Field notes from inside a sovereign AI.
Mickai® is a Sovereign Intelligence Operating System (SIOS) that runs on your own hardware. These are long-form essays on the architecture of the Mickai SIOS, the patterns that keep surfacing in commercial AI in 2026, and the engineering choices that make sovereign intelligence possible. Written by Micky Irons, named inventor of the 104 filed UK patent applications, recorded on the UK IPO public register at numbers GB2607309.8 to GB2611702.8, GB2611885.1 onwards, GB2612762.1 to GB2612793.6, GB2613386.8 to GB2613404.9, and GB2615041.7 to GB2615043.3.
The cooperative the field notes describe, running on the sovereign silicon substrate.
Showing 265 to 288 of 1124 articles.
How do you find the AI agents already running in your organisation?
The same way you find shadow IT, but with lenses built for agents, and a register that keeps them found.
How do you update an air-gapped AI system safely?
Sign every artefact, use one controlled import path, stage before promotion, and seal the update to the ledger.
Is your IT provider feeding your data into cloud AI?
Possibly, through helpdesk copilots you never approved, and your contract may already require your say-so.
What happens when your AI vendor is acquired?
Your rights become whatever the contract says on closing day, and most AI contracts were not written with acquisition in mind.
What is the EU Cloud and AI Development Act?
A European Commission proposal adopted on 3 June 2026 that grades cloud sovereignty on a four-tier ladder, still in the legislative process.
What is the UK AI Growth Lab and who should use it?
A cross-regulator guidance channel announced 8 June 2026, starting with lawtech and conveyancing, that helps but does not replace evidence.
Will AI vendors soon need independent safety audits?
Vendor audits are arriving jurisdiction by jurisdiction, but they check the vendor, not whether your own deployment is auditable.
Are AI prompts and outputs subject to freedom of information?
For UK public authorities yes where the information is held, including records a vendor keeps on the authority's behalf.
Can a security operations centre use AI on incident data without a cloud SIEM?
AI triage, enrichment and reporting can run entirely inside the security perimeter on hardware the operator owns, with every action sealed to a ledger.
Can AI run inside an OT network under IEC 62443?
Yes, as a local workload inside the zone model; outbound internet from an OT zone creates a conduit that is very hard to justify.
Can an AI agent hold regulated responsibility under the UK SM&CR?
No; the Senior Managers and Certification Regime allocates responsibility to named humans, so every agent action lands on a senior manager's record.
Can an AI agent sign a contract on behalf of your company?
The company can be bound but the agent cannot be responsible, so authority and evidence become the questions that matter.
Can bidders use AI on data room material in M&A due diligence?
Only after reading the NDA and data room terms; the defensible pattern is AI inside the confidentiality perimeter with a sealed processing record.
Can directors be personally liable for AI risk under NIS2?
Yes in a specific sense: NIS2 Article 20 places approval, oversight and training duties on management bodies personally, with liability for infringements.
Can HR use AI on grievance and disciplinary cases?
Yes, for summarising and drafting inside the employer's own boundary, with humans deciding outcomes and a sealed record of every AI action.
Can insolvency practitioners use AI on case data?
Yes, for claims review, records reconstruction and reporting, when estate data stays under the practice's control and every step is evidenced.
Can you fine-tune an AI model on customer data without it leaking?
Yes, if you treat the fine-tuned weights as a copy of the training data and keep both inside your own perimeter.
Can you meet NIS2 24-hour incident reporting when AI is in the loop?
You can only report what you can see, and a sealed local audit ledger makes the 24 hour early warning achievable.
Can you use AI on whistleblowing reports?
Yes for triage and anonymisation, but only inside the organisation's own perimeter with every access sealed to an audit record.
Do employees need AI training under the EU AI Act?
Yes, the Article 4 AI literacy duty has applied since 2 February 2025 and was not deferred by the Digital Omnibus.
Do you need a DPIA before deploying AI?
Almost always yes when personal data is involved, and for cloud AI services the honest assessment is often impossible to complete.
Does DORA require threat-led penetration testing of your AI systems?
DORA does not name AI, but AI supporting critical functions falls inside the resilience testing programme, including TLPT for designated entities.
Does the EU AI Act apply to UK companies selling into the EU?
Yes. The Act is extraterritorial: UK providers placing AI on the EU market, or whose output is used in the EU, are in scope.
Does the EU Cyber Resilience Act apply to AI products?
Yes for AI shipped as software on the EU market, with reporting duties biting from 11 September 2026.

