DEV Community

Micky Irons
Micky Irons

Posted on

What does people-led AI mean in practice?

People-led AI means a named person approves every consequential action before it takes effect, and the record shows who approved what, when and on what evidence. The system retrieves, drafts and proposes at full speed. A human decides. Accountability stays with that person, because it cannot be transferred to a model.

I have the same conversation with regulated buyers most weeks, and it stalls at the same point. Everyone can see what the technology drafts. Nobody can say who is answerable once a draft becomes an action. People-led AI is the answer we built into the Mickai Sovereign Intelligence Operating System, and it is an architectural commitment rather than a slogan. The system does the preparation. A named person authorises anything consequential. The record of that authorisation outlives the supplier, including us.

Why can accountability not transfer to a model?

Because there is nobody to hold. Accountability in UK regulation attaches to organisations and, in financial services, to named individuals under the Senior Managers and Certification Regime. A model cannot hold a senior management function, cannot be interviewed by a supervisor and cannot be sanctioned.

Data protection works the same way. The controller remains responsible for an outcome however it was produced, which is why the ICO's guidance on automated decision-making and profiling turns on whether human involvement was meaningful rather than whether a human was technically present. Someone who clicks approve without seeing the evidence has not supplied oversight. They have supplied a signature.

So the buying question is not whether a system is capable enough to act alone. It is who signs, and whether that person could defend the decision a year later. If they cannot see what the system was about to do, why it proposed that, and what it relied on, the accountability is fictional. Our design starts by refusing that fiction.

What counts as a consequential action?

An action is consequential when it leaves the organisation or changes a record that other people rely on. Sending a client communication. Filing a submission. Amending a case or customer record. Releasing a document to a third party. Granting access to a system. Committing money. Each of those waits for a named approver before it takes effect.

Everything upstream runs at full speed. Retrieval across internal documents, extraction, comparison, summarisation, drafting, analysis: none of it needs permission, because none of it is visible outside the team and all of it is reversible. The test I apply when we classify a new action in a studio is deliberately plain. If this turned out to be wrong, would somebody outside this room be affected, or would we have to explain ourselves to a regulator, a client or a court? If the answer is yes, it waits.

That line is worth drawing explicitly during procurement, because it is where systems differ most and where suppliers describe themselves most vaguely. Ask where it sits in anything you are evaluating, and ask who is able to move it.

How is an approval recorded so it can be checked later?

In the Open Audit Record. Every consequential action is sealed to it using ML-DSA-65, a parameter set of the post-quantum signature scheme NIST published as FIPS 204 in 2024. The sealed entry carries the action, the inputs it relied on, the model version that produced it, the hardware identity it ran on, the named person who approved it and the moment they did.

What matters is what happens afterwards. An auditor exports the record and verifies it offline with a public key, on a machine we have never touched, using tools that are not ours. An audit trail you can only read inside a supplier's console is a claim about the past. A record a third party can verify without that supplier is evidence about the past. Those are different things, and only one of them holds up in a dispute.

The OAR is tamper-evident, and that word is chosen carefully rather than out of modesty. Nothing about it stops a determined administrator altering a file. Altering the file breaks the signature, so verification fails and the alteration announces itself. Tamper-evidence is the honest property to claim, and it is the one an auditor can actually test.

Does putting a person in the loop slow the work down?

Less than buyers expect, because approval is the only step the person keeps. The system reaches the decision point with the draft written, the sources cited, the exceptions flagged and its reasoning stated in plain terms. The approver reads a prepared case instead of assembling one. Related items queue together, so somebody clears a batch in a single sitting rather than being interrupted repeatedly through the day.

Set that against how regulated teams work now, where a qualified professional does the assembly as well as the judgement, and in the teams I work with the assembly takes far longer than the judgement does. We are removing the assembly. We are deliberately not removing the judgement. The same rule holds across all 63 studios in SIOS, the 14 that are production-ready at launch and the 49 in development: prepare completely, then stop and ask.

How is this different from full autonomy?

The difference is ordering, and ordering is everything. A fully autonomous agent acts and leaves you to reconstruct the reasoning afterwards. People-led AI puts the decision before the effect, so no reconstruction is needed. Autonomy fails open, because the action has already landed by the time anyone notices. This fails closed, because nothing consequential happens while a person is absent and the work waits instead.

It also differs from the weaker versions of oversight now in circulation. A reviewer who cannot see the evidence is a rubber stamp. A log the supplier can regenerate is not an audit trail. A system that pauses for approval only when its own confidence is low has decided for itself where accountability applies, which is exactly the judgement a regulated organisation cannot delegate. I would rather build a system that proposes and waits than one that acts and explains afterwards, because only the first of those leaves a person in a position to say no.

The test of people-led AI is simple: when something goes wrong, a named person can be identified, and the evidence they saw can be reproduced by somebody who has no reason to trust us.

What does UK guidance expect of human oversight?

It expects oversight to be real, informed and documented. The ICO's guidance on AI and data protection places responsibility on the organisation deploying a system rather than on whoever supplied the model. Its position on solely automated decisions with legal or similarly significant effects rests on meaningful involvement by a person with the authority and the information to change the outcome, and the Data (Use and Access) Act 2025 changes how that regime works without removing the expectation that a person can intervene. The NCSC's guidelines for secure AI system development push the same way, treating logging, provenance and the ability to investigate an incident as design requirements rather than later additions.

None of that is satisfied by an interface with an approve button on it. It is satisfied when the approver sees the evidence, when the approval is bound to their identity, and when the whole sequence can be produced months later in a form somebody else can check. Sector rules add their own weight: firms supervised by the FCA and the PRA carry individual accountability, and every organisation processing personal data carries duties under the Data Protection Act 2018. The common thread is that a named human stays answerable.

What should a buyer ask a supplier to prove?

Five questions separate architecture from marketing. Which actions require human approval, and who is able to change that list? Is the approver's identity cryptographically bound to the action, or only written into a log? Can the audit record be verified offline, by us, using tools you do not supply? What exactly breaks if the record is altered? And can the whole system run on hardware we own, with no data leaving the building?

We built SIOS so that each of those answers is demonstrable rather than asserted. It runs on the customer's own hardware, offline capable, with no data egress, and 50 specialised models sit behind the studios. Mickai LTD is a UK company (Companies House 17166618) holding 104 filed UK patent applications that carry 2,340 claims across this architecture, filed and not granted, with the audit record and the approval model among them. The full architecture is set out at /sovereign-ai, and the closed beta at /beta is open, with one regulated company already onboarding as a design partner.

None of this makes AI simpler to adopt. It makes the accountability legible, which is the condition a regulated organisation has to meet before anything else is worth discussing.

Frequently asked questions

Does people-led AI mean a person has to check every output?

No. Retrieval, drafting, extraction, summarisation and analysis run without interruption, because that work is reversible and stays inside the team. Approval is reserved for consequential actions: anything that leaves the organisation, changes a shared record, grants access or commits money. The aim is to remove the assembly work, not the professional judgement.

Can an AI system be held accountable for a decision instead of a person?

No. Under UK regulation accountability attaches to the organisation and, in financial services, to named individuals under the Senior Managers and Certification Regime. A model cannot hold a senior management function, be questioned by a supervisor or be sanctioned. Data protection duties also stay with the controller, whatever produced the output.

What is the difference between human in the loop and people-led AI?

Ordering and evidence. Human in the loop often means a person could intervene in principle. People-led AI means the consequential action cannot take effect until a named person approves it, and that the approval, the evidence they saw and the model version are sealed into a record an auditor can verify independently later.

How do I prove to an auditor that a person approved an action?

Export the Open Audit Record and verify it offline with a public key, using tools the supplier does not provide. Each entry is sealed with ML-DSA-65, published by NIST as FIPS 204 in 2024, and carries the action, its inputs, the model version, the hardware identity and the named approver. Altered entries fail verification.

Does people-led AI still work if the system runs offline?

Yes, and it is designed that way. The Mickai Sovereign Intelligence Operating System runs on hardware the customer owns, offline capable, with no data egress. Approvals, identities and the sealed audit record are all local, so an air-gapped installation loses no oversight and the record still verifies on a separate machine.


Written by Micky Irons, founder and chief executive of Mickai LTD, which builds a sovereign AI operating system for regulated organisations. More at mickai.co.uk.

Top comments (0)