The Pentagon Takes AI Behind the Air Gap. Trust Must Be Built In
Air-gapped classified deployments prove that trustworthy AI must carry its own accountability, because behind the air gap there is no vendor cloud to supervise it.

Commercial AI can be trusted on classified networks only when its accountability is engineered into the system itself, because an air-gapped enclave cannot lean on a vendor's cloud for supervision, telemetry or support. That is the standard the US Department of Defense has now set for the entire defence market. In early May 2026 the Department cleared eight technology firms to deploy their AI models on its classified networks under its GenAI.mil programme, a move first reported by Breaking Defense. Classified networks are cut off from the public internet, which is why we read the clearances as AI going behind the air gap.
The decision matters far beyond Washington. It confirms that the most security-conscious buyer in the world now judges modern AI useful enough to bring inside its most sensitive enclaves, and it fixes the terms on which that happens. The models travel to the data. The data never travels to the models. We built Mickai, our Sovereign Intelligence Operating System, around exactly that principle, so we took the announcement as validation of a design philosophy. If AI is going to work where secrets live, trust has to be resident in the machine, not rented from a remote provider.
What did the US Department of Defense actually clear in May 2026?
It cleared eight technology firms to run their AI models on its classified networks under the GenAI.mil programme, with approval covering Impact Level 6, which handles secret data, and Impact Level 7, a semi-official term for the most highly classified systems. Breaking Defense reported the clearances in early May 2026. Networks at these levels have no connection to the public internet, so in practice everything the AI needs, from model weights to updates to monitoring, has to exist and be managed inside the classified boundary. We will not speculate on the operational detail, which is rightly not public, but the architecture itself tells you what the Department demanded: capability without connectivity, and intelligence without exfiltration risk.
Why does an air gap change how AI has to be governed?
Because an air gap removes every external safety net at the same moment it removes every external threat. In a cloud deployment the vendor watches for abuse, ships silent patches, aggregates telemetry and can intervene when something misbehaves. Behind an air gap none of that exists. The organisation that owns the enclave owns the whole burden of oversight, and any governance that depended on the vendor's visibility simply disappears. That is not a reason to avoid air-gapped AI. It is a reason to choose systems that were designed for disconnection from the start, rather than cloud services with the network cable pulled out.
“When a system cannot phone home, accountability has to be built into the box itself. Oversight has to survive even when the connection to the vendor does not.”
What should an accountable AI system prove inside the enclave?
It should prove what it did, who authorised it and that the record of both is intact, all without reference to any outside service. We designed Mickai to meet that test with five resident controls.
- A complete, signed history. Every action taken on the operating system is written to the Open Audit Record and cryptographically signed with post-quantum algorithms, so the log is tamper-evident and cannot be quietly rewritten, even by an adversary harvesting encrypted data today to decrypt years from now.
- Offline verifiability. The Open Audit Record can be verified entirely offline, which means an inspector inside a classified enclave can prove the integrity of the history without a single packet leaving the room.
- Agreement before action. Our cooperative multi-model consensus substrate requires specialist sovereign models to agree before any sensitive action runs, so no single model output can trigger a consequential step on its own.
- A human bound to the decision. Sensitive actions are gated behind voice-biometric confirmation, tying each authorisation to a specific person rather than to a password that can be shared or stolen.
- A root of trust in hardware. The chain of integrity anchors to a hardware-held root of trust on the customer's own machines, so the foundation of the system's identity never depends on a remote certificate authority.
Together these controls answer the question an air gap otherwise leaves open. The enclave keeps threats out, and the operating system keeps an incorruptible account of what happened within.
How is Mickai built for classified and disconnected environments?
Mickai runs entirely on the customer's own hardware, on-premise and fully offline, with no dependency on any external service in normal operation. The intelligence comes from our own sovereign models, resident on the same machines, so there is no third party to route a prompt through and no telemetry to leak. The work itself happens in studios, purpose-built environments for tasks such as analysis, drafting and operations. There are 87 studios on one operating system, and we launch with ten that are production-ready while the remaining 77 are in development. Beneath all of it sits a filed intellectual property estate, 104 filed UK patent applications across 2,340 claims held by Mickai LTD, which we treat as a moat around the engineering rather than the story itself.
What does the Pentagon's move mean for UK and allied organisations?
It means the hardest question about AI in sensitive environments has been answered in principle, and the remaining questions are about implementation. If AI models can operate inside America's most highly classified enclaves, then no UK department, defence contractor, critical infrastructure operator or intelligence-adjacent organisation needs to accept the claim that serious AI requires a connection to someone else's cloud. We are a British company and we make no claim on the Pentagon's programme. What we do claim is that the standard it sets, models inside the boundary, data never outside it, accountability resident in the system, is one any organisation can now reasonably demand of its suppliers. The buyers who move first will be the ones who insisted on sovereignty before it became the default.
Frequently asked questions
What is the GenAI.mil programme?
GenAI.mil is the US Department of Defense's generative AI programme, which began as a secure but unclassified service. In early May 2026, as reported by Breaking Defense, the Department cleared eight technology firms under the programme to deploy their AI models on its classified networks at Impact Levels 6 and 7, the tiers covering its secret and most highly classified systems.
What does air-gapped AI actually mean?
Air-gapped AI runs with no connection to the public internet or to the vendor, so models, updates and oversight all live inside the protected network boundary. Nothing about the system's operation depends on, or leaks to, the outside world, which removes remote exfiltration as a route out of the enclave.
How can an AI audit trail be verified without an internet connection?
By signing every entry cryptographically at the moment it is written and designing the verification to run locally. Mickai's Open Audit Record is post-quantum signed and tamper-evident, and its integrity can be checked entirely offline, so an auditor inside a classified enclave can prove the history is genuine without touching any external service.
Does Mickai need any cloud connection to operate?
No. Mickai runs fully offline on the customer's own hardware, with sovereign models resident on the same machines, a hardware-held root of trust and voice-biometric gating on sensitive actions, so normal operation requires no external connectivity at all.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on-premise and air-gapped, with every action cryptographically signed to the tamper-evident Open Audit Record. It offers 87 studios on one operating system, with ten production-ready at launch and 77 in development, and it is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.