Articles
Articles

Field notes from inside a sovereign AI.

Mickai® is a Sovereign Intelligence Operating System (SIOS) that runs on your own hardware. These are long-form essays on the architecture of the Mickai SIOS, the patterns that keep surfacing in commercial AI in 2026, and the engineering choices that make sovereign intelligence possible. Written by Micky Irons, named inventor of the 104 filed UK patent applications, recorded on the UK IPO public register at numbers GB2607309.8 to GB2611702.8, GB2611885.1 onwards, GB2612762.1 to GB2612793.6, GB2613386.8 to GB2613404.9, and GB2615041.7 to GB2615043.3.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Fifty brains · 25 domain, 25 operational
104 filed UK patent applications · 2,340 claims

The cooperative the field notes describe, running on the sovereign silicon substrate.

All articles

Showing 529 to 552 of 1124 articles.

8 Jul 2026 · Micky Irons

Which Organisations Should Run AI On-Premise Instead of Using Public Cloud AI?

Run AI on-premise when your data is legally bound to a jurisdiction, must stay auditable, or cannot lawfully leave your perimeter.

on-premise aisovereign aidata residencyai complianceregulated industries
Read →
8 Jul 2026 · Micky Irons

Who Offers a Fully Offline AI With an Immutable Audit Trail?

A fully offline AI with an immutable audit trail runs on operator-owned hardware with no egress and seals every action to a signed ledger.

offline aiimmutable audit trailsovereign aisiospost-quantum signatures
Read →
8 Jul 2026 · Micky Irons

Whose Root of Trust Is It: Confidential Computing Versus Operator-Owned Silicon

Confidential computing protects data in use, yet the trust anchor still belongs to the vendor rather than the operator who owns the machine.

confidential computingroot of trustsovereign aihardware attestationdata sovereignty
Read →
8 Jul 2026 · Micky Irons

Write Once, Prove Forever: WORM Storage for AI Decisions

Why an AI decision should be as durable and as impossible to rewrite as a regulated financial record kept under write-once, read-many rules.

worm-storageaudit-trailpost-quantumai-governancecompliance
Read →
8 Jul 2026 · Micky Irons

Your AI Vendor Is Now a Critical Third Party: DORA, Concentration Risk and Owning the Model

When a regulator can designate your AI provider critical, the safest exit plan is never needing one.

doraconcentration risksovereign aithird-party riskcompliance
Read →
8 Jul 2026 · Micky Irons

Zero-Egress AI: An Inbound Perimeter That Classifies, Firewalls and Signs

Nothing should reach a model unclassified, and every routing decision an inbound perimeter makes should be signed and auditable.

zero-egressdata-sovereigntyai-governanceinbound-perimeteraudit
Read →
4 Jul 2026 · Micky Irons

92 Percent of Security Leaders Cannot See Their AI Identities. That Is a Governance Emergency

A 2026 survey exposes an agent-identity blind spot that is really an audit gap, and why the per-action signed record only holds inside owned walls

AI governanceagent identityauditCISOsigned attestation
Read →
4 Jul 2026 · Micky Irons

AI Governance as Code

Cryptographic policies that decide before any action happens, not after

governancecomplianceoarpost-quantumsovereign-ai
Read →
4 Jul 2026 · Micky Irons

A 15 Percent Premium To Rent Sovereignty. Here Is the Ownership Maths

The AWS European Sovereign Cloud went live at a consistent 15 percent premium. We do the honest sum against a one-time owned SIOS, and show where the premium and the residual actually go.

sovereign cloudAWS European Sovereign Cloudtotal cost of ownershipdata sovereigntyCLOUD Act
Read →
4 Jul 2026 · Micky Irons

Bleu, Delos, and the Ceiling of a Licensed Sovereign Cloud

National partner clouds raise the floor for public-sector sovereignty. Ownership is where the ceiling gets interesting.

sovereign cloudpublic sectordigital sovereigntyBleuDelos
Read →
4 Jul 2026 · Micky Irons

CADA Draws A Line Through The Public-Sector Cloud. Here Is Where Owned Infrastructure Sits

The EU's Cloud and AI Development Act sorts government workloads into four sovereignty tiers. I explain the honest boundary, and why owned, air-gapped SIOS is the natural fit for the top of it.

CADAEU sovereigntypublic sectorcloud procurementdata residency
Read →
4 Jul 2026 · Micky Irons

California Now Makes You Disclose Your Training Data. Most Vendors Cannot

AB 2013 took effect on 1 January 2026. The first disclosures from the biggest labs proved a point we have been making for two years. If you scraped the open web, you cannot answer the provenance question. If you trained on a sealed, documented corpus, you can.

AI governancetraining dataAB 2013model provenanceAI procurement
Read →
4 Jul 2026 · Micky Irons

The CLOUD Act Is The Clause Nobody Repealed. It Is Why Sovereignty Is A Preference, Not A Ban

Even Microsoft cannot promise EU data will never be reached under US law. That fact does not bar most workloads from cloud. It moves the real line to the workload level. Here is exactly where that line sits.

CLOUD Actdata sovereigntycloud riskDORAGDPR
Read →
4 Jul 2026 · Micky Irons

The EU Gave Cloud A Sovereignty Score. Here Is How To Read Yours Honestly

The Cloud Sovereignty Framework put a number on foreign-law exposure. I explain what it measures, why hyperscalers still pass most of it, and the one line where an owned deployment scores where nothing foreign-controlled can.

cloud sovereigntyEU procurementCLOUD Actjurisdictional riskdata sovereignty
Read →
4 Jul 2026 · Micky Irons

Attestation-Gated Keys Are Clever. They Still Do Not Own the Building

Attestation-gated key release proves the state of a machine. It does not change whose machine it is, and that gap is structural.

confidential computingattestationAI securitysovereign AIconfidential GPU
Read →
4 Jul 2026 · Micky Irons

Content Credentials Stopped Being Optional: Provenance Is Now A Compliance Layer

C2PA has crossed from a voluntary standard into a regulatory baseline. From 2 August 2026 the EU AI Act makes machine-readable provenance a transparency obligation, and the organisations that can sign what they produce at the point of creation are the ones who stay clean.

content authenticityC2PAEU AI Actprovenancecompliance
Read →
4 Jul 2026 · Micky Irons

In-Country Processing Is Not The Same As In-Your-Control: Reading The Copilot Residency Expansion

Microsoft just widened where Copilot data is processed. That answers where your data sits. It does not answer who can compel access, or who runs the model.

data residencydata sovereigntyMicrosoft 365 Copilotsovereign AICLOUD Act
Read →
4 Jul 2026 · Micky Irons

Defending Against Model Extraction Attacks

Your model weights are your reflection. Here is how we make certain no attacker can steal it, copy it, or turn it against you.

model-extractionai-securitysovereign-aimodel-weightsattestation
Read →
4 Jul 2026 · Micky Irons

Deterministic Multi-Agent Systems for Regulated Work

Predictable, auditable agent orchestration for institutions that must prove every step

multi-agentdeterminismcomplianceauditsovereign-ai
Read →
4 Jul 2026 · Micky Irons

The EU Just Pushed High-Risk AI to December 2027. Here Is What We Are Building Instead of Waiting

The Digital Omnibus defers Annex III deadlines to 2 December 2027. We read that as a build window, not a reprieve, because the controls that arrive in 2027 are the exact attestation record a sovereign system already produces on day one.

EU AI ActDigital OmnibusAI governancehigh-risk AIsovereign AI
Read →
4 Jul 2026 · Micky Irons

The Omnibus Bought You Time On High-Risk AI. It Did Not Buy You Control

Brussels moved the high-risk deadline to December 2027. The audit that lands when it arrives will be harder, not softer. Here is why we build governed infrastructure now.

EU AI ActAI governanceDigital Omnibushigh-risk AIcompliance
Read →
4 Jul 2026 · Micky Irons

The 19 Named Providers: DORA Just Made Cloud Concentration a Supervisory Problem

When your regulator names your provider critical, substitutability and exit stop being paperwork. Owning the intelligence layer is the substitutable fourth option.

DORAconcentration riskICT third-party risksovereign AIfinancial services resilience
Read →
4 Jul 2026 · Micky Irons

DORA Named The 19 Critical Providers. Now Every Bank Has To Explain Its Concentration Risk

On 18 November 2025 the EU supervisors published the first official list of critical ICT providers. Dependence on a handful of hyperscalers is now a documented supervisory fact, and the concentration-risk math has changed.

DORAconcentration riskICT third-party risksovereign AIfinancial services
Read →
4 Jul 2026 · Micky Irons

Register of Information Season: Every Line You Do Not Have To Explain

The 2026 Register of Information cycle is live. For the AI workload, ownership does not defend the row. It removes it.

DORARegister of Informationthird-party riskICT resiliencesovereign AI
Read →