MICKAI®ArticlesSovereign On-Premise AI Versus En…
Article · 18 August 2026

Sovereign On-Premise AI Versus Enterprise Search Assistants: Where Does Your Data Actually End Up?

With sovereign on-premise AI your data never leaves your hardware, while enterprise search assistants copy every indexed document into a vendor cloud.

Author
Micky Irons
Published
18 August 2026
Follow Micky Irons
LinkedInX
sovereign aienterprise searchdata residencyon-premisezero egress
Sovereign On-Premise AI Versus Enterprise Search Assistants: Where Does Your Data Actually End Up?

Sovereign on-premise AI keeps your data on hardware you own and control, with no outbound connection to any vendor cloud. Enterprise search assistants take the opposite path: they index every connected document, email and ticket into the vendor's cloud so their models can retrieve it. That single design choice is where the data ends up, because retrieval quality depends on a searchable copy living outside your perimeter. If the index sits in someone else's data centre, so does your data, and so does the jurisdiction that governs it.

This matters in 2026 because the dominant sales narrative, that AI-powered enterprise search boosts productivity, quietly reintroduces the risk that regulated firms spent years removing. A bank, a hospital or a defence supplier cannot use public services like ChatGPT, Claude or Gemini on sensitive material, yet a search assistant that mirrors the entire document estate into a managed cloud creates the same egress and foreign-jurisdiction exposure under a friendlier label. The productivity gain is real. The data-residency cost is often unstated.

How does sovereign on-premise AI actually work?

Mickai is a Sovereign Intelligence Operating System, a SIOS. It runs offline on operator-owned hardware and its models process documents in place. There is no step where your corpus is copied to an external index. The inbound perimeter is zero-egress by design: the system accepts data in and produces answers, but has no route to send your content out. Every action is cryptographically sealed as it happens, so the record of what was read, retrieved and generated stays inside the same trust boundary as the data itself.

An enterprise search assistant inverts this. To answer across your knowledge, it must first ingest and embed your knowledge into its own store. That store is the offering. The convenience you buy is a hosted, always-current copy of your most sensitive material.

Where does the data end up in each model?

With a SIOS, the data ends up exactly where it started: on your machines, under your keys, inside your building or your private cloud tenancy. Nothing is retained by a third party because nothing is transmitted to one.

With a vendor-hosted search assistant, the data ends up in the vendor's infrastructure as embeddings, cached text and retrieval logs. Even when a contract promises isolation and no training use, the physical location of the index determines which laws reach it.

If answering your questions requires a copy of your documents to live in a vendor's cloud, then that vendor's jurisdiction, not your policy, decides who can compel access.

What can an auditor actually check?

An auditor should be able to verify the claim, not just read the marketing. Mickai binds identity to hardware-attested credentials, so every action is tied to a specific, attested machine rather than a shared cloud account. Each entry in the audit ledger is signed and the ledger is verifiable offline, without calling home.

The signatures use the post-quantum standards NIST finalised in 2024: FIPS 204 (ML-DSA) is the primary signature scheme that seals and verifies each ledger entry, with FIPS 205 (SLH-DSA) available as a hash-based alternative. Note the distinction: FIPS 203 (ML-KEM) is key encapsulation, not a signature scheme, so it never signs or seals the record. A concrete test: take the sealed ledger to an air-gapped machine and verify the signature chain with no network present. If it verifies offline, the record is self-contained. If verification needs the vendor's servers, it is not sovereign.

Which rules make this necessary?

Several regimes now push in the same direction. DORA has applied to EU financial entities since January 2025 and holds firms accountable for their ICT third parties, including where processing happens. NIS2 raises security and oversight duties for essential and important entities across critical sectors. GDPR still governs personal data and cross-border transfer. The US CLOUD Act allows US authorities to compel US-headquartered providers to hand over data they hold, wherever that data physically sits, which is the crux of the jurisdiction problem for any cloud-indexed corpus.

On the EU AI Act, be precise about timing. The high-risk Annex III obligations, once expected on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk moving to 2 August 2028 and the Article 50 transparency duties largely unchanged. We read that as a build window, not a reprieve. ISO/IEC 42001 gives a management-system framework for demonstrating this governance rather than asserting it.

Does keeping data in-country solve it?

Region selection helps with latency and some residency clauses, but it does not close the jurisdiction gap on its own. A data centre physically located in your country, operated by a foreign-headquartered provider, can still fall under that provider's home-country compulsion powers. Sovereignty is about who can be compelled to produce your data, not only about the map pin on the server. The reliable test is control: do you hold the keys, does the system run without outbound egress, and can you verify the audit trail without the vendor. If the answer to any of those is no, the residency label is doing less than it appears.

Can you get search-assistant usefulness without the egress?

Yes, and that is the point of the sovereign design. Retrieval, summarisation and cross-document reasoning do not require a vendor to hold your index. Mickai runs those functions locally on sovereign models, and adds cross-model consensus so more than one model must agree before an answer is surfaced, reducing single-model error inside the perimeter. The result is the assistant experience without the outbound copy. The intellectual property behind this architecture sits in 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, and is patent pending.

Frequently asked questions

Does enterprise search AI store your documents in the cloud?

In most designs, yes. To search across your knowledge, the assistant ingests and embeds your documents into its own hosted index, which is a persistent copy in the vendor's infrastructure. Contracts may limit training use and promise tenant isolation, but the searchable copy still lives outside your perimeter. Ask specifically where the index is stored and who can be compelled to produce it.

What is the difference between sovereign AI and a private cloud deployment?

A private cloud deployment usually still runs on a provider's infrastructure and under that provider's jurisdiction, even in a dedicated tenancy. Sovereign AI means the system runs on hardware you control, with no outbound egress, keys held by you, and an audit trail you can verify independently. The test is compulsion and control, not the tenancy label.

Can regulated firms use ChatGPT, Claude or Gemini for internal documents?

For genuinely sensitive or regulated material, generally no. Sending confidential records to a public cloud AI service creates egress and foreign-jurisdiction exposure that DORA, NIS2 and GDPR obligations make hard to accept. These services suit public or low-sensitivity work. The gap they leave is exactly what sovereign, on-premise processing is built to fill.

How can an auditor verify that no data left the building?

Look for two properties. First, a zero-egress inbound perimeter, so the system has no route to transmit content outward, which can be confirmed at the network layer. Second, an offline-verifiable audit ledger whose entries are signed with post-quantum signatures under FIPS 204, checkable on an air-gapped machine. If both hold, the absence of egress is demonstrable rather than merely promised.

Is the EU AI Act high-risk deadline still 2 August 2026?

No. The Digital Omnibus deferred the high-risk Annex III obligations to 2 December 2027, with embedded Annex I high-risk moving to 2 August 2028 and Article 50 transparency duties largely unchanged. Treat the extra time as a window to build verifiable, sovereign systems rather than a reason to delay. The underlying direction of travel on accountability and traceability has not changed.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-vs-enterprise-search-assistants. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.