MICKAI®ArticlesSovereign AI in Healthcare: Data …
Article · 2 September 2026

Sovereign AI in Healthcare: Data That Never Leaves the Building

Running the model on hardware the care provider owns, offline and provable, so health records never leave the perimeter.

Author
Micky Irons
Published
2 September 2026
Follow Micky Irons
LinkedInX
Healthcare AISovereign AIPatient dataNHSSIOS
Sovereign AI in Healthcare: Data That Never Leaves the Building

Yes. If the model runs on hardware the care provider owns and controls, kept offline behind the organisation's own perimeter, patient data never has to leave the building to be useful. Sovereign artificial intelligence brings the model to the data instead of shipping the data out to a third-party cloud. Every prompt, every record, and every answer stays inside walls the provider already secures, and every action can be written to a record the provider can inspect.

  • Sovereign AI runs the model on hardware the provider owns, offline, so health records never travel to an external cloud.
  • Patient confidentiality and the common law duty of confidence are easier to honour when data stays inside the organisation's own perimeter.
  • UK GDPR treats health information as special category data, raising the bar for how and where it is processed and stored.
  • Data residency and information governance expectations in health and care point towards processing that can be located, owned, and proven.
  • Mickai runs as a SIOS on the provider's own hardware and writes every action to the Open Audit Record.

Why does patient data leaving the building matter?

Health records are among the most sensitive information a person ever hands over. In the United Kingdom they sit under the common law duty of confidence, and under UK GDPR they are special category data, which raises the bar for how they are processed, where they are stored, and who can reach them. The moment a record is copied to an external system, the care provider is trusting someone else's infrastructure, someone else's staff, and someone else's location for data that patients expect to stay close.

Information governance expectations in health and care lean heavily on being able to say where data lives and to show, not merely assert, that it was handled properly. Data that never leaves the building is far easier to account for than data scattered across services a provider does not own.

What does sovereign AI mean in a hospital or clinic?

Sovereign AI means the intelligence runs on infrastructure the organisation owns and controls, on its own premises, able to work with the network unplugged. The model, the records it reads, and the answers it produces all sit inside one perimeter. Nothing is streamed to an outside vendor to be processed and nothing depends on a connection to a remote service that the provider cannot see into.

That is a different posture from the common pattern of calling out to a hosted model over the internet. With sovereign AI the question of where the patient data is right now has a single, physical, checkable answer: here, on our hardware, in our building.

How does keeping the model onsite help with information governance?

Data residency stops being a paperwork exercise and becomes a fact of the floor plan. When processing happens on owned hardware, a provider can point to the rack, confirm the data never crossed into an external cloud, and produce a trail of what happened. Ownership, location, and evidence line up instead of pulling in different directions.

This also narrows the number of parties who have to be trusted. Fewer third parties in the chain means fewer contracts to police, fewer sub-processors to map, and fewer places a record could sit without the provider's full knowledge.

What is the risk of sending patient data to a third-party cloud model?

Once patient data is sent to an external model, control passes to whoever runs it. The provider is relying on that vendor's residency, retention, and access practices, and often cannot prove where a record was processed or whether a copy was retained to improve a service. For special category health data under UK GDPR, and for information held under a duty of confidence, that loss of provable control is the heart of the risk.

None of this is medical or legal advice, and every organisation should take its own governance guidance. The general point stands: data that leaves the perimeter is harder to confine, harder to account for, and harder to bring back.

How does Mickai keep patient data inside the perimeter?

Mickai is a SIOS, a Sovereign Intelligence Operating System that runs on the provider's own hardware, owned, offline, and provable. The model sits next to the records rather than in a distant data centre, so a clinic or trust can put AI to work on real information without that information leaving the building. Because the system is offline by design, there is no outbound path for patient data to slip through.

Every action the system takes is written to the Open Audit Record, a tamper-evident log the provider can inspect, so a request to show what happened has an answer rather than a shrug. Mickai holds 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, covering the sovereign and audit machinery underneath. Micky Irons, founder of Mickai, has kept a single principle at the centre of the work: the data belongs to the organisation that holds it, and the intelligence should come to the data.

The Mickai closed beta is open, and applications are welcome at mickai.co.uk/beta. It is a selective design-partner programme, so not every applicant is accepted, and it is built for organisations that want AI they can own and prove rather than rent and hope.

Frequently asked questions

Does sovereign AI really keep patient data inside the building?

Yes, when the model runs on hardware the provider owns and controls, kept offline behind its own perimeter. The records are read locally and the answers are produced locally, so nothing has to be sent to an outside service for the system to be useful.

Is my patient data used to train someone else's model?

With a sovereign, offline deployment there is no outbound path for records to reach an external vendor, so there is nothing to be quietly folded into another party's training. The data stays on the provider's own hardware, inside its own perimeter.

How does this fit patient confidentiality and UK GDPR?

Keeping health information on owned, offline infrastructure makes the common law duty of confidence and UK GDPR special category obligations easier to honour, because location, ownership, and access all sit inside the organisation. This is general information, not medical or legal advice, and each provider should follow its own governance.

Can we prove what the system did with a record?

Yes. Every action is written to the Open Audit Record, a tamper-evident log the provider can inspect, so an information governance question can be answered with evidence rather than assurances.

How do we take part in the Mickai closed beta?

Apply at mickai.co.uk/beta. The programme is a selective design-partner arrangement, not everyone is accepted, and it runs the Mickai SIOS on the provider's own hardware, owned, offline, and provable, with every action written to the Open Audit Record.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-in-healthcare-patient-data. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles