The architecture of sovereign AI is already filed.
Anyone building sovereign or on-premise AI converges on the same architecture: a request perimeter that classifies before it routes, many brains that must agree before they act, a post-quantum audit record a regulator can walk, provenance bound to every generated artefact, and a trust anchor the operator holds. Mickai reached that architecture first and filed it. These 104 applications are not scattered ideas; they occupy the 13 families of ground a serious builder cannot avoid, which is why the sensible move is an inbound licensing conversation rather than a redesign that keeps reading onto the same claims. They are filed applications, not yet granted; they establish priority dates and form a published prior-art record.
Multi-Brain Cooperative Orchestration and Consensus Gating
Fifty specialist brains cooperate under a deterministic arbiter; consensus is a precondition of action.
This family replaces the single monolithic model with a cooperative substrate of fifty specialist brains that exchange typed message envelopes over a signed internal bus under a deterministic arbiter, so that no sensitive action dispatches until independent brains, and in the higher-tier filings independent model families drawn from distinct lineages, reach byte-equivalent agreement. Consensus is engineered as a precondition of action rather than an afterthought: divergence across brains triggers refusal and catches a hallucination at the moment of generation, a fresh voice-biometric utterance is bound to the specific action digest so the same utterance cannot authorise anything else, and any action that fails after dispatch is reversed by an automatic compensating rollback, with the whole runtime partitionable into department-scoped fleets on a single offline device. It is hard to design around because the isolation, the signing, and the quorum are architectural invariants fuse-bound to an operator-held hardware root of trust with no network authority in the trust path, so an attacker would have to compromise several physically separate model families, each brain's hardware-attested key, and the arbiter simultaneously to move a single sensitive action.
- A hospital runs clinical decision support where a treatment or discharge instruction is emitted only when several independent brains agree, and any single brain hallucinating a dose triggers refusal before the instruction reaches a clinician.
- A defence or intelligence facility operates the full brain fleet air-gapped on one owned device, partitioned into department-scoped enclaves so an analyst in one compartment cannot compose across another, with every cross-compartment aggregation sealed to a top-level ledger.
- A bank gates payment release, model changes, and large exposures behind a cross-model consensus quorum so a prompt-injection attack against one model family cannot dispatch a transfer, and a failed instruction rolls back automatically to a known good state.
- A government department serves several classifications from a single multi-tenant device with cryptographic isolation and voice-gated switching, so an official moving between tenants cannot leak between them and each tenant keeps a separate partitioned audit record.
- A critical-national-infrastructure operator requires a fresh voice-biometric utterance bound to the specific action digest before a switching or shutdown command executes, defeating replay and misdirected-authority attacks even when an adversary holds full session access.
Anyone building sovereign or on-premise AI eventually reaches the same conclusion Mickai reached first: a single model cannot be trusted to authorise a consequential action on its own, so the safe architecture is many independent brains that must agree before anything dispatches. The moment a competitor adds a second model to cross-check the first, gates a sensitive action on their agreement, refuses on divergence to catch hallucination, binds authorisation to hardware-attested keys, or partitions brains into isolated department fleets on an owned offline box, they are standing on this filed ground, because these filings claim the cooperative substrate, the signed envelope bus, byte-equivalent cross-model quorum, divergence-triggered refusal, replay-resistant voice-to-action binding, TPM-attested quorum with automatic rollback, and department-partitioned offline orchestration as an integrated whole rather than one narrow trick. The filings also pre-empt the obvious escape routes by distinguishing cloud multi-tenant isolation, single-tenant inference frameworks, and confidential-computing enclaves, so the design space around a sovereign, offline, consensus-gated multi-brain system is already occupied, which is why the sensible next step is an inbound licensing conversation rather than a redesign.
If your roadmap has more than one model checking another before a sensitive action fires, you are building on ground Mickai has already filed, and a licence is faster and safer than a redesign.
The 7 filed applications in this family
Multi-Brain Cooperative Intelligence
Specialist brains, signed envelope bus, voice-biometric quorum.
Read the application →Adaptive Multi-Tenant OS
Healthcare and enterprise isolation with voice-gated switching.
Read the application →Cross-Model Consensus Gating
Multiple independent model families must agree before sensitive actions dispatch. 25 claims.
Read the application →Cross-Brain Quorum for Generative Hallucination Detection with Divergence-Triggered Refusal
N independent brains must agree within a per-domain semantic-distance threshold or no artefact is signed.
Read the application →Voice-Gated Multi-Brain Quorum with Replay-Resistant Action Composition for Sovereign Personal Artificial Intelligence
Single gate composes fresh voice biometric, action-digest binding, and multi-brain quorum agreement.
Read the application →TPM-Attested Cross-Brain Quorum with Automatic Compensating Rollback
TPM-attested brains must reach quorum; a failed action rolls back automatically. 12 claims.
Read the application →Sovereign Offline Orchestrator for Department-Partitioned Artificial Intelligence Brain-Fleet Inference on a Single Offline Computing Device
Partitions the brain fleet into department-scoped enclaves on a single offline device, provable from a public key alone. 36 claims.
Read the application →Privacy-Preserving Routing and Clearance-Gated Retrieval
Nothing reaches a brain unclassified, and absence is indistinguishable from nonexistence.
This family covers the complete inbound trust boundary of a sovereign intelligence system, from the moment a request arrives to the moment data is returned. Every request is classified by sensitivity, held behind an egress firewall and prompt-injection inspection, and separated into trusted instructions and untrusted data before it can reach a model, while retrieval is tagged with a clearance ceiling and access descends to the individual row, column, and skill, gated per voiceprint rather than per login. It is hard to design around because the filed inventions do not sit at one checkpoint but bind classification, routing, injection containment, clearance-ceiling retrieval, and per-voiceprint revocation into a single perimeter, where a query that lacks clearance receives the same response as a query for content that never existed.
- A hospital runs one on-premise assistant across clinical, research, and administrative data, and a clinician without the right clearance is told nothing was found rather than that a record was withheld.
- A defence or intelligence deployment keeps compartmented material invisible below its clearance ceiling, so the existence of a classified file is never disclosed by the pattern of what a query returns.
- A bank contains an attacker who has hijacked a session or a document channel, because untrusted data can never acquire instruction authority and every routing decision is written to a tamper-evident record.
- A law firm or regulator revokes a departing employee's voiceprint and has every read that person previously made retroactively flagged in the ledger and excluded from any future composition.
- A government department gates each deployable skill behind a clearance level and forces fresh verbal re-authentication on a stale session, so a forgotten unlocked terminal cannot invoke a sensitive capability.
Anyone building sovereign or on-premise AI has to solve the inbound perimeter, and this family has already filed the ground on which that perimeter is built. A credible sovereign system cannot let raw requests reach a model unclassified, cannot allow retrieved context to carry hidden instructions, and cannot answer a below-clearance query in a way that betrays that classified material exists, yet those are precisely the behaviours the filed inventions claim, right down to gating access per voiceprint rather than per login and making revocation reach backwards through the audit record. The pieces are not severable, because the value comes from binding classification, injection containment, clearance-ceiling retrieval, and per-voiceprint revocation into one boundary, so a competitor who reimplements any serious version of it lands inside filed claims. Filed applications establish priority dates and form a published prior-art record, which is why the sensible path for a serious builder is an inbound licensing conversation rather than a redesign that still reads onto the same ground.
If you are building a sovereign or on-premise AI perimeter, the classification, injection containment, and clearance-gated retrieval you need is already filed here, so talk to us about a licence before you build onto it.
The 6 filed applications in this family
Trust Agent
Privacy router and tamper-evident audit ledger.
Read the application →Sovereign Security Framework
Egress firewall, injection detection, per-tool rate limits.
Read the application →Privacy-Preserving Sovereign RAG
Clearance-ceiling retrieval. Absence is indistinguishable from nonexistence.
Read the application →Granular Row/Column ACL
Per-voiceprint revocation retroactively invalidates prior access.
Read the application →Per-Skill Clearance-Gated Execution
Verbal re-authentication on stale sessions. Five clearance levels.
Read the application →Sealed Trust-Tagged Instruction-Data Separation with Capability-Gated Injection Containment
Instructions and data kept cryptographically separate to contain prompt injection. 13 claims.
Read the application →Post-Quantum Audit and the Open Audit Record
Every action sealed to a post-quantum, regulator-walkable audit record on operator-held keys.
This family turns the audit trail of a sovereign AI system into a cryptographic object that outlives the vendor and the current era of computing. Every tool invocation, decision and routing step is signed with the post-quantum ML-DSA-65 algorithm under FIPS 204 and threaded into a causally linked decision-lineage DAG, so a regulator can take any single output and walk it all the way back to the originating prompt and operator identity. Because the record format is vendor-neutral, the verifier runs offline inside a single self-contained browser file, and the audit witness sits in its own trust domain separate from the layer that proposes actions, there is no point in the chain a competitor can substitute without landing on filed ground.
- A financial regulator receives a bank's on-premise AI decision and walks the signed lineage DAG back to the exact prompt, model routing and operator who authorised it, with no access to the bank's network.
- A defence contractor proves to an auditor that an air-gapped intelligence workflow was never tampered with, verifying the entire post-quantum chain offline from a single browser file on the operator's own hardware.
- An NHS trust demonstrates to the Information Commissioner that every clinical AI recommendation carries an ML-DSA-65 attestation that will remain verifiable long after a cryptographically relevant quantum computer arrives.
- A government department running two different sovereign AI vendors federates their audit trails through one vendor-neutral record format, so a single conformant verifier reads both chains without vendor-specific logic.
- A law firm shows that its case-analysis AI cannot silently bypass policy, because the action-proposing layer, the policy perimeter and the signed audit witness each run in separate hardware boundaries.
Any organisation building sovereign or on-premise AI eventually has to answer one question from its regulator: prove what the system did, on keys you control, in a way that survives both a vendor's disappearance and the arrival of quantum computing. The moment a competitor tries to answer it properly they reconstruct this family, a post-quantum signed ledger, a causally linked lineage graph that walks back to the originating prompt, a vendor-neutral record format, an offline browser-resident verifier and a separated audit-witness domain, because those are the only architecture that actually satisfies an independent auditor rather than merely logging events. These are filed UK applications with established priority dates, part of 104 filed applications and 2,340 claims owned by Mickai LTD, and they sit precisely where the verification, cryptography and trust-separation ground converge. A serious buyer of sovereign AI does not route around this; they find they need a licence to it, which is where the conversation with us begins.
If your sovereign AI has to prove to a regulator what it did, on your own keys and in a form that survives quantum computing, this is the filed ground you will need to license.
The 5 filed applications in this family
Quantum-Safe Attestation (ML-DSA-65)
FIPS 204 signed tool-invocation ledger.
Read the application →Decision Lineage and PQ-Signed Audit Ledger
DAG of decisions, causally signed, regulator-verifiable.
Read the application →Open Inter-Vendor Audit Record Format
Vendor-neutral signed audit schema with cross-vendor trust-bundle federation. 20 claims.
Read the application →Browser-Resident Offline Post-Quantum Verifier
Wasm-compiled ML-DSA verifier with no-network invariant. 20 claims.
Read the application →Trust-Domain Externalisation Pattern
Three-domain separation for independent verification of AI execution authority. 20 claims.
Read the application →Voice-Biometric Gating, Typed Actions and Reversible Execution
Every sensitive action is voice-gated, typed, simulated, and reversible by construction.
This family governs the moment an AI system is about to act. It makes every sensitive action a typed, hardware-bound entity that declares its own inverse at definition time, requires a fresh, replay-resistant voice-biometric match before it can dispatch, simulates its effect against the target state so the operator reviews a diff before committing, and can be retroactively undone through a tracked compensating-inverse chain. Because authorisation, reversibility and on-device behavioural forecasting are woven into the action schema itself rather than bolted on as an outer policy layer, an implementer cannot reach comparable safety without rebuilding on the same filed primitives, and cannot strip any one of them without collapsing the guarantees the other five depend upon.
- A defence or aerospace operator confirms a weapons-release or evacuation instruction by live voice inside a pressurised cabin or EVA suit, where cold-induced and helmet distortion would defeat conventional speaker verification.
- A bank blocks a fraudulent transfer because the payment action demands a fresh voice-biometric match bound to that exact payment digest, so a replayed or misdirected authorisation cannot move the money.
- A hospital lets a clinician commit a medication change only after a dry-run simulation shows the resulting record diff, so the effect is reviewed before it is written.
- A law firm retroactively unwinds a mistaken bulk document action through the tracked compensating-inverse chain, restoring the prior state without a manual rebuild.
- A critical-infrastructure operator has the gating thresholds tighten automatically when on-device forecasting predicts an out-of-pattern session, raising the bar exactly when risk rises.
Any organisation building sovereign or on-premise AI that is allowed to take consequential actions, moving money, deleting records, signing contracts, commanding hardware, must solve the same problem this family already occupies: how to prove a specific living person authorised a specific action, how to undo that action cleanly if it was wrong, and how to be sure of the effect before it commits. The filed inventions do not describe one feature; they describe the interlocking substrate, a typed-action ontology whose every action carries a declared inverse, deterministic voice gating bound to that ontology, dry-run simulation over the same typed actions, compensating rollback over the same declared inverses, and forecast-driven thresholds that tune the gates, so a competitor who adopts even a fraction of the pattern is reading directly onto claims with a UK priority date. This is the ground a diligence lawyer or a security auditor will insist a serious sovereign-AI product stands on, which is precisely why the sensible move is an inbound licensing conversation rather than an attempt to invent around six mutually reinforcing filings at once.
If your on-premise AI is permitted to act on the real world, the authorisation, simulation and reversible-undo layer it needs is already filed here, so the efficient path is to license it.
The 6 filed applications in this family
Voice-Biometric Extreme-Environment Verification
Cold, pressurised, and spacesuit-adjusted speaker match.
Read the application →Typed-Action Ontology
Hardware-bound actor identity with inverse-action schema.
Read the application →Voice-Gated Deterministic Tool Invocation
Biometric gating on every sensitive agent action.
Read the application →First-Class Actions with Compensating Rollback
Every action has a tracked inverse; retroactive undo.
Read the application →Pre-Commit Dry-Run Simulation
Actions simulate before they execute. User reviews the diff.
Read the application →Forecast-Driven Adaptive Gating Thresholds
On-device time-series forecasting tightens or relaxes gates based on predicted owner behaviour. 25 claims.
Read the application →Agent-Safety and the Sentinel Action Interceptor
Destructive AI-agent failure is made impossible by construction.
This family places an enforced perimeter around every autonomous AI agent, so that an agent cannot take a destructive or unauthorised action without that action first being intercepted, classified, gated, and sealed into a post-quantum signed record. The Sentinel interceptor tags each agent process at launch without touching its source and routes every filesystem write, shell command, version-control operation and outbound model prompt through a signing daemon in a separate trust domain, while its companion primitives seal the agent's plan-execute-verify cycle, attest the model before it is allowed to run, gate each self-improving skill mutation behind a fresh voice-biometric match and a hardware-signed mutation ledger, record the reasoning behind each output, diff a candidate policy against live decisions before it is enforced, and refuse consent-less generative edits. It is hard to design around because the safety guarantee is structural rather than advisory: the perimeter lives in a trust domain the agent cannot reach, and every gate produces its own signed, offline-verifiable proof that the boundary held.
- A hospital trust runs an autonomous coding agent against clinical systems knowing that a destructive shell command or a mass deletion is intercepted and held in a copy-on-write shadow layer before it can touch a live patient record.
- A bank confines an autonomous agent inside a sealed plan-execute-verify ledger, so a supervisor and an auditor can confirm offline that the agent did exactly what it planned and that every step was checked.
- A defence contractor attests each model's provenance and integrity before any inference is allowed to run, so a tampered or substituted model on an air-gapped workstation is refused rather than trusted.
- A self-improving agent can only rewrite its own skills after a fresh voice-biometric match, and every mutation is written to a hardware-signed ledger, so an agent cannot silently evolve a new capability nobody authorised.
- A media organisation lets a generative tool retouch imagery while the consent-gated inpaint refuses to edit a depicted person without consent on record and seals every refusal for later audit.
Anyone building sovereign or on-premise AI that lets an agent act, and not merely answer, has to cross this filed ground. The moment an autonomous agent can write a file, run a command, place an order, rewrite its own skills or edit an image, the operator needs an enforced boundary the agent cannot bypass and an offline record that proves what the boundary did, which is precisely the interceptor, the sealed plan-execute-verify ledger, the pre-inference model attestation, the hardware-attested skill-mutation gate, the verifiable reasoning ledger, the policy-shadowing diff and the consent-gated refusal set out here. There is no partial route. Bolting logging on after the fact does not deliver structural prevention, and running the gate inside the agent's own process does not deliver independent proof, so a competitor either builds the perimeter as its own trust domain with post-quantum signed evidence, in which case it reads onto these applications, or it ships an agent that can fail destructively with nothing to show a regulator. That is why the sensible move is an inbound licensing conversation rather than a redesign attempt.
If your roadmap includes an AI agent that takes real actions or improves itself, it is faster to license the perimeter that makes destructive failure impossible by construction than to rebuild it around filed claims.
The 7 filed applications in this family
Hardware-Attested Skill Mutation in Self-Improving Agents
Per-mutation voice-biometric gating with hardware-signed mutation ledger. 28 claims.
Read the application →Agentic Sealed Plan-Execute-Verify Ledger
An agent's plan, each executed step, and each verification sealed into one ledger. 15 claims.
Read the application →Pre-Inference Model Provenance and Integrity Attestation
A model's provenance and integrity attested before any inference is allowed to run. 14 claims.
Read the application →Verifiable Reasoning Ledger
Each step of a model's reasoning recorded in a signed, independently checkable ledger. 13 claims.
Read the application →Policy Shadowing and Compliance Diff Engine
A candidate policy run in shadow against live decisions to diff compliance impact. 12 claims.
Read the application →Consent-Gated Person-Edit-Refusing Generative Inpaint with Sealed Refusal
Generative inpainting refuses to edit a person without consent and seals the refusal. 11 claims.
Read the application →Universal Action Interceptor for Autonomous Coding Agents with Post-Quantum Signed Audit
Supervises autonomous AI coding agents and seals every action under a post-quantum key. 26 claims.
Read the application →Sovereign Generative Provenance and Watermarking
Every generated frame, pixel, token, note, and line carries verifiable cryptographic provenance.
This family binds a verifiable, post-quantum cryptographic seal to the output of a generative system at the finest granularity of each modality, per pixel block for imagery, per frame for video, per buffer for live voice, per token for translation, per line for synthesised code, per voxel and spawn event for game worlds, per utterance for cloned voices, and per iteration for refined assets, every seal held under a key that lives in operator-controlled hardware. The manifests hash-link stage to stage and iteration to iteration, so a regulator, licensee, or court can walk any single output element back through every transform to the originating prompt and reasoning trace, and can localise tampering to the exact frame, block, or line at which it entered. It is hard to design around because the provenance is generated at the moment of synthesis, inside the signing pipeline, rather than stamped on afterwards, so an output either carries the operator seal from birth or it does not carry one at all.
- A defence broadcaster verifies within one audio buffer that an inbound live voice call is a genuine attested speaker rather than a real-time deepfake, with latency held under fifty milliseconds.
- A hospital confirms that a generated or enhanced medical image has not had a lesion inserted or removed, localising any tampering to the individual pixel block before the scan informs a diagnosis.
- A film studio clears a derivative work by walking an iteratively refined generative asset back through every accepted and abandoned branch to its first generation, settling AI-output authorship for copyright.
- A bank's software team ships regulated trading code with per-line lineage from the operator's spoken intent, exporting a regulator-grade software bill of materials suitable for the standards that govern safety-critical systems.
- A music rights body accepts a released track as provenanced under a three-of-three watermark quorum across waveform, metadata, and symbolic sheet music, with an AI-training opt-out flag enforceable at dataset ingestion.
Anyone building a sovereign or on-premise generative system faces the same non-negotiable customer demand: prove what your model produced, prove nobody altered it, and prove it offline without trusting the vendor's servers. Mickai has filed on the mechanism that satisfies that demand at the level of the individual generated element across every modality a buyer will ship, imagery, video, live voice, cloned voice, avatars, music, code, translation, design systems, and game worlds, each seal bound to a key the operator holds in their own hardware and each output walkable back to its originating prompt. A competitor can reach for container-level or file-level watermarking, but the moment a regulator, a court, or an enterprise procurement team asks for per-frame, per-pixel, per-token, or per-line attestation that survives editing, transcoding, and re-encoding, they land on this filed ground. Because these applications are published and establish priority dates, they form a prior-art record that a rival cannot quietly reinvent, which is precisely why a serious sovereign-AI builder ends up talking to Mickai rather than around it.
If your sovereign or on-premise system generates anything a regulator, court, or customer may later need to authenticate, this filed family is the ground you build on, so let us open a licensing conversation.
The 15 filed applications in this family
ChatClone Anti-Deepfake Sovereign Clone
Per-clone signing, consent classes, dual signatures.
Read the application →Attestable Avatar Rendering
Per-frame signed avatars with liveness nonces.
Read the application →AudioSeal Dual-Layer Watermark
Spread-spectrum plus ML-DSA cryptographic audio provenance.
Read the application →Sovereign 8K Video Provenance Chain Across Upscale and Interpolation
Continuous cryptographic chain across generation, super-resolution, frame interpolation, and encoding.
Read the application →Sovereign Voice-Cloning Consent-Class Framework with Per-Utterance Attestation
Every cloned utterance bound at synthesis to a specific authorised consent class.
Read the application →Sovereign Generative Game-World Provenance with Per-Voxel and Per-Object Signing
Per-voxel, per-spawn-event, and per-biome cryptographic signing of a real-time generative game world.
Read the application →Sovereign Code-Synthesis Audit Trail with Line-Level Lineage from Spoken Intent
Per-line cryptographic lineage from operator utterance to AI-generated source code.
Read the application →Sovereign Multi-Modal Avatar with Per-Modality Watermarking and Cross-Modality Consistency Verification
Independent watermarks across face, video, audio, and lip-sync, bound under one operator signing key.
Read the application →Sovereign Music Provenance via Triple Watermark across Waveform, Metadata, and Symbolic Sheet Music
Three independent watermarks across three orthogonal representations of the same musical work.
Read the application →Sovereign Edit-Distance Tracking with Per-Iteration Signed Lineage for Iteratively Refined Generative Assets
Per-iteration domain-distance metric paired with a signed iteration tree retaining abandoned branches.
Read the application →Sovereign Generative Design System Provenance with Signed Design Tokens and Accessibility-Tree Lineage
Generated UI components bound to a signed design-token graph, component genealogy, and accessibility-tree.
Read the application →Sovereign Translation Provenance with Per-Token Bilingual Lineage and Confidence Attestation across Languages
Per-token signed lineage across 450+ living languages, with confidence and dictionary corroboration scores.
Read the application →Sovereign Per-Pixel Image Authenticity Verification via Merkle-Tree Signing on Generated Imagery
Per-pixel-block Merkle signing with localised tamper detection at sub-image granularity.
Read the application →Sovereign Real-Time Streaming AudioSeal for Live Voice Synthesis with Rolling-Window Signatures
Per-buffer rolling-window signature chain verifiable within one buffer of arrival, latency under 50 ms.
Read the application →Beat-Synchronised Multimodal Artifact Binding
Audio, visual, and timing artefacts bound together on a shared beat under one seal. 9 claims.
Read the application →Sovereign Generative Composability and Decision-Support Binding
Every edit is a signed, reversible node; every recommendation travels bound to its disclaimer.
This family treats every act of generative composition as a first-class, cryptographically sealed node: each document edit, image layer, building revision, transformation stage, video join, and generated game asset is captured with its inputs, carries a declared inverse where relevant, and is hash-linked into an operator-signed ledger that a third party can replay from source. It extends the same discipline to reasoning, so what-if and society-scale simulations are sealed to their seed and inputs to reproduce exactly, game balance is attested deterministically, and decision-support output is bound to its governing disclaimer so the two cannot be separated without breaking the seal. It is hard to design around because the alternative, storing only the finished artefact, cannot answer the question every regulated buyer now asks, which is how an output was reached and whether it can be undone, reproduced, or trusted, and this ground answers that at the level of the individual edit, pixel, revision, and simulation run rather than the whole file.
- A hospital trust runs an on-premise what-if model for winter bed capacity and hands the regulator a sealed run that reproduces exactly from its seed, with the decision-support guidance arriving permanently bound to its clinical-limitation disclaimer.
- An architecture and engineering practice traces any element of a finished building model back through every signed revision to the originating brief, satisfying a client audit and a building-control review without reconstructing the project by hand.
- A bank's advisory desk issues a portfolio recommendation whose disclaimer cannot be stripped in downstream forwarding, so a later suitability challenge is met with the sealed record showing exactly what limits were declared at the moment of advice.
- A film studio assembles a feature from generated and captured clips and proves to an insurer and an IP-clearance counterparty that the delivered timeline was not reordered, spliced, or substituted, joint by joint.
- A defence or civil-planning team runs a seed-sealed society and resource simulation and lets an independent reviewer reproduce the entire trajectory from the stated starting conditions, so the policy conclusion rests on a run anyone can rerun.
Anyone building sovereign or on-premise AI that composes or advises, rather than merely chats, has to touch this ground. The moment a system lets a user edit a document, composite an image, revise a model, cut a video, generate a game, run a scenario, or issue a recommendation, the regulated customer needs to prove after the fact how the result was reached, whether it can be undone, whether it reproduces, and what limits governed the advice. Mickai has filed the primitives that make each of those provable at the granularity of the individual edit and run: type-safe inversion for retroactive section-level undo, source-anchored transformation lineage, deterministic seed-sealed simulation, and disclaimer binding that survives forwarding. A competitor can rebuild a generative feature, but the sealed, replayable, reversible, disclaimer-bound record around it is the part their own auditors and regulators will demand, and that record is exactly what these filed applications describe as prior art. That is why the conversation comes inbound: the capability is easy to ship and the accountable version of it is already on the register in Mickai's name.
If your sovereign AI edits, composites, simulates, or advises and has to prove it afterwards, the accountable version of that capability is already filed here, and the shortest path to shipping it is a licence.
The 10 filed applications in this family
Sovereign Document Composability with Type-Safe Inversion for Retroactive Section-Level Undo
Every edit is a typed action with a declared inverse, signed and inversion-propagated through a dependency graph.
Read the application →Sealed Layered-Edit Graph for Non-Destructive Image Compositing
Every compositing edit is a node in a signed, replayable layer graph. 20 claims.
Read the application →Sovereign Building-Design Provenance
Cryptographic lineage from design intent through every revision of a building model. 20 claims.
Read the application →Source-Anchored Sealed Transformation Lineage
Every transformation stage hash-links back to the original source artefact. 20 claims.
Read the application →Continuity-Chained Sovereign Video Assembly
Assembled video clips chained in signed continuity order with verifiable joins. 20 claims.
Read the application →Sealed Agent-Built-Game Provenance
Every asset and rule an agent generates for a game is signed into a provenance record. 20 claims.
Read the application →Sealed Deterministic What-If Simulation
What-if scenarios run deterministically and sealed so results are reproducible. 12 claims.
Read the application →Auditable Deterministic Game-Balance Attestation
Game-balance rules attested deterministically so outcomes are auditable. 9 claims.
Read the application →Sealed Deterministic Decision-Support Disclaimer Binding
Decision-support output bound to its disclaimer in a sealed, deterministic record. 12 claims.
Read the application →Seed-Sealed Reproducible Society and Resource Simulation
Society and resource simulations sealed to a seed so any run reproduces. 14 claims.
Read the application →Sovereign Silicon, the Poseidon SoC and Portable Identity
The silicon's cryptographic identity is the operator's identity, personalised at first power-on.
This family moves the root of trust off the manufacturer and onto the operator, so a sovereign AI accelerator ships with its cryptographic identity store empty and performs a one-shot irreversible burn of an operator-generated key only at first power-on at the customer's premises. From that moment the silicon carries the operator's complete Mickai state, verifies each host against an operator-signed policy before it will unseal, accumulates its own tamper-evident audit chain as it travels between machines, bootstraps against the operator's own distribution endpoint, and can run indefinitely air-gapped. It is hard to design around because the inversion is structural rather than a setting: the chip refuses to be anyone but the operator, and the same signed provenance discipline reaches up to the model alias layer, where friendly model names resolve to signed weights, training corpus, and fine-tuning recipe that a holder of the operator public key can verify offline.
- A defence agency issues each analyst a personalised accelerator bound to the analyst's own key, so a lost or stolen unit is inert to anyone else and a compromised workstation is survived by moving the silicon to a clean host and resuming in seconds with no state loss.
- A hospital trust runs clinical models on operator-owned silicon that refuses to unseal patient state onto any machine failing its signed trusted-boot and TPM policy, keeping inference inside the estate with a continuous on-silicon audit trail for the regulator.
- A law firm lets a partner carry a complete matter context on a single removable unit that survives an arbitrary number of host insertion and removal cycles, with the host-side copy cryptographically zeroised on removal and privilege preserved end to end.
- A bank in a jurisdiction with strict data-residency rules provisions accelerators whose bootstrap trust anchor is a distribution endpoint under the bank's exclusive control, so units update on the bank's terms and otherwise operate air-gapped with local-only integrity checks.
- A public-sector body procuring sovereign AI can prove, offline and from the operator public key alone, that a given output traces through a named model alias to specific signed weights, corpus, and fine-tuning recipe, satisfying auditors without any call to a vendor registry.
Anyone building sovereign or on-premise AI has to answer a single question, who owns the trust anchor, and every honest answer walks straight into this filed ground. If the chip's identity is set at fabrication or held by a vendor, it is not sovereign; the moment a designer moves that identity to the operator and burns it at first power-on, they are inside the operator-personalised silicon root of trust that Mickai filed. The neighbouring claims close the obvious escapes: making the accelerator removable invites the host-acceptance attestation inversion, letting operator state follow the silicon invites the on-silicon migration and accumulating audit chain, cutting the vendor out of updates invites the operator-controlled bootstrap with air-gap mode, and giving customers verifiable model names invites the signed alias layer that binds identifier to weights, corpus, and recipe. These are filed UK applications, so they already establish priority dates and form a published prior-art record that a competitor's later filings must contend with, which is precisely why the sensible move is an inbound licensing conversation rather than a design-around that keeps colliding with the same five inventions.
If your sovereign accelerator personalises its identity to the operator, survives a host swap, or lets a customer verify a model name against its weights offline, that ground is filed here, so talk to us before you build it.
The 5 filed applications in this family
Operator-Personalised Silicon Root of Trust at First Power-On
Sovereign AI accelerator chip personalised to operator keys at first power-on, not at fabrication. 20 claims.
Read the application →Host-Acceptance Attestation Inversion for Removable Sovereign AI Accelerator
Removable accelerator verifies the host against operator policy before unsealing state. 20 claims.
Read the application →Sovereign Intelligence Operating System State Bundle Migration with Persistent On-Silicon Audit Chain
The operator's full Mickai state travels on the silicon; audit chain accumulates across hosts. 20 claims.
Read the application →Operator-Controlled Distribution Endpoint Bootstrap with Air-Gap Operating Mode
The Mickai SoC bootstraps against the operator's own server; runs indefinitely air-gapped. 20 claims.
Read the application →Sovereign Model Alias Layer with Cryptographic Provenance Binding of Human-Readable Model Identifiers to Weight Artefacts, Training Corpus, and Fine-Tuning Recipe Under a Post-Quantum Signature
Binds friendly model names to signed weight + corpus + recipe + runtime hashes, offline-verifiable from the operator public key alone. 35 claims.
Read the application →Offline Operation, Air-Gap Attestation and Sealed Appliances
Prove a device stayed offline for a stated interval, from a public key alone.
This family turns the claim that a machine was offline into something a third party can verify from the device public key alone, with no network, no certificate authority, and no vendor in the trust path. Operator-personalised silicon emits a continuous, hash-chained attestation of every network interface and process, pre-loads audit anchors before deployment so a workstation can run air-gapped for months and replay end to end on reconnection, and seals ordinary offline work, browsing, printing, capability gating and energy-aware scheduling into the same signed record. It is hard to design around because the guarantee is generated inside the hardware root of trust at each tick rather than asserted afterwards, so remote-attestation, tamper-evident-logging and time-stamping approaches that all assume a connected verifier cannot reproduce the offline-continuity property they are meant to prove.
- A submarine or forward operating base runs a sovereign AI workstation disconnected for a full deployment, then replays a signed continuity chain to the issuing authority that proves the device transferred no traffic across any boundary for the entire interval.
- A nuclear-engineering or classified ministerial facility emits a hardware-signed air-gap token on every tick, giving the regulator cryptographic certainty that a controlled network never touched an external one during any specified subwindow.
- A bank enforcing a Chinese wall or anti-money-laundering isolation proves offline that a segregated analytics machine ingested and emitted nothing across the boundary throughout the review period.
- A disaster-relief or off-grid clinic serves sealed survival and reference knowledge from an appliance scheduled around harvested solar and stored charge, with each print and each display mode sealed for later audit and no network dependency.
- A defence or intelligence operator prints and browses inside the sovereign application entirely offline, and can later prove exactly what was printed, on which device, and which outbound destinations were reached or blocked.
Anyone building sovereign or on-premise AI ends up making the same promise this family already occupies: that the system runs on hardware the customer owns, offline, air-gapped when required, and that the offline state is provable rather than asserted. Every serious buyer in defence, nuclear, intelligence and regulated finance now asks for exactly that proof, and the honest ways to deliver it all land inside filed Mickai ground: continuous hardware-emitted attestation of interface and process state, pre-loaded audit anchors that survive months of disconnection, capability gating and energy-aware scheduling sealed into the same chain, and a continuity demonstrator verifiable from the device public key with no network, no certificate authority and no vendor in the trust path. The standard remote-attestation, tamper-evident-logging, measured-boot and time-stamping mechanisms all require a connected verifier, which is precisely the thing an air-gapped deployment cannot have, so they cannot reproduce the property without reading onto these applications. That corner is filed and forms part of the published prior-art record, which is why a competitor reaching this ground has a reason to open a licensing conversation with us rather than around us.
If your roadmap requires proving to a regulator that a device stayed offline, that proof runs through filed Mickai ground, and the right next step is a licensing conversation with us.
The 12 filed applications in this family
Sovereign AI Inference Inside Confidential-Compute Enclaves
Operator-held attestation keys exclude the cloud vendor from the trust path. 24 claims.
Read the application →Sovereign Air-Gap Workstation Bootstrap with Pre-Loaded Audit Anchors for Submarine and Forward-Deployed Operations
Defence-grade bootstrap with pre-loaded audit anchors that survives months of disconnection.
Read the application →Continuous Air-Gap Attestation Token from Operator-Personalised Silicon for Classified-Environment Compliance
Hardware-emitted attestation chain proves air-gap status across any specified subwindow.
Read the application →Egress-Gated Sealed In-Application Browsing
In-app browsing routed through a signed egress gate that records every outbound request. 17 claims.
Read the application →Hardware-Profile-Sealed Capability Gating
Available capabilities gated against a sealed profile of the host hardware. 15 claims.
Read the application →Sealed Offline Print-Job Provenance
Every offline print job recorded and signed without any network dependency. 15 claims.
Read the application →Offline Sovereign Hardware-Rebuild Advisor
Offline guidance for rebuilding or upgrading sovereign compute hardware. 15 claims.
Read the application →Solar and Energy-Harvest-Aware Sealed Sovereign Compute Scheduling
Compute scheduled around harvested solar and stored energy, sealed for audit. 15 claims.
Read the application →Dual-Surface Energy-Bound Knowledge Display
A dual-surface display that presents knowledge within a bound energy budget. 12 claims.
Read the application →Sealed Off-Grid Survival Knowledge Appliance
A sealed appliance serving survival knowledge entirely off-grid. 13 claims.
Read the application →Inkless Energy-Aware Sealed Sovereign Printing
Inkless printing scheduled to an energy budget and sealed for provenance. 14 claims.
Read the application →Method and System for Cryptographically Demonstrating Continuous Offline Operation of a Sovereign Computing Device Across a Specified Interval Without Reliance on a Network-Connected Verifier
Proves a sovereign device was offline for a stated interval, verifiable from the device public key alone with no network in the trust path. 35 claims.
Read the application →Sovereign Memory, Inheritance and Cryptographic Erasure
Memory is owned, bequeathed under seal, and provably forgotten on request.
This family governs the whole life of a person's memory inside a sovereign intelligence system, from custody while they live, through inheritance when they die, to provable erasure when they ask to be forgotten. An owner seals envelopes of assets, credentials and instructions that open only on a trustee multi-signature plus a dead-man's switch, a verified successor inherits the sealed knowledge, permissions and audit lineage under signed, trustee-attested write-back rather than a raw file handover, heirs receive exactly the memory and oral history the owner chose under clearance-tagged release, and an erasure request produces a signed tombstone proving both the dataset fragments and the learned model weights were removed without ever re-disclosing the erased data. It is hard to design around because each stage binds to the same operator-personalised silicon and the same post-quantum audit chain, so inheritance, bequest and erasure are all cryptographically provable and revocable, not merely asserted by policy.
- A private bank holds a client's sealed credentials and estate instructions that no solicitor ever sees in plaintext, released to the executor only on a trustee multi-signature and confirmation of death.
- A hospital honours a patient's right-to-erasure request and hands the regulator a signed tombstone proving the patient's records were removed from both the training set and the model weights, without re-exposing the data.
- A defence or intelligence operator's successor inherits the sealed knowledge, clearances and full decision lineage of a departed officer under signed, trustee-attested write-back that itself remains auditable and revocable.
- A family office preserves a founder's personal archive and oral history and bequeaths it to a named heir, with each recollection gated by a clearance tag so sensitive material is released exactly as the founder intended.
- An enterprise offboards a departing executive by sealing their memory store for a designated successor while cryptographically erasing what policy requires be forgotten, with every step written to the operator's audit chain.
Any organisation building sovereign or on-premise AI eventually confronts the same three obligations this family covers, because they are not features but legal duties: a memory that outlives its owner has to pass to someone, and a regulated system has to be able to prove it forgot. Once you accept that inheritance and erasure must be provable rather than asserted, you are on filed ground. Mickai's applications claim sealed post-mortem activation, signed inheritance write-back to a successor identity, clearance-gated heir bequests of memory and personal archives, and cryptographic proof of both dataset and model-weight erasure under Article 17, all bound to operator-held silicon and one post-quantum audit chain. A competitor can build a delete button, but it cannot build a verifiable proof of erasure or a revocable, auditable inheritance without crossing claims already on the public register, owned by Mickai LTD. That is precisely the point at which the sensible move is an inbound licensing conversation rather than a redesign.
If your roadmap includes digital estates, successor identities or a defensible answer to a right-to-erasure request, this filed family is the ground you will need to license.
The 5 filed applications in this family
Hereditas Post-Mortem Activation
Sealed envelopes, trustee multi-sig, dead-man's switch.
Read the application →Post-Mortem Inheritance Write-Back
Successor identities inherit a sovereign AI estate, with signed write-back.
Read the application →Sovereign Multi-Tenant Forgetting with Cryptographic Proof of Erasure under GDPR Article 17
Signed tombstone records prove dataset and model-weight erasure without re-disclosing the erased data.
Read the application →Heir-Sealed Memory Bequest
Personal memory bequeathed to an heir under a sealed, clearance-gated release. 12 claims.
Read the application →Heir-Sealed Personal Archive with Clearance-Tagged Oral-History Retrieval
A personal archive bequeathed to an heir with clearance-tagged oral-history access. 14 claims.
Read the application →Colocated Sovereign Trading and Verifiable Strategy Attestation
The brain and the order router share one operator-owned chassis; every fill is provable from public data.
This family places the decision model and the exchange order router on a single operator-owned chassis under one memory address space, so the trading signal reaches the order envelope by an in-process call rather than a cloud round trip, and every prospective order is sealed under an operator-held post-quantum key before it leaves the machine. Around that core it builds the full sovereign trading discipline: a cooperative ensemble of role-typed agents that vote on each market event with an always-on tail-risk overlay that can veto, a liquidity-aware concentration cascade that respects resting-liquidity ceilings and preserves idle capital, voice-biometric and bounded auto-execution gates, and a signed trade lineage that ties each fill back to the signal and authorisation that produced it. It is hard to design around because the value is inseparable from the architecture: the moment a competitor separates the brain from the router, or removes the sealed envelope, or drops the public-data reproducibility, it loses the specific latency, provability, and regulator-walkable properties the claims describe.
- A quantitative hedge fund runs its decision model and execution router on one owned server so no order or alpha signal ever transits a third-party cloud, and hands a regulator a backtest that can be re-run against public exchange data alone.
- A regulated proprietary-trading desk gives an auditor a signed lineage that walks any executed fill back through the authorising signal, the ensemble vote, and the operator identity, without disclosing the strategy code.
- A family office confines an automated crypto strategy to a bounded execution envelope with a sealed circuit-breaker, so activity halts and is provably recorded the instant it breaches the configured limits.
- A treasury or asset-allocation team attests cross-market capital deployment against its recorded mandate, letting compliance verify offline that capital moved only where the mandate permitted.
- A defence or sovereign-wealth institution authorises high-value orders behind a fresh voice-biometric match bound to owned hardware, so no position can be opened without the operator's live voice even under full session compromise.
Anyone building an on-premise or sovereign trading system that wants both low decision-to-order latency and independent provability lands on this filed ground by necessity. The obvious sovereign design, keep the model and the router on hardware you own so nothing crosses a vendor boundary, is the exact colocation the family claims, and the obvious way to make such a system defensible to a regulator, seal each order under an operator key and publish a backtest that reproduces from public data, is the exact attestation and reproducibility the family claims. The cooperative ensemble with a tail-risk veto, the liquidity-aware cascade, the voice-gated and bounded execution, and the signed trade lineage then cover the practical mechanisms a serious desk needs to run and to prove what it ran. These 104 filed UK applications, 2,340 claims in total, form a published prior-art record with established priority dates, so a competitor cannot quietly ship the same architecture and cannot easily invent around a moat that mirrors the only sensible way to build the thing. That is precisely the position that turns a build decision into an inbound licensing conversation.
If your sovereign trading roadmap puts the model and the order router on the same owned box and promises regulators a provable audit trail, that architecture is already filed here, so the efficient path is to license it rather than design around a published priority record.
The 11 filed applications in this family
Multi-Agent Simulation as Qualitative Predictive Gating Layer
Sandbox simulates counterparty reactions before any sensitive action dispatches. 25 claims.
Read the application →Verifiable-From-Public-Data Strategy-Validation Backtest
Backtest reports anyone can verify against public exchange data. 20 claims.
Read the application →Sovereign Operator-Owned Subscriber-List Durability under Ephemeral Serverless Runtime
Newsletter subscriber list lives on operator hardware, baked into the deployment artefact. 20 claims.
Read the application →Colocated Frontier LLM and Exchange Execution Router on Operator-Owned Chassis
Trading workstation that hosts the AI brain and the order router on the same operator-owned chassis. 25 claims.
Read the application →Cooperative Multi-Agent Trading Ensemble with Role-Typed Routing and Tail-Risk Overlay Veto
Twenty role-typed agents vote on every market signal; tail-risk overlay can veto. 20 claims.
Read the application →Liquidity-Aware All-In Concentration Cascade with Idle-Bankroll Preservation
Bankroll sizing rule that respects liquidity ceilings and preserves idle capital across cycles. 20 claims.
Read the application →Sealed Gated-Execution Trade Lineage
Every trade passes a gate and is recorded in a signed execution lineage. 13 claims.
Read the application →Hardware-Profiled Reproducible Backtest
Backtests bound to a sealed hardware profile so results reproduce exactly. 12 claims.
Read the application →Cross-Market Sealed Capital-Allocation Attestation
Capital allocation across markets attested and sealed for independent verification. 11 claims.
Read the application →Voice-Biometric-Gated Order Authorisation
Trading orders authorised only on a fresh voice-biometric match. 11 claims.
Read the application →Bounded Auto-Execution Envelope with Sealed Circuit-Breaker
Automated execution confined to a bounded envelope with a sealed circuit-breaker. 12 claims.
Read the application →Fleet Federation, Embodied Robotics and Physical Actors
Every device and every actuator attests to the owner's key, never a master node.
This family extends sovereign attestation from a single machine out across a fleet of devices and down into the joints of a physical robot, with the owner's key, never a master node or a vendor key, as the sole root of authority. A user's phone, laptop, watch, and home hub coordinate through trust-on-first-use enrolment the owner signs, workflows fork and merge like Git branches with multiple owners contributing signed changes that reconcile deterministically, and every actuator on an embodied robot carries its own hardware signing element that seals each commanded motion into a per-tick decision-lineage ledger. It is hard to design around because the invention is not a feature bolted onto a controller but the identity model itself: authority flows from an operator-held key through federation, workflow, and physical motion, so any competing scheme must either re-centralise on a master node or leave motion unattested, and the 10 Hz autonomy-mode chain makes who was in control at any wall-clock instant a provable fact rather than a log entry.
- A hospital robotics team can prove to a medical-device regulator exactly which actuator moved a surgical arm and under whose authority for any millisecond of a procedure, because every joint motion is signed to a per-actuator key and chained to a high-level intent.
- A defence integrator running a fleet of forward-deployed devices coordinates state across handset, ruggedised laptop, and field hub with no master node, so capturing one device yields no authority over the others.
- A warehouse automation operator gives its insurer a verifiable 10 Hz timeline of whether each robot was fully autonomous, teleoperated, or in safe-stop at the moment of an incident, settling liability on cryptographic evidence rather than disputed telemetry.
- A multi-organisation research consortium federates workflows across tenant boundaries as signed branches, so each institution contributes changes under explicit consent and conflicts surface for human resolution instead of silent overwrite.
- An industrial manufacturer certifying an autonomous line demonstrates to a safety authority that the active autonomous-policy bundle governing every actuator matches the approved content hash, tick by tick, across the whole cell.
Anyone building sovereign or on-premise AI that touches more than one device, or that reaches into the physical world through actuators, lands on this filed ground the moment they decide the owner, not a cloud control plane, holds authority. The obvious architectures all re-centralise: a fleet needs a coordinator, a robot needs a controller, and the path of least resistance is to make that coordinator the trust root, which is precisely the master-node model this family displaces by making the operator's key the master and every device and every actuator a signer beneath it. Once motion must be attributable for liability, insurance, or regulatory audit, the per-actuator signing of physical actions and the 10 Hz mode-attestation taxonomy become the natural, and now published and priority-dated, way to answer who was in control, so an embodied-AI or fleet builder finds the defensible design space already occupied. Filed as part of 104 UK patent applications carrying 2,340 claims and owned by Mickai LTD, this record is what a competitor's own patent counsel surfaces during clearance, which is what turns a design review into an inbound licensing conversation.
If your fleet or your robot answers to a master node instead of the owner's key, or its actuators move without signing, this filed family is the ground to license before you ship.
The 4 filed applications in this family
Federated Fleet Coordination
Attested multi-device federation with owner-signed enrolment.
Read the application →Branch-Based Workflow and Hive-Mind Federation
Git-style branches with multi-owner signed contributions.
Read the application →Per-Actuator Cryptographic Signing of Physical Actions
Embodied robots sign every motion under per-actuator hardware key. 25 claims.
Read the application →Cryptographic Mode-Attestation of Robot Autonomy State
10 Hz signed attestation across a 7-state autonomy taxonomy for liability and insurance. 27 claims.
Read the application →The Pantheon Bridge, Consensus and Dead-Man Continuity
Sealed actions reach consensus, anchor to public chains, and survive operator incapacity.
This family turns a sovereign AI system's audit record into a chain layer where the blockchain admits and orders only actions that were already sealed off-chain under a post-quantum signature, rather than attesting them after the fact. On top of that consensus rule it settles many application chains to one attestation base layer, anchors the audit root to a public proof-of-work chain for an external immutable witness, binds compliance reporting and token supply to cryptographically attested real usage, and carries the whole structure across post-quantum key migration, cross-chain egress and even operator incapacity through chain-enforced validator succession. It is hard to design around because the property being claimed is architectural, that consensus, settlement, anchoring, compliance, supply, safety and succession are all conditioned on records sealed before they ever reach the network, so a competitor cannot reproduce the guarantee by bolting a ledger on afterwards.
- A listed company gives its auditor and regulator a compliance report mapped to the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001 that is re-verified continuously against on-chain anchors with no cooperation from the company, discharging AI due diligence at IPO.
- A defence or national-security operator proves to an oversight body that a gated AI action was authorised by a majority cross-model safety quorum, because block validity itself required the sealed quorum attestation.
- A bank or clearing house settles the sealed AI-action records of many internal application chains to a single shared attestation base layer, so the more the AI runs, the more is provably settled to one root.
- A healthcare or pharmaceutical group anchors its post-quantum audit root to a public proof-of-work chain, gaining an external immutable timestamp for patient-data and clinical-model decisions without any operator data ever leaving the sovereign chain.
- A regulated counterparty proves to a supervisor that a confidential sealed record satisfies a stated compliance predicate, using a selective-disclosure proof against an on-chain anchor, without disclosing the underlying payload.
Anyone building sovereign or on-premise AI eventually needs its actions to be more than locally logged, they need external witness, cross-organisation settlement, continuous regulator-verifiable compliance and continuity that survives key rotation and the loss of the operator. Every credible route to those properties runs straight through this filed ground, because the inventions do not claim a generic ledger, they claim the specific rule that consensus, settlement, anchoring, supply locking, the safety gate, the bridge and validator succession are all conditioned on records sealed before admission under an operator-held post-quantum key. A rival cannot reach the same assurance by attesting actions after consensus, by anchoring without pre-sealing, or by hardening the bridge and the key migration separately, because the sealed-before-admission structure is the invention rather than an implementation choice. That is why a serious sovereign-AI or chain team reading this file tends to open an inbound conversation, the cleanest path forward is a licence rather than a decade of design-around.
If your sovereign or on-premise AI needs its actions witnessed, settled, continuously compliance-verified and able to survive incapacity, this filed family is the ground to license rather than rebuild.
The 11 filed applications in this family
Consensus Admission and Ordering of Operator-Sealed Post-Quantum Action Records
A proof-of-stake chain that admits and orders AI actions sealed before consensus. 21 claims.
Read the application →Settlement of Sealed Application-Chain Artificial-Intelligence Actions to an Attestation Base Layer in a Native Token
Many AI application chains settle sealed actions to one attestation base layer. 20 claims.
Read the application →Post-Quantum Audit-Root Anchoring to a Public Proof-of-Work Chain
Anchors the post-quantum AI-audit root to a public proof-of-work chain. 19 claims.
Read the application →Continuous Third-Party Verification of Signed AI Compliance Reports Against On-Chain Anchors With Multi-Framework Control Mapping Including ISO/IEC 42001
Regulators continuously verify AI compliance reports against on-chain anchors. 22 claims.
Read the application →Hardware-Attested Earning Validator Appliance With Sealed Capability Gating
A staking validator appliance whose duties are gated by attested hardware. 22 claims.
Read the application →Attestation-Coupled Supply-Locking Mechanism Driven by a Tamper-Evident Usage-Metering Oracle
Binds token supply locking to a tamper-evident meter of attested usage. 20 claims.
Read the application →Live Post-Quantum Consensus-Key Migration of an Operating Proof-of-Stake Chain by a Hybrid Dual-Signed Transition Epoch
Migrates a live proof-of-stake chain's consensus keys to post-quantum without halting. 19 claims.
Read the application →Consensus-Enforced Artificial-Intelligence Safety Quorum as a Block-Validity Rule
Makes a cross-model AI safety quorum a precondition of block validity. 21 claims.
Read the application →Selective-Disclosure Verification That a Sealed Audit Record Satisfies a Compliance Predicate Against an On-Chain Anchor
Proves a sealed record meets a compliance test without revealing it. 22 claims.
Read the application →Post-Quantum-Attested, Sealed Cross-Chain Bridge With Egress Gating
Hardens the cross-chain bridge with sealed, egress-gated messages. 20 claims.
Read the application →Chain-Enforced Validator Succession and Dead-Man Continuity
Transfers a validator's role to a designated heir under sealed dead-man rules. 20 claims.
Read the application →Does Mickai hold patents covering sovereign or on-premise AI?
Yes. Mickai LTD holds 104 filed UK patent applications, approximately 2340 claims, across 13 invention families covering sovereign, on-premise AI. They are on the UK Intellectual Property Office public register, named inventor Micky Irons, and are filed applications that establish priority dates and form a published prior-art record.
Is tamper-evident, cryptographically audited AI patented by Mickai?
Yes. The Open Audit Record, a tamper-evident, post-quantum signed ledger that seals every AI action, is covered, including offline operator-key-bound, audit-sealed module licensing in the 25 June 2026 batch (GB2615041.7 to GB2615043.3).
Does Mickai have a patent on multi-model or multi-brain orchestration?
Yes. Multi-Brain Cooperative Intelligence (GB2608830.2) covers orchestrating specialist brains over a signed internal bus under a deterministic arbiter, with a voice-biometric quorum for high-stakes actions, alongside cross-model consensus gating that requires independent model families to agree before a sensitive action dispatches.
Are post-quantum signed AI decisions covered?
Yes. The portfolio applies post-quantum signature primitives (ML-DSA-65 under FIPS 204) to sign routing and audit decisions, beginning with the Trust Agent privacy router (GB2607309.8) and the sovereign security framework.
Does Mickai hold patents on sovereign generative provenance and audited decision lineage?
Yes. The sovereign generative provenance family covers per-frame, per-pixel, per-token and per-line watermarking and audited decision lineage across every generative modality, each seal bound to an operator signing key.
Are these granted patents or applications?
They are 104 filed UK patent applications, not yet granted. Filed applications establish priority dates and form prior art from their filing dates (from April 2026 onward); grant is a separate, later step.
Who is the inventor and who owns the portfolio?
The named inventor on every application is Micky Irons (Mickarle Sean Junior Wagstaff-Irons). The owner of record is Mickai LTD.
How can the portfolio be independently verified?
Search the UK Intellectual Property Office public register by inventor, Mickarle Wagstaff-Irons. The full application-number ranges are listed on this page.
How can I license Mickai's patented inventions?
If you are building or evaluating sovereign or on-premise AI, the architectural ground you need is likely already filed here. The efficient path is an inbound licensing conversation. Contact press@mickai.co.uk to open a discussion.
The complete portfolio, each with its own dedicated page carrying the full description, related applications, and the brains that implement it. Every number is verifiable on the UK IPO public register.
Show all 104 filed applications
Trust Agent
Privacy router and tamper-evident audit ledger.
Multi-Brain Cooperative Intelligence
Specialist brains, signed envelope bus, voice-biometric quorum.
Sovereign Security Framework
Egress firewall, injection detection, per-tool rate limits.
Adaptive Multi-Tenant OS
Healthcare and enterprise isolation with voice-gated switching.
Privacy-Preserving Sovereign RAG
Clearance-ceiling retrieval. Absence is indistinguishable from nonexistence.
Voice-Biometric Extreme-Environment Verification
Cold, pressurised, and spacesuit-adjusted speaker match.
ChatClone Anti-Deepfake Sovereign Clone
Per-clone signing, consent classes, dual signatures.
Quantum-Safe Attestation (ML-DSA-65)
FIPS 204 signed tool-invocation ledger.
Attestable Avatar Rendering
Per-frame signed avatars with liveness nonces.
Hereditas Post-Mortem Activation
Sealed envelopes, trustee multi-sig, dead-man's switch.
AudioSeal Dual-Layer Watermark
Spread-spectrum plus ML-DSA cryptographic audio provenance.
Typed-Action Ontology
Hardware-bound actor identity with inverse-action schema.
Voice-Gated Deterministic Tool Invocation
Biometric gating on every sensitive agent action.
First-Class Actions with Compensating Rollback
Every action has a tracked inverse; retroactive undo.
Pre-Commit Dry-Run Simulation
Actions simulate before they execute. User reviews the diff.
Decision Lineage and PQ-Signed Audit Ledger
DAG of decisions, causally signed, regulator-verifiable.
Federated Fleet Coordination
Attested multi-device federation with owner-signed enrolment.
Granular Row/Column ACL
Per-voiceprint revocation retroactively invalidates prior access.
Branch-Based Workflow and Hive-Mind Federation
Git-style branches with multi-owner signed contributions.
Per-Skill Clearance-Gated Execution
Verbal re-authentication on stale sessions. Five clearance levels.
Post-Mortem Inheritance Write-Back
Successor identities inherit a sovereign AI estate, with signed write-back.
Open Inter-Vendor Audit Record Format
Vendor-neutral signed audit schema with cross-vendor trust-bundle federation. 20 claims.
Browser-Resident Offline Post-Quantum Verifier
Wasm-compiled ML-DSA verifier with no-network invariant. 20 claims.
Trust-Domain Externalisation Pattern
Three-domain separation for independent verification of AI execution authority. 20 claims.
Per-Actuator Cryptographic Signing of Physical Actions
Embodied robots sign every motion under per-actuator hardware key. 25 claims.
Cryptographic Mode-Attestation of Robot Autonomy State
10 Hz signed attestation across a 7-state autonomy taxonomy for liability and insurance. 27 claims.
Sovereign AI Inference Inside Confidential-Compute Enclaves
Operator-held attestation keys exclude the cloud vendor from the trust path. 24 claims.
Forecast-Driven Adaptive Gating Thresholds
On-device time-series forecasting tightens or relaxes gates based on predicted owner behaviour. 25 claims.
Hardware-Attested Skill Mutation in Self-Improving Agents
Per-mutation voice-biometric gating with hardware-signed mutation ledger. 28 claims.
Cross-Model Consensus Gating
Multiple independent model families must agree before sensitive actions dispatch. 25 claims.
Multi-Agent Simulation as Qualitative Predictive Gating Layer
Sandbox simulates counterparty reactions before any sensitive action dispatches. 25 claims.
Verifiable-From-Public-Data Strategy-Validation Backtest
Backtest reports anyone can verify against public exchange data. 20 claims.
Sovereign Operator-Owned Subscriber-List Durability under Ephemeral Serverless Runtime
Newsletter subscriber list lives on operator hardware, baked into the deployment artefact. 20 claims.
Colocated Frontier LLM and Exchange Execution Router on Operator-Owned Chassis
Trading workstation that hosts the AI brain and the order router on the same operator-owned chassis. 25 claims.
Cooperative Multi-Agent Trading Ensemble with Role-Typed Routing and Tail-Risk Overlay Veto
Twenty role-typed agents vote on every market signal; tail-risk overlay can veto. 20 claims.
Liquidity-Aware All-In Concentration Cascade with Idle-Bankroll Preservation
Bankroll sizing rule that respects liquidity ceilings and preserves idle capital across cycles. 20 claims.
Operator-Personalised Silicon Root of Trust at First Power-On
Sovereign AI accelerator chip personalised to operator keys at first power-on, not at fabrication. 20 claims.
Host-Acceptance Attestation Inversion for Removable Sovereign AI Accelerator
Removable accelerator verifies the host against operator policy before unsealing state. 20 claims.
Sovereign Intelligence Operating System State Bundle Migration with Persistent On-Silicon Audit Chain
The operator's full Mickai state travels on the silicon; audit chain accumulates across hosts. 20 claims.
Operator-Controlled Distribution Endpoint Bootstrap with Air-Gap Operating Mode
The Mickai SoC bootstraps against the operator's own server; runs indefinitely air-gapped. 20 claims.
Sovereign 8K Video Provenance Chain Across Upscale and Interpolation
Continuous cryptographic chain across generation, super-resolution, frame interpolation, and encoding.
Sovereign Voice-Cloning Consent-Class Framework with Per-Utterance Attestation
Every cloned utterance bound at synthesis to a specific authorised consent class.
Sovereign Generative Game-World Provenance with Per-Voxel and Per-Object Signing
Per-voxel, per-spawn-event, and per-biome cryptographic signing of a real-time generative game world.
Sovereign Code-Synthesis Audit Trail with Line-Level Lineage from Spoken Intent
Per-line cryptographic lineage from operator utterance to AI-generated source code.
Sovereign Multi-Modal Avatar with Per-Modality Watermarking and Cross-Modality Consistency Verification
Independent watermarks across face, video, audio, and lip-sync, bound under one operator signing key.
Sovereign Document Composability with Type-Safe Inversion for Retroactive Section-Level Undo
Every edit is a typed action with a declared inverse, signed and inversion-propagated through a dependency graph.
Sovereign Music Provenance via Triple Watermark across Waveform, Metadata, and Symbolic Sheet Music
Three independent watermarks across three orthogonal representations of the same musical work.
Cross-Brain Quorum for Generative Hallucination Detection with Divergence-Triggered Refusal
N independent brains must agree within a per-domain semantic-distance threshold or no artefact is signed.
Sovereign Edit-Distance Tracking with Per-Iteration Signed Lineage for Iteratively Refined Generative Assets
Per-iteration domain-distance metric paired with a signed iteration tree retaining abandoned branches.
Sovereign Generative Design System Provenance with Signed Design Tokens and Accessibility-Tree Lineage
Generated UI components bound to a signed design-token graph, component genealogy, and accessibility-tree.
Sovereign Translation Provenance with Per-Token Bilingual Lineage and Confidence Attestation across Languages
Per-token signed lineage across 450+ living languages, with confidence and dictionary corroboration scores.
Sovereign Air-Gap Workstation Bootstrap with Pre-Loaded Audit Anchors for Submarine and Forward-Deployed Operations
Defence-grade bootstrap with pre-loaded audit anchors that survives months of disconnection.
Sovereign Multi-Tenant Forgetting with Cryptographic Proof of Erasure under GDPR Article 17
Signed tombstone records prove dataset and model-weight erasure without re-disclosing the erased data.
Sovereign Per-Pixel Image Authenticity Verification via Merkle-Tree Signing on Generated Imagery
Per-pixel-block Merkle signing with localised tamper detection at sub-image granularity.
Sovereign Real-Time Streaming AudioSeal for Live Voice Synthesis with Rolling-Window Signatures
Per-buffer rolling-window signature chain verifiable within one buffer of arrival, latency under 50 ms.
Continuous Air-Gap Attestation Token from Operator-Personalised Silicon for Classified-Environment Compliance
Hardware-emitted attestation chain proves air-gap status across any specified subwindow.
Voice-Gated Multi-Brain Quorum with Replay-Resistant Action Composition for Sovereign Personal Artificial Intelligence
Single gate composes fresh voice biometric, action-digest binding, and multi-brain quorum agreement.
Sealed Layered-Edit Graph for Non-Destructive Image Compositing
Every compositing edit is a node in a signed, replayable layer graph. 20 claims.
Sovereign Building-Design Provenance
Cryptographic lineage from design intent through every revision of a building model. 20 claims.
Source-Anchored Sealed Transformation Lineage
Every transformation stage hash-links back to the original source artefact. 20 claims.
Continuity-Chained Sovereign Video Assembly
Assembled video clips chained in signed continuity order with verifiable joins. 20 claims.
Sealed Agent-Built-Game Provenance
Every asset and rule an agent generates for a game is signed into a provenance record. 20 claims.
Egress-Gated Sealed In-Application Browsing
In-app browsing routed through a signed egress gate that records every outbound request. 17 claims.
Hardware-Profile-Sealed Capability Gating
Available capabilities gated against a sealed profile of the host hardware. 15 claims.
Sealed Offline Print-Job Provenance
Every offline print job recorded and signed without any network dependency. 15 claims.
Offline Sovereign Hardware-Rebuild Advisor
Offline guidance for rebuilding or upgrading sovereign compute hardware. 15 claims.
Agentic Sealed Plan-Execute-Verify Ledger
An agent's plan, each executed step, and each verification sealed into one ledger. 15 claims.
Pre-Inference Model Provenance and Integrity Attestation
A model's provenance and integrity attested before any inference is allowed to run. 14 claims.
Verifiable Reasoning Ledger
Each step of a model's reasoning recorded in a signed, independently checkable ledger. 13 claims.
Policy Shadowing and Compliance Diff Engine
A candidate policy run in shadow against live decisions to diff compliance impact. 12 claims.
TPM-Attested Cross-Brain Quorum with Automatic Compensating Rollback
TPM-attested brains must reach quorum; a failed action rolls back automatically. 12 claims.
Sealed Deterministic What-If Simulation
What-if scenarios run deterministically and sealed so results are reproducible. 12 claims.
Heir-Sealed Memory Bequest
Personal memory bequeathed to an heir under a sealed, clearance-gated release. 12 claims.
Sealed Gated-Execution Trade Lineage
Every trade passes a gate and is recorded in a signed execution lineage. 13 claims.
Hardware-Profiled Reproducible Backtest
Backtests bound to a sealed hardware profile so results reproduce exactly. 12 claims.
Cross-Market Sealed Capital-Allocation Attestation
Capital allocation across markets attested and sealed for independent verification. 11 claims.
Voice-Biometric-Gated Order Authorisation
Trading orders authorised only on a fresh voice-biometric match. 11 claims.
Bounded Auto-Execution Envelope with Sealed Circuit-Breaker
Automated execution confined to a bounded envelope with a sealed circuit-breaker. 12 claims.
Sealed Trust-Tagged Instruction-Data Separation with Capability-Gated Injection Containment
Instructions and data kept cryptographically separate to contain prompt injection. 13 claims.
Consent-Gated Person-Edit-Refusing Generative Inpaint with Sealed Refusal
Generative inpainting refuses to edit a person without consent and seals the refusal. 11 claims.
Auditable Deterministic Game-Balance Attestation
Game-balance rules attested deterministically so outcomes are auditable. 9 claims.
Beat-Synchronised Multimodal Artifact Binding
Audio, visual, and timing artefacts bound together on a shared beat under one seal. 9 claims.
Sealed Deterministic Decision-Support Disclaimer Binding
Decision-support output bound to its disclaimer in a sealed, deterministic record. 12 claims.
Seed-Sealed Reproducible Society and Resource Simulation
Society and resource simulations sealed to a seed so any run reproduces. 14 claims.
Heir-Sealed Personal Archive with Clearance-Tagged Oral-History Retrieval
A personal archive bequeathed to an heir with clearance-tagged oral-history access. 14 claims.
Solar and Energy-Harvest-Aware Sealed Sovereign Compute Scheduling
Compute scheduled around harvested solar and stored energy, sealed for audit. 15 claims.
Dual-Surface Energy-Bound Knowledge Display
A dual-surface display that presents knowledge within a bound energy budget. 12 claims.
Sealed Off-Grid Survival Knowledge Appliance
A sealed appliance serving survival knowledge entirely off-grid. 13 claims.
Inkless Energy-Aware Sealed Sovereign Printing
Inkless printing scheduled to an energy budget and sealed for provenance. 14 claims.
Universal Action Interceptor for Autonomous Coding Agents with Post-Quantum Signed Audit
Supervises autonomous AI coding agents and seals every action under a post-quantum key. 26 claims.
Consensus Admission and Ordering of Operator-Sealed Post-Quantum Action Records
A proof-of-stake chain that admits and orders AI actions sealed before consensus. 21 claims.
Settlement of Sealed Application-Chain Artificial-Intelligence Actions to an Attestation Base Layer in a Native Token
Many AI application chains settle sealed actions to one attestation base layer. 20 claims.
Post-Quantum Audit-Root Anchoring to a Public Proof-of-Work Chain
Anchors the post-quantum AI-audit root to a public proof-of-work chain. 19 claims.
Continuous Third-Party Verification of Signed AI Compliance Reports Against On-Chain Anchors With Multi-Framework Control Mapping Including ISO/IEC 42001
Regulators continuously verify AI compliance reports against on-chain anchors. 22 claims.
Hardware-Attested Earning Validator Appliance With Sealed Capability Gating
A staking validator appliance whose duties are gated by attested hardware. 22 claims.
Attestation-Coupled Supply-Locking Mechanism Driven by a Tamper-Evident Usage-Metering Oracle
Binds token supply locking to a tamper-evident meter of attested usage. 20 claims.
Live Post-Quantum Consensus-Key Migration of an Operating Proof-of-Stake Chain by a Hybrid Dual-Signed Transition Epoch
Migrates a live proof-of-stake chain's consensus keys to post-quantum without halting. 19 claims.
Consensus-Enforced Artificial-Intelligence Safety Quorum as a Block-Validity Rule
Makes a cross-model AI safety quorum a precondition of block validity. 21 claims.
Selective-Disclosure Verification That a Sealed Audit Record Satisfies a Compliance Predicate Against an On-Chain Anchor
Proves a sealed record meets a compliance test without revealing it. 22 claims.
Post-Quantum-Attested, Sealed Cross-Chain Bridge With Egress Gating
Hardens the cross-chain bridge with sealed, egress-gated messages. 20 claims.
Chain-Enforced Validator Succession and Dead-Man Continuity
Transfers a validator's role to a designated heir under sealed dead-man rules. 20 claims.
Sovereign Offline Orchestrator for Department-Partitioned Artificial Intelligence Brain-Fleet Inference on a Single Offline Computing Device
Partitions the brain fleet into department-scoped enclaves on a single offline device, provable from a public key alone. 36 claims.
Sovereign Model Alias Layer with Cryptographic Provenance Binding of Human-Readable Model Identifiers to Weight Artefacts, Training Corpus, and Fine-Tuning Recipe Under a Post-Quantum Signature
Binds friendly model names to signed weight + corpus + recipe + runtime hashes, offline-verifiable from the operator public key alone. 35 claims.
Method and System for Cryptographically Demonstrating Continuous Offline Operation of a Sovereign Computing Device Across a Specified Interval Without Reliance on a Network-Connected Verifier
Proves a sovereign device was offline for a stated interval, verifiable from the device public key alone with no network in the trust path. 35 claims.
Build on it, do not build around it.
If your sovereign or on-premise AI roadmap touches any of these 13 families, the accountable, filed version of that capability is already on the register in Mickai's name. Licensing it is faster and safer than a design-around that keeps colliding with the same claims. Open the conversation and we will map your roadmap to the portfolio.
If you build on this ground, the efficient path is a licence.
104 filed UK applications, 2,340 claims, owned by Mickai LTD. When you want the full portfolio thesis and the numbers behind it, request a briefing or read the investor case.
