MICKAI®ArticlesShared IT felled London councils.…
Article · 30 July 2026

Shared IT felled London councils. AI must not repeat the mistake

Councils reduce the blast radius of shared IT failures by running AI on hardware they own, air-gapped and audited, rather than adding another shared dependency.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
sovereign-ailocal-governmentcyber-resilienceshared-servicesair-gapped
Shared IT felled London councils. AI must not repeat the mistake

The fastest way for a council to reduce the blast radius of a cyberattack is to stop concentrating critical capabilities in systems that many authorities depend on at once, and that lesson matters most for artificial intelligence, the next capability councils are about to adopt at scale. When shared infrastructure fails, every organisation built on it fails together. The attack on shared London council IT that ran from late 2025 into January 2026 made that arithmetic painfully concrete.

A cyberattack on shared IT systems used by several London councils, including Kensington and Chelsea, Westminster and Hammersmith and Fulham, brought down core services and led to the theft of personal data relating to thousands of residents. Computer Weekly reported in January 2026 that the National Cyber Security Centre had been supporting the response through late 2025 and into the new year. One intrusion, several authorities, thousands of residents affected. In local government, that is what a wide blast radius looks like.

What happened to London's shared council IT systems?

Attackers compromised IT systems shared by several London boroughs, taking core services offline and stealing personal data relating to thousands of residents, with the National Cyber Security Centre supporting the response into January 2026. The affected authorities, including Kensington and Chelsea, Westminster and Hammersmith and Fulham, share technology services, which is exactly why one intrusion disrupted more than one council at the same time. Shared services pool scarce budgets and scarcer specialist staff, but they also pool risk, and residents of every participating borough carry that risk together.

Why does shared infrastructure widen the blast radius of an attack?

Shared infrastructure widens the blast radius because a single point of compromise becomes a single point of failure for every organisation that depends on it. An attacker who breaches one council's standalone network affects one council. An attacker who breaches a shared platform affects every authority on it simultaneously, along with every resident whose data sits inside it. Concentration cuts cost, and it concentrates consequence in exactly the same measure.

Does adding cloud AI make the dependency problem worse?

Yes, layering cloud-hosted AI on top of shared infrastructure adds a new shared dependency with an unusually wide reach into a council's most sensitive work. An AI assistant that reads case files, drafts correspondence and summarises safeguarding notes touches more resident data than almost any single line-of-business system, and if it runs in a remote cloud it extends the attack surface beyond the council's perimeter and beyond its control. Before adding any AI dependency, we believe every authority should be able to answer a short set of questions.

  • Where does the model run, and who controls the hardware it runs on?
  • If the provider is compromised or offline, does the capability survive?
  • What resident data leaves the council's network, and can that flow be reduced to zero?
  • Is there a tamper-evident record of every action the AI has taken, verifiable without the vendor?
  • How many other organisations share the same dependency, and would they all fail together?

How does a sovereign operating system reduce the blast radius?

A sovereign operating system reduces the blast radius by putting the AI capability on hardware the council owns, inside the council's own perimeter, so it never becomes another shared dependency that fails many authorities at once. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on-premise and air-gapped where required. Nothing phones home, no resident data leaves the building, and the capability keeps working even when external networks and suppliers do not. A hardware-held root of trust anchors the system to the machine it runs on, and sensitive actions are gated behind voice-biometric confirmation, so approving a consequential step takes more than a stolen password.

Control also has to cover what the system decides, not just where it runs. Our cooperative multi-model consensus substrate requires specialist sovereign models to agree before any sensitive action executes, so a single model's error or manipulation cannot quietly become a council's action. That matters in exactly the environments this attack exposed, where recovery teams had to establish what had happened across systems they did not fully control.

A capability you rent from a shared platform fails when the platform fails. A capability you own inside your own walls fails only when you do, and it keeps a signed record either way.

Mickai

What evidence does a council need after an incident?

After an incident, a council needs an account of what its systems did before, during and after the intrusion that will stand up to the Information Commissioner, to auditors and to residents. This is what the Open Audit Record provides. Every action taken through Mickai is cryptographically signed, post-quantum secure, tamper-evident and verifiable offline, so the evidence exists the moment the action happens rather than being reconstructed from partial logs under pressure. A signed, independently verifiable record does not prevent an attack, but it collapses the time between the question and a provable answer.

What should local authorities do now?

Local authorities should map their shared dependencies now, before adding AI to them, and treat every new capability as a decision about blast radius as much as functionality. We are direct about where we stand. Mickai carries 87 studios on one operating system, ten of them production-ready at launch and 77 in development, and the architecture is covered by 104 filed UK patent applications across 2,340 claims, a moat rather than the point. The point is simpler. The London attack showed what happens when many authorities lean on one compromised platform. AI is the next platform decision councils will make, and it is the one where sovereignty, ownership and a verifiable record are still available by design rather than by retrofit.

Frequently asked questions

Would an on-premise operating system have prevented the London councils attack?

No single technology prevents every attack, and we do not claim otherwise. What an on-premise, air-gapped operating system changes is the cascade. An AI capability running on each council's own hardware is not part of the shared platform, so a compromise of shared IT does not automatically compromise it, and its signed audit record remains available to support the response.

Can councils still share services if they run AI on their own hardware?

Yes. Sovereign AI does not argue against sharing back-office services where the economics work, it argues against making every critical capability depend on the same shared point of failure. Councils can continue to pool commodity IT while keeping the systems that reason over resident data, and the records of what those systems did, under their own control.

How does the Open Audit Record help during incident response?

It gives responders a cryptographically signed, tamper-evident record of every action the system took, verifiable offline and without reference to any vendor. Instead of reconstructing events from scattered logs across suppliers, a council can show exactly what its AI did, who authorised it and when, which is the evidence regulators and auditors ask for after a breach.

Does running air-gapped mean giving up modern AI capability?

No. Mickai runs our own sovereign models entirely on the customer's hardware, fully offline, with a cooperative multi-model consensus substrate that cross-checks outputs before sensitive actions run. The capability lives inside the council's perimeter, so it keeps working during an external outage or a supplier compromise rather than failing alongside them.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on-premise and air-gapped, with every action recorded in the cryptographically signed, post-quantum secure Open Audit Record. It carries 87 studios on one operating system, with ten production-ready at launch and 77 in development, and its architecture is covered by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/london-councils-shared-it-cyberattack-resilience. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles