Research at the frontier of cyber, AI & the quantum era.
Professor Kai London is an Honorary Professor in Cybersecurity, AI & Quantum Computing and a Researcher at UCL. His work asks how organisations stay trustworthy as cryptography, machine intelligence, and autonomous systems outpace the rules written for them — pursuing the governance of autonomous AI agents, post-quantum migration, the EU AI Act, zero-trust for machine identities, and the resilience of critical infrastructure under NIS2 and the Cyber Resilience Act. The questions are academic; the consequences are not.
The research agenda
Practice-informed scholarship on the technologies rewriting trust.
Professor Kai London holds an Honorary Professorship in Cybersecurity, AI & Quantum Computing and is a Researcher at UCL. His scholarship is grounded in practice: 25+ years as a CISO and senior security leader across Banking, Aviation, Defence, Government, and Critical National Infrastructure inform a research agenda concerned with how institutions remain accountable as cryptography, machine intelligence, and autonomy evolve faster than governance can follow.
Four themes anchor the work. The governance of agentic AI — shadow agents running with excessive permissions and no audit trail, and the identity sprawl that comes with growing agent fleets. Post-quantum migration: cryptographic discovery, agility, and a sequenced route off RSA-2048 and ECC P-256 before NIST deprecates them in 2030. Zero-trust architecture extended to autonomous and machine-to-machine systems, drawing on NIST SP 800-207 and, in OT and industrial estates, IEC 62443. And operational resilience under DORA, NIS2, the Cyber Resilience Act, NIST CSF 2.0 and the NIST AI RMF — where regulation, engineering, and accountability converge.
The aim is research that does not stay on the page: findings translated into teaching, standards, and decisions that institutions can actually adopt. Kai also writes for a wider readership, with ten published books examining AI accountability, machine trust, and the security of emerging systems.
He welcomes invitations to lecture, deliver keynotes, examine doctoral work, contribute to programme committees, and offer expert comment to journalists and policymakers.
Credentials & standing
Scholarship anchored in deep professional accreditation.
A breadth of certification across information security, cloud, AI governance, and the EU regulatory landscape — the technical grounding behind research that engages real systems and live regulation.
Research themes
The questions the work pursues.
Five lines of enquiry where cryptography, machine intelligence, and autonomy meet governance, standards, and accountability — each open to collaboration, supervision, and invited talks.
Agentic AI Security & Agent Governance
The enterprise's fastest-growing attack surface: shadow agents with excessive permissions and no audit trail, and the identity and permission sprawl that follows an expanding agent fleet.
Post-Quantum Migration
From crypto discovery and inventory to agility and sequencing — NIST deprecates RSA-2048 and ECC P-256 in 2030, and FIPS 140-2 certificates have now moved to the Historical list. "Harvest now, decrypt later" makes it a today problem.
AI Governance & the EU AI Act
Operationalising the EU AI Act, ISO/IEC 42001 and the NIST AI RMF — transparency duties already live, high-risk obligations landing in Dec 2027 and Aug 2028, and the auditable controls that answer both.
Zero Trust for Autonomous Systems
Extending NIST SP 800-207 to machine-to-machine traffic and autonomous agents, where identity, intent, and trust must be continuously verified.
OT/ICS & Critical-Infrastructure Resilience
IEC 62443 in industrial estates, alongside NIS2 enforcement and Cyber Resilience Act reporting duties — the regulated core of keeping essential services running.
Public Scholarship & Writing
Translating research into books, lectures, and commentary that reach students, practitioners, policymakers, and the wider public.
The hard problem is not building the next technology — it is keeping our institutions trustworthy as cryptography, intelligence, and autonomy outpace the rules we wrote for them. That gap is where my research lives.
Academic & professional standing
Where the research is grounded.
An honorary professorship and an active research base at UCL, set on more than two decades of senior practice in the field.
Get in touch
Invite a lecture, keynote, or collaboration.
For guest lectures, conference keynotes, doctoral examination, research collaboration, or expert comment, the best place to reach Professor London is LinkedIn.