Kirti Kumar helps European organisations build AI capabilities they control: sovereign by design, cyber-proof by construction, and compliant by evidence rather than by assertion.
Kirti Kumar is the practitioner European boards, regulators and engineering teams turn to when the question is not whether to use AI, but how to use it without handing control to someone else. His work sits at the intersection of three disciplines that rarely meet in one person: AI architecture, cyber security, and the economics that decide what actually gets built.
The position he has made his own is simple to state and hard to execute: sovereignty is a control-plane problem. The models will be rented for years to come. The harness around them, the knowledge they run on, the assurance that gates what ships, and the evidence that satisfies the regulator are all things an organisation can own today. Kirti designs that control plane and shows organisations how to run it.
He is known for making the case with numbers: measured bypass rates rather than vendor promises, unit costs rather than budgets, and dated obligations rather than principles. It is why his frameworks are adopted by teams who have to defend their choices to a board, a supervisor, and an attacker at the same time.
Each engagement ends with something that runs, something that can be measured, and something a regulator can read.
A layered reference architecture with a sovereignty score for every layer, tiered workloads, an owned model portfolio, and a policy-gated valve to the frontier. Sized from the workload, not the brochure.
Guardrails as control points on the request path, the harness as the enforcement point, a signed model supply chain, and detection rules that join what an agent reads, does and reaches.
Roles, dates and evidence for the AI Act, NIS2, DORA, the CRA and the GDPR, delivered as one pipeline that produces the technical file from the system's own telemetry.
A sovereign security operations model in which the agents that defend the estate are themselves governed, monitored and kept inside the enclave.
Kirti's cyber-economics method models a security programme as volumetric units, such as alerts, cases, detections, vulnerabilities and obligations, each with a unit cost sized from the organisation's own telemetry and priced from benchmarks. It reads financial pressure as the variable that decides whether a programme is bought for offence or defence, and it is the lens through which AI in the security operation is judged: by the cost per triaged alert with the human review inside it, not by a vendor's headline percentage.
Sign in with your LinkedIn profile or with a one-time code sent to your email. No passwords to remember.