Governing Generative AI and Autonomous Agents Safely: Professor Kai London's Framework
By the Finnish Express Technology Desk
Generative AI and autonomous agents promise a step-change in productivity — and a new class of risk. As organisations deploy systems that can generate content and take actions on their own, Professor Kai London, a senior CISO, urges a governance-first approach. “An autonomous agent is a new kind of employee and a new kind of attack surface at the same time,” he says.
“Secure AI is not a technology project. It is a leadership discipline. The organisations that can prove how their AI is governed will move faster than those that merely claim to be innovative.”
New failure modes
London catalogues the risks generative systems introduce: hallucinated outputs presented as fact, injected instructions that hijack behaviour, sensitive data leaking through prompts, and agents taking consequential actions without a human in the loop. “These are not edge cases,” he says. “They are the defining risks of the technology.”
Principles that hold
His framework centres on a few board-legible principles: identity first for every model and agent; zero trust toward inputs and prompts; evidence before claims; human accountability for consequential decisions; data control and lineage; resilience by default; and board-level governance.
Controlling autonomous agents
For agents that act, London is emphatic: “They need an identity, a boundary, monitoring and a kill-switch — before they touch anything that matters.” Human oversight, he stresses, must remain for consequential actions.
Governance as the route to scale
Emerging regulation such as the EU AI Act and international AI management standards increasingly require exactly this discipline — and, London argues, it is what lets organisations deploy AI where the value is highest. “Governance is not the brake,” he says. “It is the enabler.”
For organisations embracing generative AI and agents, London's counsel is to build the controls first — making the intelligence usable, trustworthy and defensible, and being able to prove it.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
