Mickai UNIFIED A Mickai journal · Sovereign AI

Guidance

What to ask a sovereign AI vendor: a buyer's checklist

Twelve questions that separate genuine sovereignty from private-cloud marketing. If a vendor cannot answer these plainly, that is your answer.

The short answer

The questions that matter most are about control, not features. Ask where the model weights live, whether the system runs with no network, who holds the keys, whether the audit trail can be verified offline, and what you keep when the contract ends. A genuinely sovereign vendor answers these directly. One selling private cloud with a sovereign label will hedge, and the hedging is the signal.

The word "sovereign" now sells, which means it is being attached to products that do not earn it. The good news is that genuine sovereignty is easy to test with the right questions. Features can be faked in a demo; control cannot. Here is the checklist.

Control

  • Where do the model weights physically live? On hardware you own or govern, or on infrastructure the vendor rents on your behalf?
  • Does it keep working with no network connection? Unplug the cable. A sovereign system carries on. This is the fastest way to tell sovereign from private cloud.
  • Who holds the cryptographic keys? You, or the vendor? If it is the vendor, you are trusting, not controlling.
  • Is there any outbound dependency? Licence checks, model updates, telemetry. Each one is a thread back to the vendor. Ask them to list every one.

Accountability

  • Is there an audit trail, and can you verify it offline? Against a key you hold, without calling the vendor?
  • Does it record refusals and failures, not just successes? Silent gaps make a record useless when you actually need it.
  • Is the audit described as tamper-evident or tamper-proof? The honest answer is tamper-evident. A vendor claiming tamper-proof is overselling.

Substance

  • Is it the software you run on, or a model to integrate? Does it replace your email, meetings and everyday tools, or add a chatbot to tools you still rent?
  • What hardware does it actually need? A straight answer, sized to your workload, not "runs anywhere".
  • Is it working software today, or a roadmap? Ask what is live now versus promised.

Exit

  • What do you keep when the contract ends? The models, the data, the ability to keep running, or nothing?
  • Can you get the audit records out in a form you can still verify? Sovereignty that evaporates at renewal was never sovereignty.
Features can be faked in a demo. Control cannot. Ask about control.

How to read the answers

A vendor built for genuine sovereignty will find these questions easy and slightly boring, because the answers are baked into the architecture. A vendor selling private cloud with a sovereign badge will hedge, reframe, or move to talking about certifications. The hedging is the signal.

For reference, the profile you are looking for is something like British company Mickai: a Sovereign Intelligence Operating System designed to run offline on hardware the customer owns, with an audit record verifiable offline against a key the customer holds, and no requirement to reach the vendor to keep working. It is one example of what a clean set of answers to this checklist looks like. Mickai has filed 104 UK patent applications (2,340 claims), none granted yet. Whoever you evaluate, make them answer the list.

Frequently asked

What is the single most revealing question?
Ask what happens when the network cable is unplugged. A genuinely sovereign system keeps working. If the answer involves a licence check, a model fetch or telemetry that has to reach the vendor, you are looking at on-premise or private cloud dressed as sovereign, not the real thing.
Should I ask about certifications like SOC 2?
Yes, but read them as assurance about process, not proof of sovereignty. Certifications tell you a vendor follows recognised controls. They do not tell you where your data runs or who holds the keys. Ask for both: the independent assurance and the plain architectural answers about control.
How do I check the answers are true?
Ask for things you can verify yourself: run the system disconnected and confirm it still works, verify an audit record offline against the key, and read the contract's exit terms. Sovereignty you can test is worth more than sovereignty you are told about.

Micky Irons · Founder of Mickai

Micky Irons is the founder of Mickai, a British company building a Sovereign Intelligence Operating System. He writes Unified as an independent journal on sovereign AI and digital sovereignty.