Insights & thought leadership · Cyber · AI · Resilience

Perspective on the forces reshaping enterprise cyber risk.

This is where Professor Kai London publishes analysis and commentary for the people who carry cyber risk to the top table. Each piece works through what agentic AI, post-quantum migration, and live regulation — DORA, NIS2, the EU AI Act and the Cyber Resilience Act — actually mean for strategy, budgets and accountability. Written for CISOs, risk leaders and boards who need a clear read on what is already enforceable and what lands next.

Agentic AIPost-QuantumDORANIS2EU AI ActCRAIEC 62443
Agentic AI SecurityAI Agent GovernancePost-Quantum MigrationDORANIS2EU AI ActCyber Resilience ActIEC 62443Zero TrustOperational ResilienceBoard Cyber RiskNIST CSF 2.0NIST AI RMF Agentic AI SecurityAI Agent GovernancePost-Quantum MigrationDORANIS2EU AI ActCyber Resilience ActIEC 62443Zero TrustOperational ResilienceBoard Cyber RiskNIST CSF 2.0NIST AI RMF

Why this writing exists

Cutting through the noise on regulation and AI.

Cyber leaders are not short of headlines. They are short of clear, honest interpretation — analysis that says what a new regulation or technology shift genuinely changes, what is hype, and what a board should decide next. That gap is what these insights set out to close.

Professor Kai London writes from the seat, not the sidelines. With 25+ years across Banking, Aviation, Defence, Government and Critical National Infrastructure — and roles spanning VP, CIO, CTO, CISO and Head of Cyber Security, alongside a Big Four background — his commentary is grounded in what it takes to actually run DORA and NIS2 obligations in supervision, meet the EU AI Act and Cyber Resilience Act, govern fleets of autonomous AI agents and move an estate to post-quantum cryptography under real-world constraints.

The aim is practitioner-first: each article connects the regulatory and technical detail back to the questions risk leaders are being asked in the room — about exposure, accountability, resilience and trade-offs — so the reader leaves with a position they can defend, not just a summary.

As Founder & CEO of Quantum AI Systems Security LLC and an Honorary Professor in Cybersecurity, AI & Quantum Computing and Researcher at UCL, Kai keeps this commentary anchored in current research as well as live practice.

25+Years of frontline practice behind the commentary
5Published books on AI, trust and cyber security
6Core themes tracked across the insights library
UCLResearch anchoring AI, quantum & cyber commentary

The basis for the view

Commentary backed by deep accreditation.

The perspective offered here is informed by formal expertise across information security, cloud, AI governance and the EU regulatory landscape — not opinion in a vacuum.

CISSPCISMCCISOCISACRISCCCSPISO 27001 Lead AuditorISO 42001AIGPDORA Lead ManagerNIS2 Lead ManagerSABSATOGAF

Insight themes

The topics under analysis.

The commentary returns to six recurring themes — what is already enforceable, and what is about to land on the board agenda.

01
🤖

Agentic AI Security

Shadow agents with excessive permissions and no audit trail, fast-growing agent fleets, and agent identity and permission sprawl as the emerging attack surface.

02
🧬

Post-Quantum Migration

Cryptographic discovery and inventory, crypto-agility, and the 2030 deprecation horizon for RSA-2048 and P-256 — with FIPS 140-2 certificates now moved to NIST's Historical list.

03
⚖️

The EU AI Act

Transparency duties live since August 2026, GPAI rules already applying, and high-risk obligations deferred to December 2027 and August 2028 — translated into practical assurance, not another policy binder.

04
🏛️

DORA & NIS2 in Supervision

DORA applying since January 2025 and NIS2 now enforced through national law — ICT risk, third-party oversight, incident reporting and resilience testing under real scrutiny.

05
🛰️

The Cyber Resilience Act

Reporting obligations applicable since 11 September 2026 and full application from 11 December 2027 — what secure-by-design and vulnerability handling mean for products with digital elements.

06
🔒

OT, Zero Trust & Board Cyber Risk

Critical-infrastructure and OT/ICS resilience under IEC 62443, Zero Trust stripped back to NIST 800-207 fundamentals, and reporting risk to the board in language that informs decisions.

“

Regulation and AI are not problems to be summarised — they are decisions waiting to be made. My aim with every piece is to give cyber and risk leaders a defensible position, not just a digest of the latest headline.

From the bookshelf

Long-form thinking, published.

Where the insights compress an idea into commentary, the books explore it in full — forty-four titles on AI, trust and the future of cyber security.

BookAI & enterprise
AI Architects
On building AI into the enterprise
The roles, decisions and guardrails behind putting artificial intelligence to work responsibly at scale.
BookAI governance
AI on Trial
Accountability in the age of AI
Where responsibility sits when AI systems make consequential decisions — and how governance keeps pace.
BookCritical infrastructure
Invisible Airborne Perimeter
Security beyond the visible edge
Rethinking the perimeter for environments where the boundary is no longer where you think it is.
BookIdentity & trust
The Last Login
On identity, access and trust
A look at the moment of authentication — and what it reveals about how we extend and withdraw trust.
BookPost-quantum
TrustQuake
When the cryptographic ground shifts
The coming disruption to the trust foundations of digital systems, and what resilience looks like on the other side.

Follow the commentary

Keep up with the analysis.

New perspectives on cyber regulation, AI and resilience are shared on LinkedIn first. Follow along, or reach out there to discuss a piece or suggest a topic.