MICKAI®ArticlesCan We Run Online Safety Act Mode…
Article · 18 August 2026

Can We Run Online Safety Act Moderation Without Sending Content to Cloud AI?

Online Safety Act duties can be met by on-device classifiers that keep user content and evidence inside your own jurisdiction.

Author
Micky Irons
Published
18 August 2026
Follow Micky Irons
LinkedInX
online safety actcontent moderationon-premise aidata sovereigntysios
Can We Run Online Safety Act Moderation Without Sending Content to Cloud AI?

Yes. Online Safety Act content moderation can run entirely on operator-owned hardware, with no user content, no flagged material and no evidence ever sent to a cloud AI service. The classifiers that detect illegal harms and child sexual abuse material run as local models inside your own perimeter, so the content being judged never leaves your jurisdiction. Cloud analysis is a design choice, not a legal requirement, because Ofcom's duties are about outcomes and records, not about where the inference happens.

This matters because the common moderation stack in 2026 quietly routes anything a first-pass filter flags to a large language model hosted overseas. That is the exact moment the risk appears. The material that most needs protection, illegal content and child-safety cases, becomes the material most exposed to onward transfer, to foreign legal reach, and to a chain of custody you cannot fully attest. Keeping the whole pipeline local removes that exposure without weakening detection.

How does on-premise moderation actually work?

Mickai is a Sovereign Intelligence Operating System, a SIOS, and it runs offline on operator-owned hardware. Content arrives, is classified by sovereign models held locally, and a decision is written to an audit ledger, all inside a single sealed environment. Three design features carry the weight:

  • A zero-egress inbound perimeter. Content and users can reach the system, but the system opens no outbound path to any third-party inference service. There is no API call for a moderator to leak into.
  • Cross-model consensus. Several local models score the same item independently, and their agreement or disagreement is recorded, which raises precision on hard cases without a cloud escalation.
  • A cryptographically sealed record. Every action is bound to a hardware-attested identity and written to a post-quantum signed audit ledger, so each decision carries tamper-evident provenance.

The architecture behind this, the sealed perimeter and the attested ledger, is described in 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD and patent pending.

Which Online Safety Act duties make this necessary?

The Online Safety Act 2023 places illegal-harms duties and child-safety duties on in-scope services. Providers must carry out illegal-content risk assessments, take proportionate measures against priority illegal content, and operate systems to detect and remove child sexual abuse material. None of these duties specify a cloud provider, and none prohibit local processing. What they demand is a demonstrable system and a record that it worked. On-premise moderation can satisfy the duty and, by keeping evidence in jurisdiction, keeps the handling of the most sensitive material defensible.

What can an auditor or Ofcom actually check?

An auditor does not need to trust a claim of no egress. They can verify it. The audit ledger is offline-verifiable: a reviewer can confirm each decision's signature without contacting any external server. Signatures use the post-quantum standards, with FIPS 204 (ML-DSA) as the primary signature scheme and FIPS 205 (SLH-DSA) available alongside it, so the seal on the ledger stays checkable even against future quantum attack. Because identity is hardware-attested, the record shows which attested node made each decision. The checkable claims are concrete:

  • No outbound connection to any external inference endpoint.
  • A continuous, tamper-evident decision log.
  • Cryptographic proof that no record was altered after the fact.

The safest place to judge illegal and child-safety content is inside the operator's own perimeter, where the material never becomes someone else's data.

Does keeping it local weaken detection accuracy?

No. Detection quality comes from the models and the review workflow, not from the postcode of the server. Local sovereign models handle first-pass classification, and cross-model consensus resolves the ambiguous middle where a single classifier would previously escalate to a cloud model. Human moderators stay in the loop for edge cases, viewing content inside the same sealed environment. The cloud call was always an operational convenience, not an accuracy floor.

How does this sit with GDPR, the US CLOUD Act and the EU AI Act?

Local processing is the cleaner answer to several regimes at once. Under GDPR, content that never leaves the jurisdiction avoids the international-transfer analysis entirely. The US CLOUD Act can compel US-based providers to hand over data they hold, so content routed through an overseas cloud AI service is reachable by a foreign legal process in a way that content held on your own hardware is not. For firms already inside DORA, in force since January 2025, or NIS2, which covers essential and important entities, a system with no third-party inference dependency shrinks the supplier-risk surface those regimes scrutinise. On the EU AI Act, the high-risk Annex III obligations once due on 2 August 2026 were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk obligations moving to 2 August 2028 and the Article 50 transparency duties largely unchanged. We read that as a build window, not a reprieve. ISO/IEC 42001 gives a management-system framework to evidence the controls now.

What should a buyer ask a moderation vendor?

Three questions separate a genuinely local system from a relabelled cloud one:

  • When content is flagged, does any part of it, including text, images or hashes computed for matching, leave our infrastructure? Ask for the outbound network policy in writing.
  • Where is the escalation model hosted, and can it run with no internet access at all?
  • Can we verify the audit trail offline, and what signs it?

A vendor whose accuracy depends on a hosted cloud AI service will struggle with the second and third. A sovereign design can answer all three.

Frequently asked questions

Does the Online Safety Act require using cloud AI to moderate content?

No. The Act sets duties to assess and mitigate illegal harms and to protect children, and to keep records that show the system works. It does not mandate any particular technology, vendor or location. On-device classifiers meet the duties as well as cloud services do, and they keep the most sensitive material in your jurisdiction.

Is on-device content moderation as accurate as cloud AI moderation?

Yes. Detection accuracy is a property of the models and the review process, not of where the server sits. Local sovereign models handle first-pass classification, and cross-model consensus resolves ambiguous cases that a single classifier would otherwise send to a cloud model. Human review of edge cases happens inside the same sealed environment.

Can Ofcom or an auditor verify that no content left our systems?

Yes. A well-designed system produces an offline-verifiable audit ledger, so a reviewer can confirm each decision's signature without contacting any external server. The signatures use post-quantum standards, with FIPS 204 as the primary signature scheme. An auditor can also inspect the outbound network policy to confirm there is no path to a third-party inference service.

What is the risk of routing flagged content through an overseas cloud AI service?

Routing flagged content to an overseas cloud AI service exposes the most sensitive material to onward transfer and to foreign legal reach under the US CLOUD Act, which can compel US providers to disclose data they hold. It also complicates GDPR international-transfer analysis and lengthens your chain of custody. Keeping classification local removes all three exposures at once.

When do the EU AI Act high-risk rules apply now?

The EU AI Act's high-risk Annex III obligations, once due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027. Embedded Annex I high-risk obligations move to 2 August 2028, while the Article 50 transparency duties are largely unchanged. We treat the extra time as a window to build compliant systems, not as a reason to delay.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/online-safety-act-moderation-on-premise. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.