MICKAI®ArticlesOwner-operated AI: who controls y…
Article · 2 September 2026

Owner-operated AI: who controls your model and data

In owner-operated AI, the buyer holds the hardware, the keys, and the audit trail, not a distant cloud tenant.

Author
Micky Irons
Published
2 September 2026
Follow Micky Irons
LinkedInX
Owner-operated AIData ownershipSovereign AIModel custodySIOS
Owner-operated AI: who controls your model and data

Owner-operated AI means the organisation that uses the model also controls it: the owner holds the hardware the model runs on, the cryptographic keys that unlock it, and the audit trail that records every action. In a cloud AI deal, all three sit with the vendor, so control is rented, not owned. Mickai is built as a Sovereign Intelligence Operating System (a SIOS) where custody of compute, keys, and logs stays with the buyer. Control of a model is not who trained it, it is who can switch it off, read its logs, and prove what it did.

  • Owner-operated means custody of three things: the hardware, the keys, and the audit trail.
  • In a cloud deal, the vendor holds all three, so your control is contractual, not physical.
  • The audit trail is the asset that proves what a model did, and whoever holds it holds the evidence.
  • A SIOS keeps compute, keys, and logs on the owner's premises, under the owner's signature.
  • Mickai backs this posture with 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD.

Who holds the keys in a cloud AI deal?

In a standard cloud AI arrangement, the provider holds the keys. Your data is encrypted, but the provider manages the encryption, the model weights, and the servers, so the provider can technically read, move, or retrain on what you send. You receive a contract and a dashboard, not custody. Owner-operated AI reverses this: the keys are generated and held by the owner, and no third party can decrypt or relocate the model without the owner's action.

This matters because keys are the real boundary of ownership. Encryption without custody of the keys is a lock whose master copy sits in someone else's building. Owner-operated AI puts the only working copy in the owner's hands.

What does custody of the audit trail change?

The audit trail is the record of every prompt, decision, and output a model produces. When the vendor holds that log, you can only see what the vendor chooses to show, and you cannot prove the record was not altered. When the owner holds it, the log becomes tamper-evident evidence the owner can present to a regulator, an auditor, or a court. The cloud era of AI was a leasehold on the audit log, the sovereign era is a freehold on the chain.

This is why custody of logs is a governance question, not a technical detail. Boards and regulators increasingly ask not what a model can do, but who can prove what it did. Ownership of the audit trail answers that question in the owner's favour.

Does owner-operated mean giving up model quality?

No. Owner-operated AI is about custody, not capability. A sovereign deployment runs capable models on the owner's own hardware, so the same reasoning and drafting power is available without sending data off site. The difference is location and control: the intelligence works inside your walls, under your keys, on your logs.

The trade-off people imagine, power in the cloud versus safety at home, is outdated. Capable models now run inside owned hardware, so an organisation keeps both the intelligence and the custody. Quality and control are no longer opposing choices.

How do you know a vendor's private cloud is actually private?

You test who can switch it off. If the vendor can revoke access, push an update, or read the logs without your signature, the deployment is private in name only. True ownership is provable when the hardware sits on your premises, the keys live in your custody, and every action writes to an audit trail only you can read. A promise in a contract is not the same as a key in your hand.

In practice, three questions settle it. Can you revoke the vendor's access without asking them? Can you read the raw logs yourself? Can you keep the model running if the vendor disappears? If any answer is no, the deployment is rented.

Why does owner-operated matter for regulated sectors?

Regulated organisations in defence, finance, healthcare, and government must prove where data went and who touched it. A rented model cannot give that proof, because the evidence lives with the vendor. Owner-operated AI keeps the data, the model, and the record inside the organisation's control boundary, which is why we built Mickai as a SIOS rather than a hosted service. Micky Irons, founder of Mickai, set this custody-first principle as the starting point, not an add-on.

It also changes the negotiation. When the owner holds the hardware, the keys, and the logs, the vendor relationship becomes a licence to use capability the owner already controls, rather than a dependency on a service that can be changed or withdrawn.

Frequently asked questions

Can I run owner-operated AI without a data-centre team?

Yes. A SIOS is designed to install and operate on hardware an organisation already runs, without a specialist data-centre team. Mickai packages the model, the key management, and the audit trail into one operating system, so the owner gets custody without becoming an infrastructure company. Your staff use it, and they do not have to maintain a cloud.

If the model runs on my hardware, who can see my data?

Only the owner. In an owner-operated deployment, data stays on the owner's machines and is decrypted only with the owner's keys, so no vendor, cloud tenant, or third party can read it. Every access is written to the owner's audit trail, so even internal activity is recorded and reviewable.

Does owning the model mean I own the underlying weights?

You own the deployment, the keys, and the record of everything it does. The owner controls where the model runs, when it runs, and who can use it, and can switch it off at any time. That control, not a claim over any particular model's origins, is what owner-operated means in practice.

How is this different from a private cloud subscription?

A private cloud subscription still leaves the keys, the servers, and the logs with the provider, so you are renting isolation, not owning it. Owner-operated AI moves all three onto the owner's side of the line. The test is simple: if you cannot switch it off yourself, you do not own it.

What proof do I get that a model did what it claims?

The audit trail. In a SIOS, every action a model takes is recorded to a tamper-evident log that only the owner holds, so the owner can prove after the fact exactly what happened. This evidence stands on the owner's terms, not filtered through a vendor's dashboard.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/owner-operated-ai-who-controls-your-model. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles