MICKAI®ArticlesHow Airports Meet EASA Part-IS fr…
Article · 18 August 2026

How Airports Meet EASA Part-IS from February 2026 with On-Site AI

Airports meet EASA Part-IS by owning information-security risk themselves and running AI on airport hardware so no passenger or operational data leaves the boundary.

Author
Micky Irons
Published
18 August 2026
Follow Micky Irons
LinkedInX
easa part-isaviation cybersecuritysovereign aizero egressairport compliance
How Airports Meet EASA Part-IS from February 2026 with On-Site AI

Airports meet EASA Part-IS from 22 February 2026 by treating information-security risk as the operator's own accountability rather than the vendor's, and by keeping any artificial intelligence that touches passenger or operational data on airport-owned systems inside that accountable boundary. Part-IS requires the aerodrome operator to run its own information security management system across the systems it depends on, so a supplier's SOC 2 attestation covers the supplier and not the operator. When the AI runs on operator-owned hardware behind a zero-egress perimeter, no passenger or operational data leaves the boundary, which is the clearest way to show an auditor that the risk sits exactly where the regulation places it.

This matters because the 2026 procurement conversation has moved from features to accountability. Public cloud AI services send data off the operator's estate to infrastructure the operator neither owns nor controls, and Part-IS asks the operator to evidence control of that exact risk.

Which rule makes this necessary, and when does it apply?

Part-IS is the common name for the European information-security rules for aviation: Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203. For aerodrome operators and air navigation service providers, Implementing Regulation 2023/203 applies from 22 February 2026. It requires each approved organisation to establish and maintain an information security management system that identifies information-security risks to aviation safety, protects against them, detects and responds to events, and reports incidents to the competent authority. The accountable manager owns that system, and responsibility cannot be signed away to a supplier.

Why does a vendor's SOC 2 not discharge Part-IS?

A SOC 2 report is an independent attestation of one service organisation's controls against the Trust Services Criteria, scoped and bounded by that vendor. Part-IS obliges the operator to manage information-security risk across its own systems and across every interface with contracted providers. A clean SOC 2 from a cloud provider tells the airport how that provider runs its data centre, not how the airport controls the risk of sending its data there. Under Part-IS the operator stays accountable for the whole chain, so the attestation is an input to the operator's risk assessment, never a replacement for it.

How does keeping the AI on airport systems work?

Mickai is a Sovereign Intelligence Operating System, a SIOS. It runs offline on hardware the operator already owns, inside the airport's own security boundary. The perimeter is zero-egress and inbound-only: data and prompts enter, results stay local, and nothing is sent to an external model or a vendor cloud. Identity is hardware-attested, so every action is bound to a specific device and operator, and each action is cryptographically sealed into a post-quantum signed audit ledger. Because the sovereign models and their weights sit on the operator's own machines, there is no passenger record, no flight-operations feed and no staff data that has to cross the accountable boundary to be useful. The architecture is the subject of 104 filed UK patent applications and approximately 2,340 claims owned by Mickai LTD, filed and patent pending.

What can an auditor actually check?

If the perimeter is inbound-only and the model weights reside on operator hardware, there is nothing to send outward and nothing to intercept in transit. Beyond that, an auditor can verify four concrete things:

  • The audit ledger is cryptographically sealed and can be verified offline, signed under FIPS 204 (ML-DSA) as the primary signature standard, with FIPS 205 (SLH-DSA) available as a stateless-hash alternative.
  • Hardware-attested identity binds each recorded action to a known device and a named operator, so the log is tamper-evident, not merely tamper-resistant.
  • The network configuration shows an inbound-only path, which an auditor can test rather than take on trust.
  • Cross-model consensus is recorded, so where more than one sovereign model contributed to an output the decision trail is preserved.

These are checkable facts about the operator's own estate, which is precisely what a Part-IS assessment is meant to examine.

Part-IS makes the airport accountable for its own information-security risk, so the safest architecture is one where the AI never moves the data off the operator's systems in the first place.

How does this sit with DORA, NIS2 and the EU AI Act?

The same on-site architecture answers several regimes at once. DORA has been in force since January 2025 and governs operational resilience for financial entities and their critical providers. NIS2 covers essential and important entities, and air transport falls inside its scope. GDPR governs any personal data in the system. On the EU AI Act, the high-risk obligations under Annex III that were once due on 2 August 2026 have been deferred by the Digital Omnibus to 2 December 2027, with embedded high-risk systems under Annex I moved to 2 August 2028 and the Article 50 transparency duties largely unchanged. Keeping data and inference inside the operator's boundary, sealed and offline, is the same answer whether the auditor arrives under Part-IS, DORA, NIS2 or GDPR. It also sidesteps the US CLOUD Act, because data that never leaves sovereign hardware is not reachable through a foreign provider.

What should an airport ask a supplier before 22 February 2026?

Procurement teams can compress the whole question into a short checklist:

  • Where does inference run, and can it run with no outbound network path at all?
  • Do model weights sit on our hardware, or on infrastructure a third party controls?
  • Is the audit log independently verifiable offline, and under which signature standard is it signed?
  • Is identity attested in hardware and bound to each logged action?
  • Does the supplier claim a SOC 2 discharges our Part-IS duty, or does it accept that accountability stays with us?

A supplier that cannot keep inference and data inside the operator's boundary is asking the airport to carry a risk that Part-IS says the airport must control. Mapping to ISO/IEC 42001 for AI management-system governance is a reasonable further test of maturity.

Frequently asked questions

Does EASA Part-IS apply to airports?

Yes. Aerodrome operators and air navigation service providers fall under Commission Implementing Regulation (EU) 2023/203, which applies from 22 February 2026. Each approved organisation must run an information security management system covering the systems its aviation safety depends on, and the accountable manager owns that duty.

Does a vendor's SOC 2 report satisfy Part-IS?

No. A SOC 2 attests to a vendor's own controls within a scope the vendor sets. Part-IS makes the airport accountable for information-security risk across its own systems and its supplier interfaces. A SOC 2 is useful evidence to feed the operator's risk assessment, but it does not transfer the operator's accountability to the vendor.

Can we use public cloud AI and still meet Part-IS?

Using public cloud AI is not automatically non-compliant, but it moves passenger and operational data to infrastructure the operator does not own, which the operator must then assess and control under Part-IS. Keeping the AI on operator-owned hardware with no outbound path removes that risk at source rather than documenting it after the fact.

What is a zero-egress AI deployment?

A zero-egress deployment runs the AI models entirely on the operator's own hardware behind an inbound-only perimeter. Prompts and data go in, results stay local, and nothing is transmitted to an external model or vendor cloud. Because no passenger or operational data leaves the accountable boundary, the operator can evidence control directly rather than relying on a third party's assurances.

How does on-site AI help with DORA and NIS2 as well?

DORA has applied since January 2025 and NIS2 covers essential and important entities including air transport. Both ask the entity to control operational and information-security risk across its systems and providers. AI that runs offline on owned hardware, with a sealed and verifiable audit ledger, gives one architecture that answers Part-IS, DORA and NIS2 from the same evidence base.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/airports-easa-part-is-2026-onsite-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.
18 Aug 2026
Can councils run AI on resident and social care records without adding a cloud data processor?
Councils can run AI on resident and social care records without adding a cloud data processor by running it on hardware they own, with no data leaving the building. If no third party ever receives the records, there is no processor to contract or record.