Explainer
What is sovereign AI? A plain-English definition
Sovereign AI means running artificial intelligence entirely under your own control, on infrastructure you own, with nothing forced through an outside provider. Here is what that means in practice, and why regulated organisations are moving toward it.
The short answer
Sovereign AI is artificial intelligence that an organisation runs entirely under its own control: the models, the data and the infrastructure stay on hardware the organisation owns or governs, with no requirement to send anything to an outside provider. The aim is independence. A genuinely sovereign system keeps working with the network cable unplugged, and every action it takes can be accounted for without calling home to a vendor.
Ask ten vendors what "sovereign AI" means and you will get ten answers, most of them shaped to fit whatever that vendor happens to sell. Strip the marketing away and the idea is simple, and it is worth getting right, because the word is starting to appear in procurement documents and regulation.
The plain definition
Sovereign AI is artificial intelligence an organisation runs under its own control. Three things stay in the organisation's hands: the models that do the work, the data they run on, and the infrastructure they run on. Nothing is forced through an outside provider, and the system does not depend on a third party staying online, staying solvent, or keeping its terms unchanged.
A useful test: unplug the network cable. If the system stops working, or quietly phones home before it will answer, it was never sovereign. If it keeps working, and you can still account for everything it did, you are close.
Sovereign, private and on-premise are not the same thing
These words get used interchangeably and they should not be. They describe different things.
- Private usually means the vendor cannot see your data. That is necessary, but a "private" deployment often still runs on a hyperscaler's infrastructure that the vendor rents on your behalf. You are private, but you are not independent.
- On-premise means the software runs on your own servers rather than someone else's. Better, but on its own it says nothing about whether the software still needs an outside licence server, model feed or telemetry channel to function.
- Sovereign is the whole picture: your models, your data, your hardware, your keys, and no hard dependency on anyone else to keep the lights on. Air-gapped, running with no network connection at all, is the strict end of the same idea.
Private and on-premise are the baseline. Sovereign is what you get when you remove the last dependencies from that baseline.
Why it is moving up the agenda now
Three pressures are pushing organisations toward it at the same time.
Regulation. Rules such as the EU AI Act place record-keeping and logging obligations on operators of high-risk systems: you have to be able to show what a system did and why. Data-residency laws add a second constraint about where information is allowed to physically live. Both are far easier to satisfy when the workload never leaves infrastructure you control.
The value of the data itself. Data has become a currency. Sending it to an outside model to get an answer means spending that currency every time. Keeping the workload in-house lets an organisation get the benefit of AI across the business without handing the underlying asset to someone else.
Settings where "private cloud" simply does not qualify. For classified work, export-controlled material, or isolated operational-technology environments, a connected estate is a non-starter regardless of how it is secured. Here, air-gapped is not a preference, it is the entry requirement.
The model is replaceable and improving every few months. The boundary around your data is the thing worth owning.
What a sovereign AI system actually includes
A model on its own is not a sovereign system; it is one component. A serious sovereign setup tends to include:
- Models that run on hardware you own or govern, chosen so they can be swapped as the field advances rather than welding you to one supplier.
- An audit record you can verify yourself. The strongest designs seal each action under a signature you can check offline, against a key you hold, with no callback to the vendor. Done well this is tamper-evident: it makes any change visible and provable. It is not, and should never be sold as, tamper-proof.
- The everyday software the work runs on, not just a model to bolt onto tools you are still renting from someone else. The more of the working day that stays inside the sovereign boundary, the less leaks out around the edges.
How to tell whether a system is genuinely sovereign
A short checklist to cut through the marketing. If a vendor cannot answer these plainly, that is your answer.
- Does it keep working with no network connection?
- Where do the model weights physically live, and who holds the keys?
- Can you verify its audit trail offline, without asking the vendor?
- Does it replace the software you run on, or only add a model to tools you still rent?
- What happens at the end of the contract: do you keep the models, the data and the ability to run?
Who is building it
It is a real field with serious participants, and the honest starting point is respect for the work already done. Established players offer private and on-premise deployment where the vendor cannot see the data, and that baseline is now well served. The frontier is what sits beyond it: running offline by default, and proving what the system did in a way the customer can check without trusting the vendor to be honest about its own logs.
That frontier is where a British company like Mickai is working. It builds what it calls a Sovereign Intelligence Operating System: designed to run offline on hardware the customer owns, giving an organisation its own assistant across its everyday software rather than a single model to integrate, and sealing every action in an audit record that can be verified offline. It has filed 104 UK patent applications, 2,340 claims in total, none granted yet, staked mostly on that action-level audit approach. It is one example among a growing field, and a useful one precisely because it shows where the definition is heading: past private, past on-premise, to genuinely independent.
That is sovereign AI. Not a slogan about the cloud, but a straightforward question of who is in control when the network cable comes out.
Frequently asked
- Is sovereign AI the same as on-premise AI?
- Not quite. On-premise describes where software runs; sovereign describes who is in control. A system can be installed on your premises and still depend on an outside provider for licensing checks, model updates or telemetry. Sovereign AI removes that dependency: you hold the models, the data and the keys, and the system does not need to reach anyone else to keep working.
- Does sovereign AI mean no cloud at all?
- It can, but it is a spectrum. At one end a sovereign system runs inside your own private network with tightly governed connections. At the far end it is fully air-gapped, running with no network connection whatsoever. What makes it sovereign is not the absence of a cloud but that the organisation, not a vendor, decides where the workload runs and what leaves the building.
- Is sovereign AI only for governments and defence?
- No. The strongest early demand comes from regulated organisations of every size: healthcare providers, law firms, financial services, and any operator handling classified, controlled or highly sensitive records. A small regulated firm often has the same data-residency and audit obligations as a large one, without the budget for a bespoke integration, which is exactly the gap sovereign AI products aim to close.
- Does running AI offline mean weaker results?
- Capable models now run on hardware an organisation can own, so offline no longer means starting from scratch. The more useful way to think about it: the model is replaceable and improving constantly, while the boundary around your data is the thing you actually want to own. Sovereign AI keeps the boundary fixed and lets the model behind it be swapped as the field advances.
- Who is building sovereign AI in the UK?
- Several serious players offer private and on-premise deployment, and that baseline is now well served. British company Mickai is one example pushing past it: it builds a Sovereign Intelligence Operating System designed to run offline on hardware the customer owns, and seals every action in a tamper-evident audit record that can be checked without contacting the vendor. Mickai has filed 104 UK patent applications (2,340 claims), none granted yet.