Why I Built a Sovereign AI Operating System
The founder's account of why regulated organisations deserve capable AI without surrendering custody of their data.

I built Mickai, a British Sovereign Intelligence Operating System, because the organisations that most need capable AI are the ones the cloud locks out. A bank, a hospital, a law firm or a government department cannot send its most sensitive records to a third party's servers just to get a useful answer. The prevailing model of AI demands exactly that: it takes custody of your data in exchange for intelligence. I decided to invert the trade. Instead of moving the data to the model, Mickai moves the model to the data, so the data never leaves the building. That is the whole reason the company exists.
- The problem: capable AI has, until now, required handing custody of your data to someone else's cloud.
- The inversion: Mickai brings the model to the data, so nothing sensitive leaves your infrastructure.
- Own it: the system runs on hardware you control, fully offline, on a loopback-only inference engine called Poros.
- Prove it: every material action is written to an Open Audit Record, post-quantum signed and verifiable offline.
- The mission: give regulated organisations the same capability as everyone else without asking them to give up sovereignty.
The problem I kept running into
For years the pattern was the same. A regulated organisation would look at what modern AI could do, get excited, then read the data processing terms and quietly walk away. To use the capable models, they had to send their documents, their customer records, their case files or their patient notes to infrastructure they did not own and could not inspect. For a retailer that might be a manageable risk. For a bank bound by supervisory rules, a hospital holding special category data, or a law firm carrying legal professional privilege, it is a non-starter.
The uncomfortable truth is that the cloud AI bargain is a custody bargain. You get intelligence, and in return you give up control of the very thing that makes your organisation sensitive. Most vendors dress this up in encryption and compliance badges, but the core fact remains: your data sits on someone else's machine, subject to someone else's jurisdiction, readable under someone else's process. I kept meeting serious people who wanted the capability and simply could not accept the terms.
The decision: bring the model to the data
So I stopped trying to make the cloud model safe enough and asked a different question. What if the data never moved at all? What if, instead of shipping your files to the intelligence, you brought the intelligence to your files, inside your own walls, on hardware you control? That single inversion is the founding idea of Mickai.
It sounds obvious once you say it, but it changes almost everything about how the system has to be built. The model has to run locally and capably. It has to work with no internet connection. It has to keep a record you can trust without phoning home. And it has to do real work, not toy demonstrations. Building for that constraint is harder than renting a cloud endpoint, which is precisely why so few have done it.
Own it: your hardware, your weights
Sovereignty starts with ownership. Mickai runs on infrastructure the customer controls, from a workstation to a rack, with no dependency on an external service to function. The model weights sit with you. Nothing about the core capability requires a live link to a vendor, which means no silent updates, no metering of your queries, and no third party with a window into what your people are asking.
Ownership also means the system keeps working when the network does not. Air-gapped sites, secure facilities and field deployments are first-class cases, not edge cases we apologise for. If the connection drops, the intelligence does not.
Run it: offline by design, on Poros
The engine that makes this possible is Poros. It runs a large, genuinely capable model on local hardware, bound to loopback only, with no outbound connection. In plain terms, the intelligence answers from inside the machine and cannot reach the internet even if it wanted to. That is not a setting you toggle. It is the design.
On top of Poros sit the studios: sixty-three of them on the one engine, of which fourteen are production-ready at launch and forty-nine are in active development. Email, documents, meetings, knowledge bases, analysis and more, each a focused workspace, all sharing the same private brain. The point is that offline does not have to mean underpowered. You can do the everyday work of a modern organisation without a single byte leaving the building.
Prove it: the Open Audit Record
Capability you cannot prove is not much use in a regulated setting. This is where most sovereign or on-premise claims fall down: they keep the data local but cannot show a regulator, an auditor or a court what actually happened. Mickai writes every material action to the Open Audit Record, or OAR.
The OAR is post-quantum signed, using the FIPS 204 standard (ML-DSA-65), and it is verifiable offline. I am deliberate about the language here: it is tamper-evident, not tamper-proof. No honest engineer promises a record that cannot be interfered with. What we promise is that interference leaves a mark you can detect, independently, without trusting us and without an internet connection. That is the difference between a marketing claim and evidence.
One inventor, a filed patent estate
I am the founder and named inventor of Mickai, and the company is Mickai LTD, registered at Companies House under number 17166618. The mechanisms behind the system are the subject of 104 filed UK patent applications carrying 2,340 claims, patent-pending at the UK Intellectual Property Office. To be precise, these are filed applications, not granted patents.
Our philosophy is simple: we patent the mechanism, not the model. The moat is in how sovereignty, offline inference and verifiable audit are engineered together, not in any particular set of weights. I have also published technical preprints on Zenodo, under ORCID 0009-0000-5511-5858, covering the offline attestation record, sovereign inference, private knowledge bases and turning compliance into evidence, because the ideas should stand up to scrutiny in the open.
Why this is the mission
I did not build Mickai to compete on who has the cleverest chatbot. I built it because there is a whole class of institutions doing the most consequential work in society, in finance, health, law and government, that has been told it must choose between capability and control. That is a false choice, and it is a dangerous one, because the organisations most likely to be excluded are exactly the ones we most need to get this right.
Bringing the model to the data closes that gap. Own it, run it offline, prove what it did. If you are wrestling with the same trade-off, the closed beta is open at mickai.co.uk/beta, and we are onboarding a first cohort of design partners now.
Frequently asked questions
What is a sovereign AI operating system?
It is a complete AI environment that runs on infrastructure you own and control, rather than a vendor's cloud. Mickai keeps your data inside your walls, runs its intelligence offline, and records what it does in a way you can verify independently.
Does Mickai really work with no internet connection?
Yes. The Poros engine runs a capable model on local hardware, bound to loopback only, with no outbound connection. Offline operation is the default design, not an optional mode, which makes air-gapped and secure sites first-class deployments.
What is the Open Audit Record?
The OAR is Mickai's tamper-evident log of material actions. It is post-quantum signed under FIPS 204 (ML-DSA-65) and can be verified offline, so an auditor or regulator can confirm what happened without trusting the vendor or needing a network.
Is Mickai patented?
The mechanisms are the subject of 104 filed UK patent applications with 2,340 claims, patent-pending at the UK Intellectual Property Office. These are filed applications rather than granted patents. Our approach is to patent the mechanism, not the model.
Who is behind Mickai?
I am Micky Irons, founder and named inventor, and the company is Mickai LTD, Companies House number 17166618. I have also published technical preprints on Zenodo (ORCID 0009-0000-5511-5858) on sovereign inference, offline attestation, private knowledge bases and compliance to evidence.
How do I try it?
The closed beta is open at mickai.co.uk/beta. We are onboarding a first cohort of design partners, and that is the best way to put a sovereign, offline system to work against your own regulated use cases.