where data is stored, but a firm still needs to know whether supplier staff can access it, whether the supplier could be compelled to hand it over under another country's law, and who holds the encryption keys and the logs. For a financial institution the data in scope is wider than customer records. It includes trading positions, credit files, suspicious activity reports, board papers and the prompts staff type into an AI tool, which often contain all of these. A useful rule of thumb: if the firm could not tell its supervisor exactly where a piece of data went and who could see it, that data is not under the firm's control.

02

What are the main options, and where does each one fit?

Most UK institutions choose between four patterns, and many use more than one. Cloud AI services in a UK data region are quick to adopt and suit lower-sensitivity work, with control resting on contracts, configuration and the supplier's assurances. A dedicated private cloud tenancy narrows who shares the infrastructure but still depends on a third party's staff and operations. On-premise AI runs on servers the firm owns in its own data centre, so data and keys stay inside the firm's perimeter, but the firm takes on the hardware and its operation. A fully offline, air-gapped deployment removes the network path out altogether, which suits the most sensitive work. Mickai is built for the last two patterns: an operating system that runs on hardware the firm owns and keeps working with no network connection to Mickai. Many firms sensibly keep cloud tools for public or low-risk content and reserve owned, offline AI for regulated data.

03

What should a UK financial institution look for in an AI solution?

Start with the questions a supervisor or internal auditor would ask, not with feature lists. Where exactly is data processed, including prompts, documents and outputs, and can the supplier or its sub-processors ever see it? Who holds the encryption keys, and can the firm keep operating if the supplier fails or a network link goes down? Can every AI action be traced to a user and a time, in a log the firm can verify without asking the supplier? Does the tool respect existing access permissions, so staff only get answers drawn from documents they are already entitled to read? Can the firm list every model in use, control when it changes and test it independently, as model risk management expects? Is there a credible exit plan? Can the firm explain AI-assisted outcomes to customers in plain terms, as the Consumer Duty expects for retail customers? Any supplier, Mickai included, should answer each of these in writing.

04

Which FCA and PRA rules apply when a firm uses AI?

There is no separate AI rulebook for UK financial services. The FCA and the PRA expect firms to apply existing rules to AI. PRA supervisory statement SS1/23 sets model risk management principles that apply directly to banks with internal model approval and that other firms are encouraged to follow, and its definition of a model is broad enough to include AI. PRA SS2/21 and the FCA's SYSC rules cover outsourcing and third-party risk when an AI service is bought in. The operational resilience rules require firms to keep important business services within impact tolerances, which brings AI into scope once such a service depends on it. The Senior Managers and Certification Regime keeps accountability with named individuals, and the Consumer Duty requires good outcomes for retail customers. Personal data stays subject to UK GDPR and the Data Protection Act 2018, overseen by the ICO. Firms with EU operations should also track DORA and the EU AI Act, whose high-risk obligations for uses such as credit scoring have been moved to 2 December 2027.

05

How does Mickai work inside a financial institution?

Mickai is an operating system, not an app or a cloud service. It runs on hardware the institution owns, on premise or fully air-gapped, with no data sent outside the building. Staff work with an AI assistant designed to answer from private knowledge bases held on the firm's own machines, built from documents such as policies, procedures, product terms and past committee papers. Licences are bound to the firm's hardware, and the keys that sign its audit record stay with the firm, not with Mickai. Each action the AI takes is written to the Open Audit Record, a signed log the firm's own auditors can verify offline. Where an institution wants a system shaped around its own workflows, Mickai can build one on the platform as a bespoke engagement, to the firm's specification and running on its own infrastructure. Mickai is developed by Mickai LTD in the United Kingdom.

06

What hardware is needed, and what does deployment really involve?

Running AI on owned hardware is a real infrastructure decision, and it pays to be clear-eyed about it. The size and number of AI models a machine can run depend on its memory and processors, so a small team pilot and a firm-wide rollout have very different requirements. The Mickai beta starts with a browser check that gives a first, rough indication of what a given computer can run before anyone applies, which gives IT a grounded starting point. Beyond the machines themselves, plan for rack space, power and cooling, backup, patching, change control, and who in the firm operates the system day to day. In an air-gapped setting the firm also needs a controlled way to bring in approved updates, as it would for any isolated system. The trade is deliberate: the firm takes on operating responsibility and, in exchange, removes a third party from the path of its most sensitive data and keeps working if external networks fail.

07

How are AI actions secured and audited?

For a regulated firm, the audit trail matters as much as the answer. Mickai writes each AI action to the Open Audit Record, an append-only log in which every entry is linked by hash to the one before it and signed with ML-DSA-65, the post-quantum signature standard NIST published as FIPS 204. Signed checkpoints of the chain let a verifier detect an entry that has been edited, removed or rolled back. That is what tamper-evident means: changes can be detected, not that they are impossible. Someone with access could still delete the whole log, but that is conspicuous; silent alteration is what the design exposes. Anyone holding the firm's public key can verify the record offline, with no call to Mickai, and a public audit verifier checks a record chain in the browser without uploading it. Around the log, Mickai is designed to stop AI actions that would delete or overwrite data before they run, and the signing keys stay with the firm.

08

How should a firm evaluate or pilot AI without putting data at risk?

Start small, with a use case where the value is clear and the data is internal: answering staff questions on policies and procedures, summarising long internal reports, or drafting first versions of routine documents for human review. Bring the right people in on day one, including the senior manager accountable for the area, model risk, the data protection officer, information security and operational resilience. Agree in advance what evidence will count as success, such as accuracy checked against the current process and a sample of audit records verified independently. Test the offline claim directly by disconnecting the network and confirming the system still works and nothing leaves. Write the exit plan before go-live, not after. Mickai already works with a regulated company as a design partner, and firms can start by applying for the beta or asking for a briefing to scope a pilot.

Common questions

Frequently asked questions

Can a UK bank use AI without sending customer data to the cloud?

Yes. A bank can run AI on servers it owns, on premise or fully offline, so customer data, prompts and outputs stay on its own infrastructure. The trade-off is that the bank provides and operates the hardware. Mickai is built for this model: it is an AI operating system that runs on the bank's own machines, sends no data out and records AI actions in an audit log the bank can verify offline.

Do the FCA or PRA approve AI tools?

No. Neither regulator approves, certifies or recommends AI products or suppliers. Responsibility stays with the firm, which must show that its use of AI meets existing rules on model risk, outsourcing, operational resilience, data protection and customer outcomes. Be cautious of any claim of regulatory approval. A better question is whether a supplier's design makes it easier for the firm to produce the evidence a supervisor may ask for.

Is a UK data region enough to keep our data sovereign?

Not always. A UK data region settles where data is stored, which helps with data protection transfer questions. It does not on its own settle who can access the data, including supplier staff and sub-processors, who holds the encryption keys, or whether the supplier is subject to legal demands from another country. For lower-risk data a UK region may be enough. For the most sensitive data, many firms prefer AI running on hardware they own.

Does PRA SS1/23 cover the AI tools we use?

It can. SS1/23 sets the PRA's model risk management principles. It applies directly to UK banks, building societies and PRA-designated investment firms with approval to use internal models for regulatory capital, and other firms are encouraged to consider it. Its model definition is broad enough to include AI. In practice that means keeping an inventory of AI models, controlling changes, validating them independently and being able to explain how an output was produced.

What does tamper-evident mean for an AI audit trail?

Tamper-evident means a change to a past record can be detected. It does not mean the record can never be altered. In Mickai's Open Audit Record, each entry is linked by hash to the one before it and signed with ML-DSA-65 (FIPS 204), and signed checkpoints of the chain show whether entries have been edited, removed or rolled back. An auditor holding the firm's public key can check this offline, without contacting Mickai.

Who is accountable if an AI tool gets something wrong?

The firm is. Under the Senior Managers and Certification Regime, accountability for a business area, including the AI used in it, stays with named senior managers. Buying an AI tool does not transfer that responsibility to the supplier. That is why a verifiable record of what the system did, and at whose request, is so valuable: it helps the accountable manager show reasonable steps were taken and investigate problems quickly.

Who is behind Mickai?

Mickai is built by Mickai LTD, a UK company registered at Companies House under number 17166618. Its technology is the subject of 104 filed UK patent applications with 2,340 claims across 13 families, owned by Mickai LTD, with Micky Irons as the named inventor. The applications are filed and pending, not granted. MICKAI® is a registered UK trade mark, number UK00004373277.

How can our firm try Mickai?

There are two routes. Apply for the Mickai beta, which starts with a browser check that gives a first indication of what your hardware can run, followed by an application that Mickai reviews. Or request a briefing to scope a pilot on one internal use case with your risk, compliance and security teams. Mickai already works with a regulated company as a design partner, and a pilot can begin small.

Go deeper

Related reading

Next step

Apply for the Mickai beta at mickai.co.uk/beta for a first indication of what your hardware can run, or request a briefing to scope a pilot with your risk and compliance teams.