MICKAI®ArticlesSovereign AI for defence and secu…
Article · 23 July 2026

Sovereign AI for defence and security suppliers

An air-gapped operating system for suppliers handling sensitive or export-controlled work. See the studios you run and what you stop renting.

Author
Micky Irons
Published
23 July 2026
Follow Micky Irons
LinkedInX
defencesecuritysovereign-osair-gappedexport-control
Sovereign AI for defence and security suppliers

Sovereign AI for defence and security suppliers is an operating system that runs entirely on hardware the supplier owns, air-gapped by default, so sensitive and export-controlled work never leaves the building. It is not a set of cloud subscriptions and not a model you wire into someone else's service. It is the whole software estate, email, documents, meetings, the CRM and one assistant across all of it, running as studios on the MICKAI sovereign operating system on your own kit. Nothing crosses your boundary to make the product work.

Why suppliers handling sensitive work need a different default

Most business software assumes a connection to a vendor cloud. That is fine for a lot of firms and awkward for the ones that hold controlled information. If you build to a defence contract, handle export-controlled technical data, or sit inside a supply chain that a prime or an authority audits, "our tools run in a vendor cloud in a region we do not control" is a difficult sentence to say.

Private cloud arrangements get you part of the way. The vendor still owns the platform, the region and the update cycle, and the data still leaves your walls to be useful. We start from the same place everyone should, a deployment where an outside party cannot see your data, and we go further. The operating system is air-gapped by default. The studios function with no connection to the outside. Your controlled information stays on hardware you own, in a building you control.

We are careful about the claim. This does not make you accredited and it does not certify anything. It gives you architectural control and a full record of who did what, which is what most hard questions from a client or an authority are really asking about.

What runs on the operating system

You get working studios, not a toolkit to assemble. The ones a sensitive supplier reaches for first:

  • Our email system, so correspondence about a controlled programme sits on your hardware, not a mail vendor's cloud.
  • Our documents and file collaboration studio, so technical data packs, drawings and specifications are edited and shared inside your boundary.
  • Our meetings and collaboration platform, so programme reviews and their notes stay local rather than passing through an outside conferencing service.
  • Our CRM, so the record of who you supply and what you have quoted lives on your kit.
  • Our assistant, one assistant across every studio, working from your data on your hardware.

These are studios on one operating system sharing a single data store, not separate apps stitched together with connectors. That matters for sensitive work: every connector between clouds is another vendor and another place controlled data is copied to. Here there is no sync job and no integration to license. The mailbox, the document, the meeting and the record already know about each other because they sit on one foundation.

Air-gapped by default, and what that buys you

Air-gapped by default means the system is designed to run with no path to the outside, not bolted shut after the fact. For a supplier that is the difference between a claim and a property you can show.

When someone opens a controlled document, it is read from local hardware. When they log a call or edit a drawing, it is written to local hardware. If the site's connection drops, the work carries on, because getting to your own material was never conditional on reaching a vendor. For firms in secure rooms or on isolated networks, this is the ordinary way the platform behaves.

There is no hyperscaler underneath and no foreign cloud in the path. The value we offer is beyond private deployment: the whole software stack on your hardware, not a model or a service you rent from a provider whose region and roadmap you do not set.

The action-level audit record

Sensitive supply work turns on a simple question: who touched this, and when. Our operating system writes every action to the Open Audit Record, held on your own hardware. Not just logins, the actions. A view, an edit, an export, a share, each is logged for you to review.

For export-controlled information that record is the practical heart of control. If a prime, a client or an authority asks you to show who accessed a controlled data pack, you have the trail on kit you own, not a report you request from a vendor. It answers the insider question too: if a member of staff quietly exported a file, the export is in the record. That record gives you evidence and control. It does not confer certification, and we do not claim any.

The intelligence layer, kept inside the wall

The assistant works across every studio. Ask it what is happening on a programme and it answers from the correspondence, the documents and the meeting notes together, because they are all in one place you own. Ask it to draft a response to a client, pull the relevant technical thread, or find where a controlled document has moved, and it reads across the studios to do it.

The point worth stating for a sensitive supplier: this reasoning happens locally, against your data, on your hardware. Nothing about your programme is sent to an outside service for the assistant to be useful. It is one assistant across all the studios, not a chatbot bolted onto a single app.

What you stop renting

We do not publish MICKAI pricing. What we can do is show the recurring bill the alternative prints, so you can model your own number honestly.

The mainstream stack is sold per user per month, billed every year, without end. A supplier of any size is usually paying for a cloud email and productivity suite, a separate meetings tool, a chat platform, a CRM, and the connectors to make them talk. Each publishes a per seat list price on its own website. The editions and figures move over time, so use the current list price for the tier you would actually buy, and use the method rather than trusting any single number.

Take your seat count. Multiply by the vendor's published price per user per month. Multiply by twelve. That is one year for that one tool. A worked example on a stated assumption: a 60 person firm, on a published productivity suite list price of 20 pounds per user per month, is 60 times 20 times 12, which is 14,400 pounds a year for that suite alone. Add a CRM at a published 80 pounds per user per month for the 20 seats that need it, and that is 20 times 80 times 12, which is 19,200 pounds a year on top. Those are illustrative figures on stated assumptions, not quotes. Put in your real seat counts and the real published prices, add the meetings tool, the chat platform and the connectors, and you have your own recurring total, repeating every year.

We do not print our price here. Hold your rented total against what we offer: the same functions as studios on one operating system, running on hardware your company owns, inside your own wall.

Built for the regulated small and mid-sized supplier

The heavyweight vendors are built for very large buyers. The regulated small and mid-sized supplier, the machine shop on a defence framework, the specialist integrator, the security firm holding controlled data, often gets the same multi-tenant cloud with none of the leverage and all the exposure. That is the firm we build for.

Our operating system gives that supplier a straight answer to the questions that decide contracts. Where does the controlled data sit? Here, on hardware we own. Who can see it? These named people, and every access is in the record. Does it depend on a foreign cloud? No, it runs air-gapped. What we hand you is architectural control and an action-level audit trail on kit you own, not a certificate.

The wider platform

The studios a sensitive supplier starts with are part of a larger estate. The operating system spans 87 studios built on the same foundation, and clients onboard onto a focused initial set rather than switching everything at once. The email, documents, meetings, CRM and assistant are the same system, sharing your data, running on your hardware, behind your air gap. The reason to buy is simple: sensitive work stays inside your building, on hardware you own, with one assistant across all of it and a record of every action.

Frequently asked questions

Is this certified or accredited for classified work? No. We hold no SOC 2, ISO or Cyber Essentials certification and we make no accreditation claim. What we give you is architectural control: an air-gapped operating system on hardware you own, with every action logged. Certification and accreditation are decisions for you and your authority, on your own kit.

Does anything leave our building? No. The operating system is air-gapped by default. The studios run on hardware your firm owns, reading and writing your own data store, with no connection to the outside required to work.

How does it help with export-controlled information? It keeps the information in one place you control and logs who touched it at the action level in the Open Audit Record. That gives you a straight answer on where controlled data sits and who has viewed, edited or exported it. Your compliance duty stays yours; the platform makes it auditable.

Do we depend on a US or foreign cloud? No. There is no hyperscaler underneath. The stack is the whole software estate running on your hardware, not a model or service you rent from a vendor in a region you do not set.

Which studios would a supplier start with? Usually the ones handling sensitive material first: email, documents and file collaboration, meetings, the CRM and the assistant. Clients onboard onto a focused initial set rather than all of them at once.

Is the intelligence layer sending our prompts somewhere? No. The assistant runs locally against your data on your hardware. Nothing is sent to an outside service to reason over your information.

Frequently asked questions

Is this certified or accredited for classified work?

No. We hold no SOC 2, ISO or Cyber Essentials certification and we make no accreditation claim. What we give you is architectural control: an air-gapped operating system on hardware you own, with every action logged. Certification and accreditation are decisions for you and your authority, on your own kit.

Does anything leave our building?

No. The operating system is air-gapped by default. The studios run on hardware your firm owns, reading and writing your own data store, with no connection to the outside required to work.

How does it help with export-controlled information?

It keeps the information in one place you control and logs who touched it at the action level in the Open Audit Record. That gives you a straight answer on where controlled data sits and who has viewed, edited or exported it. Your compliance duty stays yours; the platform makes it auditable.

Do we depend on a US or foreign cloud?

No. There is no hyperscaler underneath. The stack is the whole software estate running on your hardware, not a model or service you rent from a vendor in a region you do not control.

Which studios would a supplier start with?

Usually the ones handling sensitive material first: email, documents and file collaboration, meetings, the CRM and the assistant. Clients onboard onto a focused initial set of studios rather than all of them at once.

Is the intelligence layer sending our prompts somewhere?

No. The assistant runs locally against your data on your hardware. Nothing is sent to an outside service for the studios to reason over your information.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-for-defence-and-security-suppliers. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles