Field notes from inside a sovereign AI.
Mickai® is a Sovereign Intelligence Operating System (SIOS) that runs on your own hardware. These are long-form essays on the architecture of the Mickai SIOS, the patterns that keep surfacing in commercial AI in 2026, and the engineering choices that make sovereign intelligence possible. Written by Micky Irons, named inventor of the 104 filed UK patent applications, recorded on the UK IPO public register at numbers GB2607309.8 to GB2611702.8, GB2611885.1 onwards, GB2612762.1 to GB2612793.6, GB2613386.8 to GB2613404.9, and GB2615041.7 to GB2615043.3.
The cooperative the field notes describe, running on the sovereign silicon substrate.
Showing 289 to 312 of 1124 articles.
Does the UK Data (Use and Access) Act change the rules for AI decisions?
Yes, the UK is moving from prohibition to permission with safeguards for most automated decisions, which makes the evidence burden sharper.
How do you back up and restore an air-gapped AI system?
With the same discipline as any critical system: versioned, signed backups inside the perimeter, proven by rehearsed restore drills.
How long must you keep AI decision logs under the EU AI Act, DORA and GDPR?
The EU AI Act sets a six month floor, DORA follows supervisory rules, and GDPR requires a documented retention schedule.
How do you run a sovereign AI pilot in 90 days?
Pick one measurable workflow, run it on operator-owned hardware inside your perimeter, and let the sealed evidence decide the scale decision.
Is AI CV screening high-risk under the EU AI Act?
Annex III classifies AI used to screen and filter job applications as high risk, with obligations applying from 2 December 2027.
Is air-gapped AI less capable than cloud AI?
For most enterprise work no, for a narrow set of frontier tasks yes, and regulated buyers should know which.
Is emotion recognition AI banned at work under the EU AI Act?
In the workplace yes, with narrow medical and safety exceptions, and the prohibition has applied since 2 February 2025.
Is your AI provider about to become a UK critical third party?
Possibly: FSMA 2023 lets HM Treasury designate providers critical to UK finance, and AI services concentrate exactly the way cloud does.
Can audit firms use AI on client working papers?
Yes, when the AI runs inside the firm's perimeter, engagements are segregated, and every procedure writes to a verifiable sealed record.
Can care providers use AI on safeguarding and resident data?
Yes, when the AI runs inside the provider's own boundary, professionals keep every decision, and each action is sealed to a verifiable record.
Can charities use AI on donor and beneficiary data?
Yes for drafting, grants and admin, provided beneficiary-identifying data never leaves the charity's control and trustees can evidence oversight.
What should a housing association require from AI used on tenant data?
Processing inside the association's own boundary, a per-case audit trail an Ombudsman can verify, and officers keeping every decision.
Can schools use AI without sending pupil data to the cloud?
Yes, when the AI runs on infrastructure the trust controls and pupil data never leaves the school's own boundary.
Should a trade union let member data anywhere near cloud AI?
No, because membership itself is special category data and the confidentiality promise to members should be structural, not contractual.
What should AI operators prepare for the UK Cyber Security and Resilience Bill?
Prepare the evidence discipline NIS2 already demands: know your suppliers, log what your AI does, and report from records you hold.
What does a credible exit plan from a cloud AI vendor look like under DORA?
A credible exit plan names the replacement, proves data and logs extract in usable form, and has been rehearsed, not merely documented.
What does an AI readiness assessment actually check?
A serious assessment checks five domains: data, infrastructure, governance, people and evidence, starting from what you must prove afterwards.
What happens when your cloud AI model is deprecated?
Your validated workflows change on the provider's schedule, and the regulated answer is version permanence on infrastructure the operator owns.
What hardware do you need to run enterprise AI on-premise?
One capable workstation serves a small team, larger servers serve departments, and a small cluster serves an organisation, with memory the real constraint.
What should an AI acceptable use policy cover in 2026?
Approved tools by data class, banned data, approval routes, logging, output verification, AI literacy training and consequences, plus a capable sanctioned alternative.
What skills does your team need to run sovereign AI?
Four ordinary roles and governance judgement, not a research lab, because an operating system approach removes the need for specialist model skills.
When does an AI failure become a reportable incident under DORA?
When it meets the DORA classification criteria for a major ICT-related incident, reportable on a strict clock.
Who maintains on-premise AI when something breaks?
Mostly your existing IT team, because the failures are typically ordinary, and a serious sovereign deployment diagnoses and repairs its own runtime.
AI Compliance Is Not Just About GDPR
GDPR is the floor, not the ceiling. The EU AI Act, NIS2, DORA, sector supervision and your own authority matrix all converge on one obligation: prove what the system did.

