MICKAI®ArticlesPoros: The Door That Opens Sovere…
Team
Article · 25 August 2026

Poros: The Door That Opens Sovereign AI

Mickai's inference engine runs a large, capable model on your own hardware, fully offline, and gives a signed record of what ran.

Author
By Micky Irons
Published
25 August 2026
Follow Micky Irons
DEV CommunityLinkedIn
PorosSIOSSovereign AIOn-Premise AIInference

For years the deal with capable AI has been simple and, for regulated organisations, quietly unacceptable. You want the intelligence, so you send your data out. Prompts, documents, customer records, case files: they leave your walls, cross a network, and land on someone else's machine. You get the answer. You also get a dependency, a data-residency problem, and a question you can't fully answer when the auditor asks it: where did that information actually go?

Poros is Mickai's answer to that question. It's the inference engine, built and tested ahead of integration into SIOS, the British sovereign-AI operating system; the installed product does not run on it yet. It lets an organisation run a large, capable AI model locally, on its own machine, fully offline. Nothing leaves. Nothing needs to.

The premise: keep the model where the data already lives

Most people assume serious AI means a datacentre. Racks of accelerators, a cloud contract, and a standing pipe to the outside world. That assumption is the thing Poros is built to break.

Poros runs a large model on a single workstation-class GPU. Modest hardware, the kind an organisation can put under a desk or in a locked cabinet in its own building. No datacentre. No cloud tenancy. No shared infrastructure you don't control. The model comes to where your data already lives, instead of your data going out to where the model lives.

For a bank, a hospital trust, or a government team, that inversion matters more than any benchmark. It means sensitive material never has to become someone else's traffic to get useful work done.

One engine, matched to your hardware

Hardware in the real world is never tidy. Some teams have the newest cards. Plenty are running kit that's a few years old, and some have no serious GPU at all. A tool that only works on ideal hardware isn't a tool a real organisation can deploy at scale.

Poros reads a machine's GPU, memory and CUDA capability and decides which models it can run; only NVIDIA Turing has been validated so far. That's the whole point of the seam Mickai built into the engine: it meets your estate where it is, rather than dictating a shopping list before you can start. The person deploying it doesn't need to think about any of this. They run the installer. Poros works out the rest.

Nothing phones home, and that's been tested

Offline has to mean offline, or it means nothing.

Poros is a loopback-only component. It connects only to a loopback address, with no name lookup. It talks to the machine it's running on and to nothing else. There's no telemetry channel, no quiet check-in, no update ping carrying who-knows-what back out through your firewall. The engine simply has no way to reach the outside world.

That's a strong claim, so it shouldn't rest on our word alone. An independent adversarial review went at the engine specifically to break out of that boundary, and the egress guard held. For a security leader, that's the difference between a marketing promise and something you can put in front of a board: not "we designed it to stay local", but "someone was paid to make it leak, and it didn't."

Prove what ran: the audit ledger

Running locally is necessary. It isn't sufficient. In a regulated setting you also have to prove what happened, after the fact, to someone who wasn't in the room and doesn't take your word for it.

Every Poros session gives one signed record in the customer's own audit chain for every request it routes. Mickai calls it the OAR.

Think about what that gives you. When compliance asks whether an unapproved model touched a piece of work, you have a signed record, not a shrug. When something's queried months later, the provenance travels with the evidence. The ledger is tamper-evident: if anyone alters the record, that shows. And it's signed against the day cryptography gets harder, so the proof you write today still stands up tomorrow.

Local keeps your data in. The ledger lets you demonstrate control to anyone entitled to ask. Regulated sectors need both, and most tools give you neither.

The foundation, not the finish line

Here's where it's worth being precise, because precision is the whole promise.

Poros is built and tested ahead of integration; the installed product does not run on it yet. What it proves today is the hard part: a large model, running locally, offline, with one signed record in the customer's own audit chain for every request.

What's real today is the engine. It's built. It's been independently reviewed. It runs a large model on a workstation GPU right now, sealed to the audit ledger, offline. That's not a roadmap slide. That's the working core.

The rest is honest about its stage. The full desktop assistant and the agentic "studios", the layers where SIOS becomes an everyday working environment across a whole organisation, are later phases of the build. They're coming. They aren't finished, and we're not going to pretend they are. The reason to take the vision seriously is that the hardest part, the part everyone else hand-waves, is the part that already works. If the engine can't run locally, refuse to leak, and prove itself, nothing built on top of it is worth trusting. Poros does all three, now.

Why the door matters

Sovereignty in AI has become a word people say and rarely deliver. Too often it means the same borrowed intelligence with a friendlier data-processing agreement stapled to the front.

Poros means something narrower and far more useful: the capable model runs on your hardware, in your building, under your control, and it can prove it did. That's the door. Once it's open, a regulated organisation can finally use serious AI on its most sensitive work without giving up custody of that work to do so.

You don't have to choose between capability and control any more. That was always a false trade, and Poros is how Mickai retires it.

Keep the intelligence. Keep the control.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. Delivered through our email service provider. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/poros-sovereign-inference-engine. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles