Give staff a sanctioned assistant inside the institution's own environment and personal AI accounts lose their pull. In practice that means an assistant running on infrastructure the university controls, indexing only approved collections, and recording what it did. Mickai installs on hardware the institution owns, including a fully offline installation where that is required.
Why are university staff signing up for personal AI accounts?
Because the work arrived before the policy did. A registry officer answering the same admissions question again and again each week, a research manager reading funder terms, a lecturer rewriting a module handbook: all of them found a tool that helped, and signing up took ninety seconds and a personal email address.
That demand is genuine. It is not recklessness, and treating it as a discipline problem will not fix it. I have seen the same pattern in every regulated sector I have worked in: when the sanctioned route is slower than the unsanctioned one, people use the unsanctioned one and stop mentioning it.
The cost is not the subscription. It is that draft grant applications, unpublished method notes, committee papers, staff grievance summaries and pieces of student work get pasted into an account the institution does not hold, cannot audit and cannot search if a subject access request arrives. There is no record of what went out. That is the exposure, and it grows quietly.
What does an approved environment actually mean here?
It means an environment where the institution can state where processing happened, what the system could reach, who authorised it and what it did, and can produce evidence rather than a supplier's assurance. Three tests decide it: location of processing, whether anything leaves, and whether there is a record you can hand to someone else.
Many private AI offerings pass the first test and fail the third. A single-tenant instance in a hosted region tells you where the data sat. It does not give your information governance team an independent account of what the system did on a particular Tuesday in March.
To be clear about the market: the cloud remains a good answer for a great deal of university work. Web hosting, non-personal research computing, timetable modelling, public-facing content. The argument is not against the companies building compute and cloud infrastructure. It is against the assumption that a regulated institution must rent its intelligence, ship its material offsite, and accept a vendor's word about what happened to it.
Which staff groups get the most value first?
Professional services and administration, ahead of academics. Their work is document-heavy, rule-bound and repetitive, which is exactly what an assistant grounded in your own policies does well.
Registry and admissions spend much of the year restating procedure that is already written down. HR answers the same narrow set of questions about leave, probation and grievance routes. Finance and procurement interpret thresholds and framework rules. A research office reads funder terms and conditions that change every cycle. None of that needs a frontier model. It needs accurate retrieval from documents the institution has already approved, with the source shown so the reader can check it.
Academic value follows, and it lands first in humanities, social science and engineering: literature triage, drafting ethics applications, summarising committee and consultation responses, turning a long dataset description into something a collaborator can read. Teaching administration benefits before teaching itself does.
What data should never go into a staff assistant?
Anything you could not defend in a breach report, and anything you hold under a restriction you did not write yourself. The second category catches more universities than the first.
Export-controlled material, data under an industrial collaboration agreement, anything covered by a non-disclosure agreement with a partner, embargoed pre-publication work, and datasets whose ethics approval names a defined processing environment. In each case the restriction is contractual or statutory, and the fact that the assistant runs on your own estate does not automatically satisfy it. Read the clause. Some will be satisfied by an on-premises installation with no egress, and some will require the dataset to stay exactly where it is.
Running the system yourself removes the transfer question. It does not remove the authorisation question. Decide at collection level, with a named owner for each collection, and record the decision alongside the collection rather than in someone's inbox.
How do we handle student personal data and assessment material?
Treat it as a separate decision, taken later. My recommendation is to exclude student personal data from the first phase entirely, because it changes your lawful basis, your transparency obligations and the scope of your assessment. Staff productivity is the easier case: make that work first.
Assessment is a further step again. Marking assisted by a model touches academic regulations and appeals procedure, not only data protection. If you go there, the design matters more than the model: the assistant drafts, a named marker decides, and the record shows which is which. In SIOS, consequential actions wait for a named person to approve them. A mark is a decision about someone's future, and it should carry a human name.
Student-facing chat is a different product with a different risk profile. Do not fold it into a staff pilot to save time on approvals. It will cost you the approval.
What does information governance need to see before approval?
Four things: where processing happens, what the assistant can reach, who approved each consequential action, and evidence that it behaved the way you described. The first three are architecture. The fourth is where most proposals are thin.
SIOS produces an Open Audit Record. It is append-only and hash-chained, and each entry is signed using ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024. An auditor exports the record and verifies it offline with a public key, using tools that are not ours. That last point is what makes it evidence rather than a report.
The record is tamper-evident, and the difference from tamper-proof is worth stating plainly to an audit committee. Tamper-proof would mean the log cannot be altered, which no software can honestly promise. Tamper-evident means that if an entry is changed or removed, verification fails and the break is located. You are not asked to trust that nothing happened. You are given the means to check.
How do we run a pilot the data protection officer will sign off?
Narrow it until it is boring, and do the assessment first. UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals, and the ICO's DPIA guidance asks you to carry it out before the processing begins, not alongside it. The ICO's guidance on AI and data protection covers how the wider accountability duties apply to a system like this.
A shape that tends to get approved: one team of eight to fifteen named users. One or two approved collections, each with a named owner. No student personal data. No external egress. A written list of the questions you expect the assistant to answer and the ones it must refuse. Four to six weeks, then a review that reads the audit record rather than the enthusiasm.
Write down in advance what would stop the rollout. Wrong citations of policy, staff routing around the assistant, an audit record nobody can interpret. A pilot with no failure condition is a procurement exercise wearing a lab coat.
Jisc publishes an AI maturity toolkit for tertiary education, covering colleges as well as universities, which sets out stages an institution moves through from early exploration to embedded use. It is a useful way to tell a senior team where a pilot sits and what the next stage would ask of them.
What does this look like on university-owned hardware?
A server, or a small cluster, on your own estate, running the Mickai Sovereign Intelligence Operating System. It can run with no external connection at all, including a fully offline installation where a department or a funder requires one.
Capacity is decided by the machine, so plan it honestly. Memory and a capable graphics card set how large a model you can load and how many people can work at once. Models are sized to the hardware you own, so judge them on your own tasks rather than on anyone's league table: give them your actual admissions queries and your actual funder terms, and see what comes back. SIOS covers 63 studios in total, of which 14 are production-ready and 49 are in development, alongside 50 specialised models we call brains, so the assistant answering an HR question is not the one reading a procurement framework.
One practical caveat, because universities run on scanned paper. A local OCR runtime has read scanned PDFs in controlled tests, and the extraction and ingestion integration inside SIOS is still being completed. If your first use case depends on a filing cabinet of scans, plan around that.
Mickai LTD is a UK company, Companies House 17166618, and the platform sits behind 104 filed UK patent applications carrying 2,340 claims. The closed beta is open, with one regulated organisation onboarding as a design partner. If you want the architecture rather than the sales case, start with sovereign AI and internal knowledge AI.
Frequently asked questions
Can a university run an AI assistant on its own servers?
Yes. SIOS installs on hardware the institution owns and can run with no external network connection at all. Capacity is decided by the machine: memory and a capable graphics card set how large a model you can load and how many people can use it at once. Size the hardware to the group you intend to serve.
How do we stop staff using personal AI accounts for work?
Give them something better inside the estate. Policy on its own moves the behaviour out of sight rather than out of existence. A sanctioned assistant that answers from institutional policy, is reachable from a normal browser and needs no personal sign-up removes the reason to go elsewhere. Pair it with one short, clear rule and enforce that.
Do we need a DPIA before giving staff an AI assistant?
Assume yes and start it early. UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals, and the ICO asks you to carry it out before the processing begins. Even where a full DPIA is arguable, a written assessment is what your data protection officer needs to approve a pilot.
Can the assistant answer from our internal policies and handbooks?
Yes, and that is the main use. You build a knowledge base from approved collections: academic regulations, HR policy, procurement rules, module handbooks. Answers cite the source document so the reader can check the wording themselves. A named owner decides what enters each collection, and the audit record shows when something was added or removed.
Will research data be safe in a staff AI assistant?
It stays on your estate, which removes the transfer question, but that is not the whole answer. Controlled or contractually restricted datasets should be excluded by default and added only with the agreement of the principal investigator and the research office. Keep grant material and industrial collaboration data in separately governed collections.
Related briefings
Education
- AI Governance for Further Education Colleges: Checklist
- Student Work and AI Training: Copyright and Consent
Data protection and UK GDPR
- UK GDPR and AI: Does Your Data Have to Stay in the UK?
- UK Data Storage vs AI Processing: What Is the Difference
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)