MICKAI®ArticlesMonitoring Machines Without Sendi…
Article · 4 September 2026

Monitoring Machines Without Sending The Readings Away

Equipment telemetry is more sensitive than it looks, and anomaly detection is only useful if it can show its evidence.

Author
Micky Irons
Published
4 September 2026
Follow Micky Irons
LinkedInX
Sovereign AIMonitoringCritical infrastructureBespoke systems
Monitoring Machines Without Sending The Readings Away

An organisation running an estate of instruments or machinery usually has more monitoring data than it can read and fewer options for what to do with it than it expects. The obvious answer, stream the telemetry to a cloud service that watches for abnormalities, runs into a problem that has nothing to do with the quality of the detection: the readings themselves are often not free to send.

Telemetry is more sensitive than it looks

Operational readings are treated as boring because they are numerical, and that intuition is usually wrong. A sequence of measurements from an instrument estate can disclose a great deal.

  • Utilisation, which is commercially sensitive when a competitor can infer capacity, throughput or margin from it.
  • Fault and failure history, which frequently sits under warranty, service or maintenance contract terms that restrict disclosure to third parties.
  • Location, movement and duty cycle, which in defence, energy and transport contexts is operationally sensitive on its own.
  • Indirect subject data, where the pattern of usage maps to identifiable individuals even though no identifier appears in the feed.
  • Configuration and calibration, which reveals how a regulated process is actually run rather than how it is documented.

None of that is exotic. It is why procurement teams in regulated sectors ask where monitoring data will be processed long before they ask how accurate the detection is, and why an otherwise strong monitoring proposal can fail on a question the engineering team considered secondary.

Detection is the easy half

Finding an anomaly in a signal is a well understood problem with a deep literature and a great many workable methods. The hard part in an operational setting is not detection. It is what happens in the twenty minutes after the flag.

Somebody has to decide whether to intervene. That person needs to know what the system saw, what it compared the reading against, whether the same pattern has appeared before, and what happened last time. A flag without that context is an interruption rather than information, and an estate that produces interruptions gets its alerting turned down until it produces nothing at all. Most monitoring deployments do not fail loudly. They fail by being quietly ignored.

A system that flags an exception without showing its evidence has moved the work rather than done it.

Evidence changes the architecture

Requiring the evidence alongside the flag is not a reporting feature bolted on at the end. It constrains the design from the beginning, because the system has to retain what it compared against, record the reasoning at the moment of the decision, and be able to reproduce that later without the underlying data having moved or changed.

This is where the sovereign architecture earns its place rather than merely satisfying a procurement question. If the readings stay on the organisation's own hardware, the history the system reasons over is complete and locally held. If every consequential action is written to a tamper evident record, the reasoning behind a flag can be produced months later for a regulator, an insurer or a counterparty, and can be checked without asking the vendor to vouch for it.

The offline test

For estates in genuinely constrained environments, isolated operational technology, secure facilities, remote sites with intermittent connectivity, there is a simple test worth applying to any monitoring proposal. Disconnect the network and see what still works.

A system that depends on a cloud endpoint stops detecting, or worse, silently queues and then floods when the link returns. A system designed to run offline continues to watch, continues to record, and can still verify its own audit trail with the cable out. That is not a resilience feature. It is a statement about where the intelligence actually lives.

What a build like this involves

The engineering is not mysterious, but the sequence matters, and it starts further back than teams expect.

  • Establish what normal looks like from the organisation's own history, rather than importing a generic baseline that will misfire on this estate.
  • Agree what counts as an exception with the people who will act on it, before building the detector, so the threshold is an operational decision rather than a statistical one.
  • Build the evidence path at the same time as the detection path, because retro fitting it means retaining data that was already discarded.
  • Run supervised alongside the existing process, with a person clearing every consequential action, until the exception rate and the false positive rate are both understood.
  • Only then decide what, if anything, is allowed to act without a person in the loop.

A necessary limit

Where a monitoring system's intended use falls under a device, clinical or safety regime, the classification and its approvals sit with the operator. Building a capable system and holding a regulatory clearance are different things, and a supplier that blurs them is not one to commission. The honest position is that the engineering can be built and evidenced now, and the regulatory pathway is the operator's to run, with the supplier supporting the evidence rather than claiming the clearance.

The general principle holds across sectors. Watch the estate, flag the exception, show the evidence, and keep all three inside the building. Most of the difficulty is in the third and fourth of those, which is exactly why they are worth specifying before anyone starts building.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/monitoring-machines-without-sending-the-readings-away. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles