惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
V
Visual Studio Blog
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
爱范儿
爱范儿
Vercel News
Vercel News
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
W
WeLiveSecurity
B
Blog RSS Feed
P
Privacy International News Feed
Latest news
Latest news
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News
人人都是产品经理
人人都是产品经理
D
Docker
Blog — PlanetScale
Blog — PlanetScale
C
Cisco Blogs
T
Threatpost
aimingoo的专栏
aimingoo的专栏
C
Cybersecurity and Infrastructure Security Agency CISA
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
有赞技术团队
有赞技术团队
L
Lohrmann on Cybersecurity
F
Full Disclosure
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
Security Latest
Security Latest
雷峰网
雷峰网
T
Tor Project blog
Cisco Talos Blog
Cisco Talos Blog
Spread Privacy
Spread Privacy
K
Kaspersky official blog
I
Intezer
The Register - Security
The Register - Security
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
P
Privacy & Cybersecurity Law Blog
Simon Willison's Weblog
Simon Willison's Weblog
腾讯CDC
U
Unit 42
T
Tenable Blog
IT之家
IT之家
NISL@THU
NISL@THU

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
From Sellafield to Sovereign AI: the engineering arc behind Mickai
Micky Irons · 2026-05-08 · via DEV Community

A founder note on the technical thread that ties Cumbria to the UK Atomic Energy Authority to Web3 to Mickai. The same question recurs in every regulated industry: who holds the keys, who can verify the chain, and does the chain still make sense after the vendor changes. Nuclear had it solved. Finance had it solved. The AI industry was making the same mistake again.

The lede

I am Micky Irons, founder of Mickai LTD. Mickai LTD is a private limited company incorporated in England and Wales, registered at 20 Wenlock Road, London, N1 7GU under company number 17166618. The product the company ships is a Sovereign Intelligence Operating System, twenty-five specialist brains across six subsystems, with a post-quantum signed audit ledger underneath and a browser-resident verifier that runs offline. The architecture is filed at the UK Intellectual Property Office across thirty-one applications. I will get to the architecture. First, the engineering arc that produced it.

From Sellafield to Sovereign AI

From Sellafield to Sovereign AI. The engineering arc behind Mickai.

Cumbria. Sellafield. Commissioning engineer.

My engineering career began as a commissioning engineer in the nuclear industry in Cumbria. Seven years there. The role of a commissioning engineer is the role that nobody outside the regulated industries thinks about. The plant has been built. The systems are installed. The question the commissioning engineer answers is whether the as-built equipment behaves the way the design said it would, under every state the plant might enter, with every record needed to defend that answer to a regulator twenty years later. The job is in the gap between design and operation. The job is to make the audit trail real, not aspirational.

Sellafield taught me one thing that has stayed with every subsequent decision I have ever made about software. In a nuclear context the operator never cedes audit control. The operator holds the keys. The operator signs the records. If a vendor leaves the site, the audit chain still verifies, because the chain was never the vendor's. The trust assumption is the operator's, not the supplier's. Every safety-critical action has a signed record under operator-held cryptography, and the chain is replayable independently. The discipline is older than software. It is older than computers. The substrate predates the vendor and survives the vendor. That is the only reason regulators have any path to inspect the chain.

Culham. UK Atomic Energy Authority. Core fusion engineering team.

From Sellafield I joined the UK Atomic Energy Authority and worked on a fusion reactor as part of the core engineering team. Two years on the fusion programme. Working with world-leading scientists, on equipment built with an engineering tolerance budget you would not believe until you measured it, taught me a different lesson. Substrate is not a bolted-on layer. The substrate has to be part of the design from the first millimetre. If the audit, the safety, the provenance, the cross-checks, the failure-mode tracking are not wired into the substrate from inception, they cannot be retrofitted. They become an afterthought. Afterthoughts fail under regulatory inspection.

Fusion is a discipline where the experiment is the regulatory artefact and the regulatory artefact is the experiment. Every shot has to be reproducible. Every measurement has to be attributable to its diagnostic, to the calibration record of that diagnostic, to the operator who took the calibration, to the engineering change record that authorised that operator. The chain is dense, and it is signed, and it is the entire point. You do not get to argue with the chain.

Two industries, the same lesson. The substrate is the product. Everything else sits on top of the substrate.

Web3. The cryptographic primitive in plain commercial form.

I left the regulated engineering world for Web3 and was the original co-founder of Collector Crypt, the digital trading-card marketplace that has gone on to operate as a live on-chain secondary market for collectible cards. Around it I founded and backed several other ventures in the blockchain and distributed-ledger space, and across the portfolio raised close to GBP 350 million for projects ranging from Web3 infrastructure to programmable collectibles to the Irons Foundation. The portfolio cared about a lot of different things on the surface. Underneath, every project was the same question, dressed for a different audience: how do you let an operator hold a cryptographic position that survives any one supplier, any one platform, any one cloud.

Blockchain provided the primitive in a form anybody could read. Hash-linked records. Append-only logs. Signature schemes that could verify offline. The same primitive nuclear had been quietly using under regulator scrutiny for forty years. Web3 made the substrate visible. The substrate, when treated as the product instead of an afterthought, dissolves vendor lock and makes audit a public good. That was the second confirmation of the same engineering thesis.

Then I started looking at the AI market.

By 2024 it was clear that the artificial-intelligence industry was racing to repeat the trust mistake the regulated industries had already solved. Frontier model APIs. Vendor-held audit logs. Operator data shipped to a hyperscaler. Conversation history retained on a vendor platform. Audit signatures, where they existed at all, signed by the vendor under the vendor's keys. The audit posture for an enterprise customer of a frontier AI was strictly worse than the audit posture for a commissioning engineer at Sellafield in the 1980s. The difference was that nobody in the AI industry was framing it as an audit problem. They were framing it as a model problem.

The model is not the problem. The substrate is the problem. A frontier model is a fast specialist, and a useful one, and a generally honest one once it is told what to do. None of that helps the operator if the audit chain underneath the action is the vendor's. None of that helps the regulator if the verifier the regulator runs is hosted by the vendor. The trust assumption is misplaced by one layer.

The gap, named in primitives.

The gap I kept hitting in every conversation with technical decision-makers in defence, the NHS, the FCA-regulated banks, and the Cabinet Office was the same. They could not adopt frontier AI under their regulatory floor. The model was good enough. The audit substrate was vendor-shaped. The data residency was vendor-shaped. The verifier was vendor-shaped. None of that survives the vendor changing, the vendor failing, the vendor being acquired, or the regulator turning up two years later asking what the system did.

The fix is structural. The audit format has to be the operator's, not the vendor's. The signing keys have to be in TPM on the operator's hardware. The verifier has to run offline in any browser. The signature algorithm has to survive the threat horizon the operator will be operating in by 2030, which means post-quantum from inception. The model has to run on the operator's iron when the data class requires it, and the model has to be substitutable when the operator chooses to swap it without losing the historical chain.

That is not an incremental product feature. That is an architecture. So I built the architecture.

Mickai. The architecture as the product.

Mickai is the architecture as the product. Six subsystems: Multi-Brain Orchestration, Agent Tooling, Knowledge and Memory, Artifacts, Vinis Voice, Governance Layer. Twenty-five specialist brains across those subsystems, with a deterministic Arbiter Brain at the head and a hash-linked, post-quantum signed audit ledger at the foot. The audit ledger is signed under FIPS 204 ML-DSA-65, the algorithm that NIST standardised in 2024 for the post-quantum era. Every committed action across all twenty-five brains is serialised in CBOR, hashed under SHA-3-512, signed under the operator's TPM-bound key, and appended to a chain that any regulator can walk in any browser tab with no network call. The browser-resident verifier emits one of four deterministic verdicts per record. VERIFIED. INVALID. STALE. REVOKED. There is no fifth verdict. There is no probabilistic answer. The chain either holds or it does not.

The architecture is filed at the UK Intellectual Property Office across thirty-one applications. The technical deep dive on the architecture is at mickai.co.uk/articles/sovereign-intelligence-operating-system-on-device-technical-deep-dive. The piece you are reading is the engineering history that produced the architecture, not a restatement of it.

Where this matters

Defence, where a unit operating under JSP 440 cannot send classified workloads to a frontier model API. Government, where NCSC, DSIT, and ICO have all published guidance that treats vendor-key custody as a structural deficiency. Finance, where PRA SS1/23 names third-party AI dependency as concentration risk that must be priced into operational resilience. Healthcare, where NHS DSPT alignment makes extra-territorial data flow a structural blocker for clinical AI. Each of those four sectors has a regulatory floor below which the data cannot leave the operator's perimeter, and each has been waiting for an architecture that respects the floor. Mickai is that architecture. The four sectors are the customer.

What I am doing now

Mickai LTD is the company. Mickai is the product. Mickai™ is the trademark. The architecture is open at the schema layer and the conformance-vector layer, with patent claims protecting the inventive composition. UK Managed Service Providers, sovereign-tech buyers, and the four anchor sectors above are the active conversation. A sandboxed instance for technical evaluation is available on request to press@mickai.co.uk.

The engineering arc has been longer than the venture, and the venture is the engineering arc made visible. Nuclear taught me that the audit substrate is the operator's. Fusion taught me that the substrate has to be part of the design from inception. Web3 made the cryptographic primitive commercially legible. Mickai is what happens when you apply the same primitive to artificial intelligence. The architecture is the differentiator. The architecture is the product.


Originally published at mickai.co.uk.
Author: Micky Irons, founder of Mickai LTD.