Which organisations should run sovereign AI in 2026, and which rule makes it necessary?
Banks, hospitals, governments and infrastructure operators should run sovereign AI in 2026, because the US CLOUD Act puts public cloud data beyond legal control.

Four kinds of organisation should run sovereign AI in 2026: regulated financial institutions, healthcare providers, government and defence teams, and operators of critical national infrastructure. The single rule that makes it necessary is the United States CLOUD Act, which lets US authorities compel any US-headquartered provider to disclose data it controls anywhere in the world. Any regulated record sent to a public cloud AI service therefore leaves the operator's legal control. Sovereign AI keeps the model, the data and the audit trail on operator-owned hardware, where no foreign order and no vendor can reach them.
This question matters in 2026 because the gap between what public cloud AI offers and what regulated law allows has become impossible to paper over. Boards want the productivity of large models. Regulators want provable control over where data lives, who touched it and whether the answer can be reconstructed later. A general-purpose service that reaches back to a foreign data centre cannot satisfy both at once. Sovereign AI is the design that can.
What is sovereign AI, and how is it different from private cloud?
Sovereign AI means the model runs entirely on hardware the operator owns and controls, inside their own perimeter, with no dependency on an external provider to function. A private cloud tenancy is still someone else's infrastructure under someone else's jurisdiction. Sovereign AI removes that dependency completely.
Mickai is a Sovereign Intelligence Operating System, a SIOS. It runs offline on operator-owned hardware, and every action it takes is cryptographically sealed into an audit record. There is no call home, no telemetry and no vendor holding a key to your data.
Which organisations actually need it in 2026?
The need is driven by specific obligations, not by sector labels. The organisations that cross the line are the ones holding data a regulator can demand a full account of.
- Banks, insurers and payment firms fall under DORA, in force across the EU since January 2025, which holds them responsible for the resilience and traceability of every critical ICT service, AI included.
- Hospitals and health systems process special-category data under GDPR, where an uncontrolled transfer to a foreign cloud can breach GDPR's transfer rules.
- Government and defence teams handle classified and citizen data that cannot lawfully sit on infrastructure a foreign state can compel.
- Energy, water, transport and telecoms operators are essential or important entities under NIS2, which requires demonstrable security and supply-chain control over the systems they depend on.
Which rule makes it necessary?
If one rule forces the decision, it is the US CLOUD Act. It gives United States authorities the power to compel a US-headquartered provider to produce data it controls, regardless of the country the servers sit in. A European bank using a US cloud AI service has no way to guarantee that a foreign order will not reach its records. For DORA, NIS2 and GDPR obligations, that is not a manageable risk. It is a structural one.
“If a foreign law can compel your AI provider to hand over your data, that data was never sovereign, whatever the contract said.”
How does it work?
Sovereign AI works by removing every path along which data could leave and every actor who could reach in. We build on four mechanisms.
- A zero-egress inbound perimeter: the system can receive work but has no outbound route, so data physically cannot leave the operator's hardware.
- Hardware-attested identity: every user and process is bound to the hardware and to the audit chain, so no action is anonymous and no credential can be spoofed.
- A post-quantum signed audit ledger: every action is sealed with FIPS 204 (ML-DSA) signatures, with FIPS 205 (SLH-DSA) as a stateless-hash alternative, so the record stays verifiable even against a future quantum adversary.
- Cross-model consensus: several sovereign models answer independently and their outputs are compared, so a single model's error or drift is caught before it reaches a decision.
This architecture is the subject of 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, all patent pending.
What can an auditor check?
An auditor should be able to verify the answer without trusting the vendor, and sovereign AI is designed so they can.
Because the audit ledger is signed with FIPS 204, an auditor can take any sealed record and verify offline that it has not been altered and which attested identity produced it. The chain is tamper-evident: a changed record breaks the signature. The zero-egress perimeter can be inspected to confirm there is no outbound path. Together these give an auditor offline verifiability, which is the property a data-controller obligation actually requires.
Does the EU AI Act change the timeline?
It changes the date, not the direction. The high-risk obligations under Annex III of the EU AI Act, once due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk systems moving to 2 August 2028. The Article 50 transparency duties are largely unchanged. We read the deferral as a build window, not a reprieve: the organisations that use the time to move regulated workloads onto sovereign infrastructure will meet the obligations calmly, and the ones that wait will meet them in a rush.
Frequently asked questions
Is public cloud AI legal to use for regulated data in 2026?
For most regulated data, not safely. General-purpose public cloud AI services run on infrastructure reachable under the US CLOUD Act, so data sent to them can leave the operator's legal control. Under DORA, NIS2 and GDPR, that loss of control is the exact risk those regimes exist to prevent.
What is the difference between sovereign AI and on-premise AI?
On-premise describes where the hardware sits. Sovereign AI describes who holds control: the model, the data and the audit trail stay under the operator's authority with no external dependency and no vendor key. Sovereign AI is on-premise, but on-premise is not automatically sovereign if it still calls out to a provider.
Does DORA require organisations to run sovereign AI?
DORA does not name sovereign AI, but it requires financial entities to prove resilience, traceability and control over every critical ICT service. A foreign cloud AI service that can be compelled under the CLOUD Act is hard to evidence against those duties. Running AI on operator-owned hardware with a signed audit ledger is a direct way to meet them.
When is the EU AI Act high-risk deadline now?
The Annex III high-risk obligations, once set for 2 August 2026, are now due on 2 December 2027 after the Digital Omnibus deferral, with embedded Annex I high-risk systems due on 2 August 2028. Article 50 transparency duties are largely unchanged. The extra time is best used to migrate regulated workloads, not to defer the decision.
Can a hospital run large AI models fully offline?
Yes. A Sovereign Intelligence Operating System runs capable models on the hospital's own hardware with no internet path out. Clinical data stays inside the perimeter, every action is sealed into a verifiable ledger, and the system keeps working even with no external connection at all.