Sign in

Mickai

@mickai.bsky.social
106 followers 3 following 2.8K posts

British Sovereign Intelligence Operating System. On-device, hardware-bound, post-quantum signed audit ledger (ML-DSA-65, FIPS 204). 50 brains. 104 UK patent applications filed, 2,340 claims.

PostsRepliesMedia
Mickai @mickai.bsky.social · 9h
Spain has moved to one of the strictest national AI regimes in the EU, making the labelling of AI-generated and AI-altered content a legal duty backed by its supervisory agency AESIA and fines up… mickai.co.uk/articles/spain-ai-cont…
010
Mickai @mickai.bsky.social · 9h
Most organisations cannot say what their cloud AI decided, because it is a black box. A sovereign substrate paired with a post-quantum signed audit ledger records every consequential decision, so you stay in control and can… mickai.co.uk/articles/do-you-know-w…
000
Mickai @mickai.bsky.social · 30/09/2026
You adopt AI without the cloud by running it on your own sovereign substrate, so your data never leaves the building. We audit, clean, classify and govern your estate in place, sealed to an audit ledger, and you own… mickai.co.uk/articles/adopt-ai-with…
010
Mickai @mickai.bsky.social · 30/09/2026
There is no good reason to key a spreadsheet by hand for a week when a governed AI can do it in minutes. We get your messy data ready in place, on your own hardware, so the work is fast and your people are freed… mickai.co.uk/articles/stop-doing-sp…
000
Mickai @mickai.bsky.social · 30/09/2026
A traditional business gets AI-ready by staging the work: assess, digitise, clean, classify and govern its data in place, on its own hardware. No rip-and-replace, nothing sent to a cloud, and you own the result. mickai.co.uk/articles/traditional-b…
000
Mickai @mickai.bsky.social · 30/09/2026
Yes. Old, messy, paper-based data is where AI readiness begins, not where it ends. We assess, digitise, clean, classify and compartmentalise it in place on your own hardware, so nothing leaves the building and you own the… mickai.co.uk/articles/historic-mess…
000
Mickai @mickai.bsky.social · 30/09/2026
Most companies are not ready for AI, and the blocker is almost never the model, it is the data. Here is an honest readiness check, the signs you are not ready, and the five steps that get you there on hardware you own. mickai.co.uk/articles/are-you-ready…
000
Mickai @mickai.bsky.social · 30/09/2026
Mandatory AI screening of high-risk purchases is only acceptable if the watchers are watchable: checks on hardware the merchant owns, in UK jurisdiction, with every automated decision sealed into an audit… mickai.co.uk/articles/counter-terro…
020
Mickai @mickai.bsky.social · 30/09/2026
Every sale of a regulated, high-risk good should pass through an intelligent check at the point of sale: AI screening that runs on merchant-owned hardware inside a gated sandbox and passes statutory flags upstream… mickai.co.uk/articles/ai-screening-…
000
Mickai @mickai.bsky.social · 30/09/2026
The UK will hold its largest home defence exercise in several decades in 2027, testing updated War Book plans across government, the military and civilian agencies. We argue national resilience should… mickai.co.uk/articles/uk-home-defen…
000
Mickai @mickai.bsky.social · 29/09/2026
Owned intelligence compounds and rented intelligence does not: models shaped by your data, records only you can produce and infrastructure nobody can withdraw appreciate every year, while a… mickai.co.uk/articles/why-the-futur…
000
Mickai @mickai.bsky.social · 29/09/2026
Most AI programmes stall because the organisation cannot name the stage of readiness it is actually at. This five-stage framework, Experimentation, Adoption, Integration, Governance and Sovereign AI, gives each stage its honest symptoms… mickai.co.uk/articles/the-ai-readin…
010
Mickai @mickai.bsky.social · 29/09/2026
The real cost of twenty workplace products is not twenty invoices: it is twenty trust boundaries, twenty audit surfaces and twenty copies of your data, none of which are priced at renewal… mickai.co.uk/articles/the-next-gene…
010
Mickai @mickai.bsky.social · 29/09/2026
The chatbot framing trained organisations to evaluate AI on one axis: answer quality. Once a system executes actions against real systems of record, accuracy becomes necessary but insufficient, and the controlling question… mickai.co.uk/articles/from-chatbots…
010
Mickai @mickai.bsky.social · 29/09/2026
An agent that acts on your systems needs what a member of staff needs: an identity, a job description, scoped permissions, supervision, an audit trail, a review and an exit. Governance for autonomous actors already exists… mickai.co.uk/articles/why-ai-should…
110
Mickai @mickai.bsky.social · 29/09/2026
GDPR governs personal data; the EU AI Act, NIS2, DORA, ISO 42001 and SOC 2 govern the system, and every one of them asks the same underlying question: prove what the system did, on what basis, and who authorised it. Conventional… mickai.co.uk/articles/ai-compliance…
000
Mickai @mickai.bsky.social · 29/09/2026
Five questions decide an AI purchase: where data is processed, who owns the outputs, whether it runs offline, who controls updates, and what evidence it leaves behind. Each one has an evasive answer that swaps a policy promise… mickai.co.uk/articles/what-cios-sho…
000
Mickai @mickai.bsky.social · 29/09/2026
Public, private cloud, hybrid and sovereign AI each win different workloads, and performance is not what separates them. The deciding questions are who can be lawfully compelled to hand over your data, and who can prove afterwards what… mickai.co.uk/articles/the-rise-of-p…
000
Mickai @mickai.bsky.social · 28/09/2026
The strategic asset of the next decade is not the model but the proprietary data an organisation holds and its ability to reason over it inside systems it controls. An organisation that rents its intelligence is… mickai.co.uk/articles/why-data-owne…
000
Mickai @mickai.bsky.social · 28/09/2026
Enterprise AI stacks have seven layers: storage, identity, models, orchestration, security, governance and interfaces. The risk does not sit in any layer, it sits in the seams between vendors, where evidence gets re-serialised and… mickai.co.uk/articles/the-enterpris…
000
Mickai @mickai.bsky.social · 28/09/2026
Shadow AI is a demand signal, not a discipline problem: staff use unsanctioned tools because the sanctioned path is slower than the deadline. Prohibition relocates the exposure rather than removing it, and the durable answer is a… mickai.co.uk/articles/the-death-of-…
000
Mickai @mickai.bsky.social · 28/09/2026
Trust in AI is an architectural property, not a policy document. The real test is whether a hostile third party can verify your claims about a system without having to trust you, and that property has to be built in before… mickai.co.uk/articles/building-trus…
000
Mickai @mickai.bsky.social · 28/09/2026
Harvest now, decrypt later gets the attention, but the sharper risk is evidential: a classical signature over an AI audit record becomes forgeable the day the asymmetry breaks, retroactively. NIST FIPS 203, 204 and 205 are… mickai.co.uk/articles/why-post-quan…
000
Mickai @mickai.bsky.social · 28/09/2026
A board cannot discharge oversight of a system whose decisions it cannot reconstruct: policy governs intent, while evidence sealed before an action executes is what a regulator or a court will actually test. Here are the… mickai.co.uk/articles/the-boardroom…
000
Mickai @mickai.bsky.social · 28/09/2026
Once AI sits in a decision path, it inherits the resilience duties of electricity and telecoms: availability targets, mapped dependencies, tested fallbacks and reportable failure. The failure mode that matters is… mickai.co.uk/articles/what-happens-…
000
Mickai @mickai.bsky.social · 28/09/2026
Offline is not a fallback for enterprise AI, it is a requirement class: the events that sever connectivity and the events that raise the stakes are usually the same events. We set out which workloads belong in that class, what… mickai.co.uk/articles/the-future-of…
000
Mickai @mickai.bsky.social · 27/09/2026
Cloud AI is priced correctly and costed wrongly: the invoice captures consumption, while switching, exposure, compliance labour, latency, dependency and evidence are incurred now and paid later. A seven-line total cost of ownership… mickai.co.uk/articles/the-hidden-co…
010
Mickai @mickai.bsky.social · 27/09/2026
Governance cost is not linear in the number of AI deployments, because accountability attaches to decisions and functions, not to software. Once AI acts across every workflow, scheduling, identity… mickai.co.uk/articles/why-every-org…
101
Mickai @mickai.bsky.social · 27/09/2026
AI sovereignty is repeating the structure of the cloud migration, not the pattern of a technology trend: the same four forces of ownership, resilience, regulation and data gravity now point the other way for a defined… mickai.co.uk/articles/ai-sovereignt…
000
Mickai @mickai.bsky.social · 27/09/2026
Regulated sectors are migrating to privately controlled AI not from distrust of the cloud, but because governance, the evidential burden and jurisdiction cannot be delegated to a supplier. Public AI stays right for… mickai.co.uk/articles/the-end-of-pu…
000
Mickai @mickai.bsky.social · 27/09/2026
Sovereign email is your organisation's mail on hardware you own, that no provider can read or be compelled to hand over. The assistant drafts each reply on the device and seals it to a verifiable audit record… mickai.co.uk/articles/sovereign-ema…
010
Mickai @mickai.bsky.social · 27/09/2026
AI infrastructure control migrates from vendor to operator across this decade, driven by regulation, not preference. This flagship guide sets out the three-tier stack, the regulatory forces reshaping it, the post-quantum and… mickai.co.uk/articles/future-of-ai-…
000
Mickai @mickai.bsky.social · 27/09/2026
AI business continuity extends existing BCM and DR discipline, BIA, RTO, RPO and a tested fallback, to cover the AI-dependent processes most plans still leave out. This guide names the four ways an AI dependency actually… mickai.co.uk/articles/ai-disaster-r…
000
Mickai @mickai.bsky.social · 27/09/2026
A five-level framework for placing an organisation's AI maturity, from isolated pilots through governed automation to owned, independently verifiable infrastructure. Includes a scoreable self-assessment and a mapping to NIST AI… mickai.co.uk/articles/enterprise-ai…
000
Mickai @mickai.bsky.social · 26/09/2026
On-premise AI means running AI infrastructure and models inside an organisation's own data centre or private cloud, under its own control. This guide covers every decision a CIO has to make and defend: hardware and GPU sizing… mickai.co.uk/articles/cio-guide-to-…
000
Mickai @mickai.bsky.social · 26/09/2026
There is no universally correct choice between building, buying and renting AI. This guide sets out the five variables that decide it, an honest tradeoffs table across cloud API, platform, on-prem and sovereign deployment, and a three-year… mickai.co.uk/articles/build-vs-buy-…
000
Mickai @mickai.bsky.social · 26/09/2026
A repeatable framework for evaluating any AI vendor: classify the use case first, then work through data handling, deployment model, output ownership, update control, auditability, security, commercial terms and exit rights. mickai.co.uk/articles/ai-procuremen…
000
Mickai @mickai.bsky.social · 26/09/2026
AI security is the discipline of protecting AI systems as assets, not just using AI to defend other assets. This checklist gives CISOs a six-layer map of the AI attack surface, the controls that belong to each layer, and how they… mickai.co.uk/articles/ai-security-c…
000
Mickai @mickai.bsky.social · 26/09/2026
A working AI governance framework needs a named owner for every system, a risk-tiering rule that is actually applied, and an evidence trail that survives an audit. This guide sets out the roles, policy architecture, controls… mickai.co.uk/articles/ai-governance…
000
Mickai @mickai.bsky.social · 26/09/2026
A working AI risk register needs five columns done right: risk, impact, likelihood, mitigation, ownership, scored as inherent and residual risk and reviewed on a named cadence. This guide sets out the method and includes a free… mickai.co.uk/articles/ai-risk-regis…
000
Mickai @mickai.bsky.social · 26/09/2026
The EU AI Act is a binding regulation that applies in stages, not on a single date. This guide sets out the corrected 2026/2027/2028 deadline timeline after the Digital Omnibus deferral, the four risk tiers, who counts as a… mickai.co.uk/articles/eu-ai-act-exp…
000
Mickai @mickai.bsky.social · 26/09/2026
When all your company data lives in one owned operating system, the assistant gets sharper and the business gets better informed. Here is why. mickai.co.uk/articles/your-data-bec…
000
Mickai @mickai.bsky.social · 26/09/2026
The UK Government AI Playbook, explained: what it asks of departments and suppliers, and which parts are binding. dev.to/mickai/ai-playbook-for-uk-go…
010
Mickai @mickai.bsky.social · 26/09/2026
Yes, if you build or use AI systems. ISO/IEC 27001 governs information security. dev.to/mickai/iso-42001-vs-iso-2700…
000
Mickai @mickai.bsky.social · 26/09/2026
Yes, if they sit inside the certification scope. Def Stan 05-138 Issue 4 scopes your whole corporate environment, not just contract data, so AI tools count as software or cloud services under Cyber Essentials. dev.to/mickai/defence-cyber-certifi…
000
Mickai @mickai.bsky.social · 26/09/2026
JSP 936 Part 1 is the MOD's directive on dependable AI. It sets mandatory requirements built on five ethical principles: human-centricity, responsibility, understanding, bias and harm mitigation, and reliability. dev.to/mickai/jsp-936-for-ai-suppli…
000
Mickai @mickai.bsky.social · 26/09/2026
Only on infrastructure you control. MOD contract information carries confidentiality conditions such as DEFCON 531, which limit disclosure to the people who need to know. dev.to/mickai/generative-ai-and-mod…
000
Mickai @mickai.bsky.social · 26/09/2026
Yes, where the AI system supports an essential service. The Network and Information Systems Regulations 2018 cover air, rail, water and road transport operators, and the duty attaches to the network and information dev.to/mickai/nis-regulations-and-a…
010
Mickai @mickai.bsky.social · 26/09/2026
Not in a public AI tool. A declaration carries commercial values, consignee details, tariff codes and contract terms that a competitor would pay for, and pasting it into a consumer service puts it outside your contr dev.to/mickai/customs-declarations-…
000
Mickai @mickai.bsky.social · 26/09/2026
Almost certainly yes. The ICO treats monitoring that tracks location and behaviour, then uses analytics to score how someone drives, as high risk. dev.to/mickai/driver-monitoring-dpi…
000