OFFICIAL SENSITIVE and AI: the question UK departments must answer
The defensible way for a UK department to apply AI to OFFICIAL SENSITIVE material is to run it inside its own estate, air gapped, with every action sealed and a person in charge.

The defensible way for a UK department to apply AI to OFFICIAL SENSITIVE material is to run the AI inside its own estate, on hardware it owns, air gapped, with a person clearing every consequential action and a sealed record of everything the system does. The UK Government Security Classifications Policy, updated in June 2023, places handling caveats on OFFICIAL SENSITIVE information, and departmental guidance restricts processing it through uncontrolled third party services. That restriction is not an obstacle to modern AI. It is a specification for where the AI has to live.
Can OFFICIAL SENSITIVE material go to a cloud AI service?
Not defensibly, because sending it to an uncontrolled third party service breaks the handling controls the caveat exists to impose. Under the Government Security Classifications Policy, OFFICIAL SENSITIVE is not a fourth classification tier. It is a handling caveat applied to OFFICIAL information whose loss or compromise would cause heightened harm, and it signals that access must be limited to people with a genuine need to know. A public cloud AI service processes prompts and documents on infrastructure the department does not control, in locations it cannot always identify, operated by staff it has never vetted. Departmental guidance restricts putting sensitive material through uncontrolled third party services, and that restriction covers AI tools just as it covers any other external processor.
What does the Government Security Classifications Policy actually require?
It requires protection proportionate to the harm compromise would cause, not a prohibition on any particular technology. The policy, published on GOV.UK, sets out three classification tiers, OFFICIAL, SECRET and TOP SECRET, and expects organisations to apply controls that reflect the consequences of loss. For OFFICIAL SENSITIVE material that means need to know access, care over where information is stored and processed, and the ability to account for how it has been handled. None of that rules out artificial intelligence. All of it rules out artificial intelligence a department cannot locate, inspect or audit. The questions to ask of an AI tool are the ones asked of any processor: where does the data go, who can see it, and what evidence exists of what was done with it. If those answers cannot be given, the tool has failed the policy before model quality is even discussed.
Why does this matter most for casework, procurement and policy files?
Because the highest value uses of AI in government are document heavy, and the documents involved are precisely the ones that carry the caveat. Casework files contain personal circumstances. Procurement records contain commercially sensitive bids. Policy drafts contain advice to ministers that is not yet, and may never be, public. Arm's length bodies hold inspection reports, investigation files and regulatory correspondence. These are long packages that need reading, cross referencing and summarising, which is the work modern AI does well, and they are also the material most clearly caveated. The result in many organisations is stalemate, because the tools that could relieve the most pressure are the ones policy will not allow near the data. The way out is not weaker policy. It is AI that comes to the data, instead of data going to the AI.
What does sovereign document review look like inside a department?
It looks like an operating system for intelligence installed on the department's own hardware, inside its own accredited estate, with no connection to the outside world. Mickai is a Sovereign Intelligence Operating System, a SIOS, built for exactly this shape of deployment. It runs air gapped, holds a hardware root of trust, and uses a cooperative multi model consensus substrate, so multiple models review the same material and must agree before a finding is presented. Applied to a department's document flows, our review capability works like this.
- Reads a complete casework, procurement or policy package and produces a first pass summary for the official who owns it
- Cross references certificates, annexes and supporting records against each other and flags anything that does not reconcile
- Drafts routine paperwork such as summaries, checklists and response skeletons for a person to review
- Holds anomalies for a person to judge rather than acting on them
- Seals every action to the Open Audit Record before that action runs
Consequential actions wait for a person's clearance, and sensitive operations can be gated by voice biometrics anchored to that hardware held root of trust. The official keeps judgement, disposition and sign off. Nothing leaves the building, because nothing needs to.
How does a sealed audit record serve accountability to Parliament?
It turns the question of what the system did from a reconstruction exercise into a query. Every review, every draft and every disposition inside Mickai is sealed to the Open Audit Record before the action executes. The record is cryptographically signed, tamper evident, designed to withstand post quantum attack, and verifiable offline, so a department can prove years later exactly what was reviewed, what was proposed, what policy permitted and which person cleared it, without trusting the system that produced the record. For organisations answerable to select committees, the National Audit Office and freedom of information requests, that is the difference between evidence and recollection.
“Accountability to Parliament does not accept that the model decided. Every consequential action in a department should be attributable to a person, sealed before it runs, and provable years later without taking anyone's word for it.”
We expect classification aware, on premise AI to become the default posture across the UK public sector. Departments and arm's length bodies that establish sovereign review now, inside their own estates and on their own terms, will set the pattern that later guidance formalises. The choice for security teams is not whether officials will use AI on sensitive documents. It is whether that use happens inside a controlled, sealed, accountable system, or informally at the edges of one.
Frequently asked questions
Is OFFICIAL SENSITIVE a separate security classification?
No. Under the Government Security Classifications Policy the three classifications are OFFICIAL, SECRET and TOP SECRET. OFFICIAL SENSITIVE is a handling caveat applied to OFFICIAL information whose compromise would cause heightened harm, signalling need to know access and additional handling care.
Can civil servants use public generative AI tools on sensitive documents?
Departmental guidance restricts processing sensitive material through uncontrolled third party services, and a public generative AI tool is an uncontrolled third party service. The defensible route is AI that runs inside the department's own estate, where the material never leaves controlled infrastructure.
Does running AI air gapped mean accepting weaker results?
No. Mickai runs its full capability on the customer's own hardware, and its cooperative multi model consensus substrate requires multiple models to agree before a finding is presented, a guard against drift and error.
Who is responsible when AI reviews government casework?
A person, always. Our platform reads, cross references and drafts, but consequential actions wait for a named official's clearance, sensitive operations can be gated by voice biometrics, and every disposition is sealed to the Open Audit Record with the name of the person who cleared it.
How can an audit trail be trusted years after the event?
Because the Open Audit Record is sealed before each action runs, cryptographically signed, tamper evident and verifiable offline, it does not depend on the continued honesty or availability of the system that wrote it. Anyone holding the record can verify it independently.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped. It is organised into 87 studios, with ten production ready at launch and 77 in development, and it seals every consequential action to the Open Audit Record before that action runs. The architecture is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted, owned by Mickai LTD.