AI Governance · OT/ICS Security · Critical Infrastructure
AI governance and OT security for critical infrastructure
I develop research, frameworks, and assurance models for governing AI in high impact operational environments, with a focus on the electric sector, ICS/OT cybersecurity, and cyber physical AI risk. Author of AAIGF-E, the first control mapped AI governance framework built for the Bulk Electric System.
Cybersecurity GRC experience across smart city, critical infrastructure, and OT/ICS aligned environments, including governance work connected to a national smart city development program aligned with Saudi Vision 2030.
AAIGF-E AuthorNIST NCCoE Community MemberISA99 / 62443 ContributorOWASP Agentic AI ReviewerIEEE P3396 Working GroupIEEE and ISA Senior MemberCISM · CISA · CRISCAAIA · AAISMISO 42001 LI · ISO 27001 LA8 SSRN papers · 250+ downloads
The Adaptive AI Governance Framework for the Electric Sector closes the governance gap that exists when AI systems operate inside the Bulk Electric System. No existing mandatory standard currently governs model integrity, adversarial threats, drift detection, or AI output influence on operators. AAIGF-E is a CIP overlay, not a replacement.
NERC CIPMITRE ATLASNIST AI RMFISA/IEC 62443ISO/IEC 42001
AAIGF-E Executive Brief — 4 page management overviewDownload PDF
Standards and Community Engagement
NIST NCCoE
Manufacturing Community of Interest
Member of the NCCoE Manufacturing Sector Community of Interest, receiving updates on events, publications, and opportunities to contribute to cybersecurity guidance for manufacturing and OT environments.
ISA99 / 62443
Industrial cybersecurity standards activity
Participant in ISA99 related standards discussions, including JT 62443 06 activity. Submitted comments on ISA IEC 62443 SR 3.1 to SR 3.5 focusing on AI/ML security gaps, and contributed feedback on Security Level Representation options.
OWASP
Agentic AI security and governance
Reviewer and contributor to OWASP agentic AI security and governance work, with emphasis on AI risk scoring, assurance, and governance considerations.
AAIGF-E: Adaptive AI Governance Framework for the Electric Sector
Presents a 111 control, 11 domain governance framework for AI systems in Bulk Electric System environments, mapped to NERC CIP, NIST AI RMF, MITRE ATLAS, ISA/IEC 62443, and ISO/IEC 42001.
The ACP Model: Operational Authority Drift in AI Enabled Industrial Systems
Introduces the ACP, AI Consequence Propagation, model to explain how authority drift in AI enabled industrial systems can create governance, safety, and operational risk.
AI Governance in Smart Grids and Industrial Automation: Integrating RAG with Framework Mapping
Explores how retrieval augmented generation interacts with AI governance requirements in smart grid and industrial automation contexts, including mapping across major AI, cybersecurity, and energy frameworks.
Exploring the Role of RAG in Enhancing Cybersecurity GRC Frameworks
Examines how retrieval augmented generation can support cybersecurity GRC workflows, including compliance traceability, evidence retrieval, and control mapping.
Guest appearance on AI governance, OT/ICS security, and critical infrastructure · Podcast
Upcoming
Research Aligned Advisory
A
AI governance reviews
Reviewing AI governance models, assurance controls, and gaps in high impact AI deployment plans for energy and industrial organizations.
B
OT/ICS AI risk workshops
Structured sessions on agentic AI risk, operational data trust, cyber physical threats, and assurance design for OT environments.
C
Framework mapping
Mapping AI governance requirements to NERC CIP, NIST AI RMF, ISA/IEC 62443, MITRE ATLAS, and ISO 42001 for utilities and asset owners.
Available for pilot assessments, framework reviews, and advisory engagements. Inquire for scope and availability.
Selected Activity
Energy Digital Q and A forthcomingSSRN · 8 published papersIEEE Istanbul 2026 · accepted paperProtect It All Podcast · upcoming guest appearanceNIST NCCoE · ISA99 / 62443 · OWASP engagement
Available for research aligned advisory work
If your work involves NERC CIP compliance, OT/ICS security, AI deployment at a utility, smart infrastructure assurance, or AI governance research, I would value a conversation.