It depends on how many people need it and how sensitive the work is. One workstation suits a single team or a pilot. A server room installation suits a department or a whole organisation. A fully air-gapped site suits classified or highly regulated work. Mickai installs in all three shapes, on hardware you own.
What are the three shapes a private AI installation can take?
There are three: a single workstation, a server in a room you control, and a fully air-gapped site. Choosing between the private AI deployment options comes down to two questions. How many people need the system, and how sensitive is the work it will touch? Everything else follows from those answers.
The three are not quality tiers. They are different perimeters. A workstation draws the perimeter around one machine under one desk. A server room installation draws it around a room you already secure and a network you already run. An air-gapped site draws it around a space with no data route in or out at all. The MICKAI® Sovereign Intelligence Operating System (SIOS) installs in all three shapes on hardware the operator owns, runs offline, and sends no data off that hardware.
None of this is an argument against cloud. Hyperscale compute is good at what it is built for, and for unregulated work it stays the sensible default. My objection is narrower: that a regulated organisation has no option but to rent its intelligence and take a supplier's word for what happened to its data.
Who does a single workstation suit, and what does it rule out?
A single workstation suits one team, one function, or a first evaluation. It is the right shape when a handful of people need the system, they work in the same place, and you want to see it running on real material before changing anything structural.
What you get is not a cut-down version. Models sit on local storage, inference runs on the local accelerator, and the Open Audit Record seals actions exactly as it does on a rack. The assurance is not downgraded because the box is smaller.
What it rules out is scale and availability. One machine serves the people who can reach it. If it is off, nobody works. There is no failover, and one machine is not the shape for many people working at once. It also concentrates risk in a physical object: a workstation under a desk leaves a building more easily than a rack in a locked room, so physical and access controls matter more here, not less. The NCSC Cyber Assessment Framework treats protection of stored and transmitted data as a principle in its own right, and a small footprint does not exempt you from it.
When does a server room installation make sense?
A server room installation makes sense when a department or the whole organisation needs the system, and when you already have somewhere you trust to put a rack. For a regulated firm with its own estate the hardware then sits behind a door you already control, on a network you already monitor. The gain is shared capacity: several people work at once, and you size it to real load rather than your busiest desk.
Buyers ask this every time, so directly: yes, the data stays inside the building. SIOS holds models, working data and audit records on the hardware it is installed on. There is no telemetry channel, no metrics upload and no model call that leaves the site. A server room installation is not a private cloud with a supplier's tunnel into it. If your network team wants to prove that, put the installation behind an egress rule that drops everything, then watch it carry on working.
When is a fully air-gapped site the right answer?
A fully air-gapped site is the right answer when material cannot leave the environment under any circumstances, and when connectivity itself is treated as the risk. That covers classified work, defence-adjacent programmes, and the parts of a regulated organisation where the governing assumption is that anything reachable is eventually reached.
Air-gapped means no network path exists, not that the path is filtered. That distinction is the whole point. A firewalled system has a route and a policy deciding what crosses it. An air-gapped system has no route, so there is no policy to misconfigure and no credential to be stolen and used from outside the building.
What you trade away is convenience. Getting anything in or out becomes a deliberate, logged, human process, and for environments that need it that friction is the feature. What I will not claim is accreditation. An air-gapped installation is an architecture, and any assurance scheme you are subject to remains yours to satisfy with your own evidence.
How do updates and new models reach each of the three?
A workstation or server room installation takes an update from a package you approve and apply on your own schedule. An air-gapped site takes the same package carried in on physical media, checked before installation, and never automatically.
There is no silent update channel in any of the three. Nothing arrives because we decided it should: you hold the package, you verify it, and you install it when your change process says you can. The same applies to the specialised models. There are fifty of them, each built for a particular kind of work, and adding one is an explicit act on your side rather than a background download.
For air-gapped sites the sequence is deliberate. The package is produced and signed, transferred to media, brought into the environment under whatever custody rules apply there, verified against its signature, then staged before it touches production work. The NCSC's guidelines for secure AI system development treat secure deployment and secure operation and maintenance as distinct stages, and an air gap is the clearest case for handling them separately. An update is a supply chain event. Treat it as one.
What does each option ask of your IT team?
A workstation asks very little: someone to own the machine, keep it patched, and control who sits at it. A server room installation asks what any rack asks, which your team already knows how to do. An air-gapped site asks for a process, and the process is the difficult part.
The workstation behaves like a managed endpoint with an unusual amount of local compute, so the skills are the ones your desktop team already has. The server room installation needs capacity planning, backup, and a monitoring hook into whatever you run today.
The air-gapped site needs written custody procedures for media, a named person who authorises a transfer in, somewhere to stage and verify packages, and a records habit that survives staff turnover. The government's voluntary AI Cyber Security Code of Practice is built around principles that run across the life of a system, and for an air gap most of that ongoing work is procedural rather than technical.
Can you start on one and move to another?
Yes, and most buyers should. A workstation evaluation that becomes a server room installation is a normal path, as is a server room installation that later spawns a separate air-gapped enclave for one programme. The system is the same in each shape, so what you learn on a workstation stays true when you move.
Different parts of an organisation can also sit in different shapes at once: one directorate on a shared rack, one programme air-gapped, one team on a single machine while it decides whether it wants more.
A migration is a move of models, configuration and audit history onto larger hardware, not a rebuild. The thing to protect is the Open Audit Record, because its value depends on the chain staying continuous.
Which option do auditors and assessors care about?
Auditors care far less about the shape than about the evidence. Deployment topology tends to get one paragraph and the audit trail gets the rest of the meeting. What an assessor wants is a record they can check themselves, showing what the system did, to what, and on whose authority.
That is what the Open Audit Record is for. Every consequential action is sealed under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024, and consequential actions wait for a named person to approve them before they run. An exported record is verified offline, with a public key, using tools that are not ours. Evidence you can only check with the supplier's own software is not independent evidence.
The record is tamper-evident, not tamper-proof. Nobody can stop a determined person editing a file. What the seal does is make the edit fail verification, so you find out. An auditor does not need a promise that nothing changed. They need a way to tell.
ICO guidance on artificial intelligence and data protection places accountability on the organisation deploying a system, meaning you must be able to demonstrate how it handles personal data rather than assert that it does. A workstation, a rack and an air-gapped site all produce the same kind of demonstrable record.
Our closed beta is open, with one regulated company onboarding as a design partner. For the short version of this decision, run the test yourself: unplug the network for a working day and confirm that nothing stops and nothing leaves.
Frequently asked questions
Can we pilot private AI on one workstation before committing?
Yes, and it is the usual starting point. A single workstation gives a team the full system on hardware you own, with the same audit sealing a rack produces. Run real work through it for a few weeks, then decide. What you learn transfers directly, because moving to a server room installation is a change of hardware rather than a change of system.
Is an air-gapped installation less capable than a connected one?
No. The software is the same build, the models are the same models, and the audit record seals the same way. What differs is logistics, not function: updates and new models arrive on physical media rather than over a network, and getting results out is a deliberate, recorded process. Capability is unchanged. Convenience is what you trade.
How do software updates reach an air-gapped site?
They are carried in. We produce and sign a package, it is transferred to physical media, and it is brought into the environment under whatever custody rules apply there. Before installation the signature is verified and the package is staged. Nothing installs automatically and nothing reaches the site over a network, because no network path exists to carry it.
Can different departments use different deployment shapes?
Yes, and larger organisations usually end up that way. One directorate can share a rack in your server room, one programme can run air-gapped in its own space, and a small team can sit on a single workstation. The installations do not need to be joined to each other, and for sensitive programmes they should not be.
Does a server room installation still keep data inside the building?
Yes. SIOS holds models, working data and audit records on the hardware it runs on. There is no telemetry channel, no metrics upload and no model call that leaves your site. If you want proof rather than assurance, put the installation behind an egress rule that drops everything outbound, then unplug the network for a working day and watch it keep working.
Related briefings
Deploying private AI
- Private AI for Business: What It Is and How It Works
- Offline AI Assistant: What It Can Do for Your Staff
- On-Premise AI Server Requirements for a Normal Office
- How Sovereign AI Integrates With Your Existing Systems
- From Data to Answers, Without the Data Leaving
Documents and retrieval
- What Is RAG? Retrieval-Augmented Generation Explained
- How to Prepare Documents for a Private AI Knowledge Base
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)