How Long Does It Take to Deploy Sovereign AI On-Premise?
A first full deployment typically takes eight to sixteen weeks from order to go-live, planned as five clear stages from hardware to acceptance testing, not the multi-year programme buyers fear.

A first full deployment of sovereign AI on hardware you own typically takes eight to sixteen weeks from signed order to go-live, not the multi-year programme many buyers fear. The work breaks into five stages: hardware procurement, standing up the local inference engine, integration with your identity and data, acceptance testing and security review, then a phased go-live. With existing hardware and light integration a first site can be live in four to six weeks. A new-build estate with formal accreditation and a full air gap can run to four to six months. The single figure that moves the total most is hardware lead time, and it is the one you can start clearing on day one.
This matters in 2026 because the assumption that owning your AI means a capital programme measured in years pushes regulated buyers toward public cloud by default, and that assumption is wrong. An on-premise rollout is closer to a large software integration than a data-centre build: measured in weeks and quarters, planned in clear stages, with most of the uncertainty concentrated in two places you can manage. Banks under DORA, essential and important entities under NIS2, and any organisation holding data it cannot lawfully export need a realistic timeline to plan against, not a vague "it depends".
What are the stages of an on-premise AI deployment?
A first deployment reduces to five stages, each with a defensible duration you can put in a plan.
- Hardware procurement and delivery, two to six weeks. Servers, accelerators, fast storage and networking to your specification. Lead times are the main variable, so this stage starts first and runs in parallel with everything that does not depend on the metal.
- Install and inference engine, a few days to one week. Racking, power and cooling, then standing up Poros, our sovereign inference engine, and loading the models onto hardware you own.
- Integration, two to four weeks. Connecting to your identity provider, your data stores and the applications your people already use, with role and permission mapping.
- Acceptance testing and security review, one to three weeks. Functional testing against agreed criteria, penetration testing and sign-off. Formal accreditation, where required, extends this stage rather than the others.
- Go-live and phased rollout, days to two weeks. A pilot cohort first, then widening access once the system is proven in place.
Add these up and a typical single-site deployment lands in the eight to sixteen week band. The stages overlap where they can, which is how the calendar total stays below the sum of the parts.
Which stage takes the longest?
Usually hardware lead time. Specialist accelerators and storage can take weeks to arrive, and nothing downstream can be racked until they do, so a sober plan places the order first and treats delivery as the critical path. For classified or safety-critical work the other long pole is formal accreditation, which adds a fixed review stage that runs to its own clock. The right move with both is to start them early and run the rest of the rollout alongside, rather than waiting for one to finish before the next begins.
How fast can a deployment go if the hardware is already there?
Fast. When suitable hardware already exists, or a pre-built appliance is used, procurement leaves the critical path entirely and the timeline collapses to install, integration and acceptance. A focused first deployment with standard integrations can then reach go-live in roughly four to six weeks. This is the route for an organisation that wants to prove the approach on a contained first use before committing to a wider estate.
What makes a deployment take longer?
A handful of factors stretch the calendar, and each is knowable in advance.
- New hardware with long lead times on specialist accelerators.
- Formal accreditation or security clearance, which adds a fixed review stage.
- Bespoke integrations into legacy or poorly documented systems.
- A full air gap, which changes how updates and evidence move in and out of the estate.
- Trying to roll out many capabilities at once instead of starting with a focused first set.
None of these turns a quarter into a multi-year programme on its own. The way a timeline slips is by discovering them late, which is why the sizing conversation should surface all five before the order is signed.
What happens after go-live?
The deployment clock stops at go-live. Everything after that is steady state, not part of the initial timeline. Updates and maintenance are a recurring cycle, delivered on-premise as signed offline packages that are verified before they run, with no outbound connection required. Planning treats them as a running cost, the same way you would treat patching any other critical system, rather than folding them into the weeks-to-live figure. A focused first deployment using the initial studios keeps that first go-live tight, with further capability added on your own schedule.
“Owning your AI is not a multi-year programme. It is a quarter of focused work, and most of the uncertainty lives in hardware lead times you can start clearing on day one.”
Where does a Sovereign Intelligence Operating System shorten the timeline?
Mickai is a Sovereign Intelligence Operating System, a SIOS, designed to run entirely offline on hardware the organisation owns, so nothing leaves the building. It compresses the two stages that most often stretch a rollout: integration and acceptance. Integration is shorter because identity is hardware-attested and bound to the audit chain from the start, and the platform is built around a zero-egress inbound perimeter, so a whole class of data-flow review simply falls away. Acceptance is faster because every action is sealed under post-quantum cryptography to a tamper-evident, independently verifiable Offline Attestation Record, the OAR, so the evidence a security reviewer asks for is generated by the system rather than assembled by hand. The design is protected by 104 filed UK patent applications, 2,340 claims, owned by Mickai LTD, Companies House 17166618, with MICKAI a registered UK trademark. Named inventor and chief executive: Micky Irons.
Frequently asked questions
How long does it take to deploy on-premise AI?
A first full deployment typically takes eight to sixteen weeks from order to go-live, across five stages: hardware, inference engine, integration, acceptance testing and rollout. With existing hardware and light integration, four to six weeks is achievable. A new estate with formal accreditation and an air gap can reach four to six months.
What is the longest part of an on-premise AI deployment?
Usually hardware lead time, because specialist accelerators and storage can take weeks to arrive and the rack cannot be built until they land. For classified or safety-critical work, formal accreditation is the other long pole. Both can be started early and run in parallel with the rest of the rollout.
Can sovereign AI be deployed faster than eight weeks?
Yes, when the hardware already exists or a pre-built appliance is used, which removes procurement from the critical path. A focused first deployment with standard integrations can then reach go-live in roughly four to six weeks.
Does an air-gapped deployment take longer?
Usually a little. An air gap adds accreditation steps and changes how updates and audit evidence move in and out of the estate, all on signed offline media. The core install and integration are not slower, but the surrounding process is more deliberate.
Is deployment a one-off, or does maintenance keep adding time?
Deployment is a one-off that ends at go-live. Updates and maintenance are a separate, ongoing steady state, delivered on-premise as signed packages verified before they run, with no outbound connection. Planning treats them as a running cost, not part of the initial timeline.
How does a Sovereign Intelligence Operating System shorten the timeline?
By pre-integrating the parts that are normally bespoke. Attested identity, a zero-egress perimeter and an automatically sealed audit record compress integration and acceptance, the two stages that most often overrun, so more of the schedule is predictable from the outset.