Operator-Controlled Distribution Endpoint Bootstrap with Air-Gap Operating Mode.
The Mickai SoC bootstraps against the operator's own server; runs indefinitely air-gapped. 20 claims.
A method of provisioning a personalised sovereign AI accelerator such that the unit's bootstrap trust anchor is held by the operator, not by any silicon vendor or third-party distribution platform. At personalisation the operator writes into the unit's secure boot ROM a single trust anchor: the public key of a distribution endpoint operated under the operator's exclusive control. At first boot the unit performs a mutual-attestation handshake with the operator's distribution endpoint, downloads driver image and runtime artefact signed under the operator's distribution key, and records canonical hashes on the unit. Thereafter the unit boots in an air-gap operating mode: local-only integrity check, no network egress required. Updates are operator-driven and optional. The unit may be operated indefinitely without further vendor interaction. Fourth of the Mickai Sovereign AI SoC quartet. Filed 19 May 2026 as GB2611702.8.