MICKAI®ArticlesSovereign AI for insurers: underw…
Article · 2 September 2026

Sovereign AI for insurers: underwriting data and model risk

Keep underwriting models and the sensitive data they touch inside a boundary the insurer owns, controls, and can prove.

Author
Micky Irons
Published
2 September 2026
Follow Micky Irons
LinkedInX
Insurance AISovereign AIUnderwritingModel riskSIOS
Sovereign AI for insurers: underwriting data and model risk

Sovereign artificial intelligence for insurers means running underwriting models, and the sensitive data they depend on, on infrastructure the carrier owns and controls rather than shipping policyholder health and financial records to an outside cloud. It keeps UK GDPR duties, model risk management, and fairness obligations inside a single boundary that can be inspected end to end. Every model input, decision, and override is recorded where the data already lives, so validation and supervision do not rest on a vendor's promise.

  • Underwriting touches the most sensitive data a household holds: health, income, claims history, and lifestyle.
  • Model risk management expects a living inventory of models, plus validation and ongoing monitoring, not a one-off sign-off.
  • Sovereign AI keeps both the data and the models on hardware the insurer owns, able to run offline and be proven.
  • A signed record of every action supports fairness testing, record-keeping, and systems-and-controls review.
  • Mickai runs as a SIOS on the insurer's own estate, writing each action to an Open Audit Record.

Why does underwriting data need a sovereign approach?

Underwriting sits on data most other functions never see. To price and accept risk, an insurer gathers medical history, prescriptions, occupation, financial standing, and prior claims. Under UK GDPR much of this is special category and high-sensitivity data, and moving it into a shared external environment widens the surface that has to be secured, contracted, and explained to a supervisor.

A sovereign approach narrows that surface. When the model and the data sit on the insurer's own hardware, there is no transfer to a third party to justify, no opaque sub-processor chain, and no question about where a policyholder's health record travelled. The insurer keeps the record, and keeps the proof of what happened to it.

What does model risk management ask insurers to prove?

Supervisors increasingly treat models as a source of risk in their own right. The Prudential Regulation Authority sets out its expectations in its supervisory statement on model risk management, SS1/23, which points firms towards a clear model inventory, independent validation, and continuous monitoring across the model lifecycle. Underwriting and pricing models fall squarely inside that scope.

Proving good model risk management is hard when models run in places the risk team cannot fully see. Sovereign AI makes the inventory tractable: models are catalogued where they run, versions are pinned, and every inference is captured. Validation and monitoring then work against a real, complete record rather than sampled logs from an external service.

How does sovereign AI support UK GDPR and fairness duties?

UK GDPR asks for lawful, fair, and transparent processing, data minimisation, and the ability to explain automated decisions that affect people. Fairness in underwriting also means being able to show that a model does not discriminate in ways the firm cannot justify. Both duties need evidence, not assurances.

Keeping processing on owned infrastructure makes that evidence native. The same boundary that holds the data holds the audit trail, so a data protection or conduct question can be answered from one place. Records of inputs, model versions, and outcomes let a team reconstruct why a given applicant was priced or declined, which is what fairness and record-keeping reviews actually require.

How does Mickai run sovereign AI inside an insurer?

Mickai is a SIOS, a Sovereign Intelligence Operating System, that runs on the insurer's own hardware. It is designed to be owned, to run offline, and to be provable, so the carrier is not depending on a remote service to underwrite. Models, data, and workflow stay inside the estate the insurer already governs.

Every action is written to the Open Audit Record, a tamper-evident log signed with FIPS 204 ML-DSA, the post-quantum digital signature standard. Signing establishes who did what and that the record has not been altered after the fact; key establishment standards such as FIPS 203 ML-KEM do not sign, so the signatures come from ML-DSA. Micky Irons, founder of Mickai, has kept that provability at the centre of how the system is built. The wider platform is backed by 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD.

The Mickai closed beta is open on a selective, design-partner basis, and applications can be made at mickai.co.uk/beta. Not everyone is accepted, because the aim is to work closely with insurers who want to run underwriting AI on their own terms.

What should a data or risk team check first?

Start with the data map. List where underwriting data is created, stored, and processed today, and mark every point where it leaves the insurer's control. Those exits are the ones a sovereign design removes or brings back inside the boundary.

Then look at the model inventory against systems-and-controls expectations from the FCA and PRA. If the team cannot name every model in use, its version, and where it runs, that gap is the first thing sovereign AI is built to close.

Frequently asked questions

Will running AI on our own hardware slow underwriting down?

Not by design. Sovereign infrastructure is sized to the insurer's volumes, and keeping data and models together removes the network round trips and contractual checks that outside services add. The trade is more control and cleaner evidence, not slower decisions.

Can I keep our existing pricing models?

Yes. A sovereign approach is about where models run and how they are governed, not about replacing the actuarial work. Existing models can be inventoried, validated, and monitored inside the boundary alongside anything new.

How does an audit record help with a supervisor's questions?

It turns a request into a lookup. Because every input, model version, and decision is recorded and signed, a fairness, data protection, or model risk query can be answered from the record rather than reconstructed from memory or partial logs.

Does offline operation mean no updates?

No. Offline capability means the system can underwrite without a live external dependency. Updates to models and software are still applied, but on the insurer's schedule and inside its own change control.

Is this legal or compliance advice?

No. This article is general information for insurance data, risk, and technology teams, and it is not legal, regulatory, or investment advice. Firms should confirm their own obligations with qualified advisers.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-for-insurers-underwriting-data. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles