Aditya Vikram Kashyap

AI governance researcher and practitioner

Governing AI when it begins to act.

I work on the institutional questions that arrive when artificial intelligence stops producing recommendations and starts exercising authority inside regulated organizations.

Where does the authority stop?

Every agentic action crosses a chain of institutional permissions. Choose a case and watch where accountability actually breaks.

  1. Instruction received
  2. Identity verified
  3. Permission scope checked
  4. Approved version confirmed
  5. Action executes on the institution

A scholar-practitioner working inside the institutions he studies.

My research sits between two conversations that rarely meet. Technology pioneers write governance frameworks for systems they build and control. Regulated institutions inherit those systems and must answer for them to boards, supervisors, and the public. I work on translating between the two, and on the questions that only surface once a model is permitted to act on its own. I do this alongside executive work in financial services rather than only in the literature, which is why the framework is built to survive contact with a three lines of defense structure rather than to sit politely beside one.

Aditya Vikram Kashyap, AI governance researcher and practitioner
Aditya Vikram Kashyap

The institutional architecture of AI power.

Four questions run through everything I write. Who is authorized to act. Who can stop the action. What happens when a system changes after it was approved. And how an institution keeps meaningful control when the critical capability is supplied by someone else. My doctoral work answered them by comparing governance practice at IBM, Microsoft, Google DeepMind, OpenAI, and Anthropic against what regulated institutions actually do.

Delegated AI authority

What changes in governance once software can authenticate, write, transact, communicate, and act across institutional boundaries on someone else's behalf.

The Architecture Of Permission CNN News18, July 2026

AI dependence and resilience

What organizations and states need in order to govern consequential systems when the models, compute, infrastructure, and evidence all sit outside their direct control.

You Don't Control The Infrastructure Your Bank Runs On Forbes, June 2026

Applied against the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SR 11-7 model risk management, and the Three Lines of Defense.

Selected work.

18%of financial institutions have implemented continuous AI monitoring. The other 82% rely on periodic review, leaving blind spots between validation events.Boston Consulting Group, 2024
72%of AI governance decisions in financial services are made by business units with limited governance oversight, against 34% in mature technology companies.Bain
31%of 700 board directors and executives across 56 countries reported that AI is not on the board agenda at all.Deloitte Global Boardroom Program, 2025

Doctoral research, Saint Mary's University, 2026

Bridging the Governance Gap

KARMA adapts governance mechanisms that technology pioneers deployed at scale for use inside regulated financial institutions, mapping four governance imperatives onto four operational pillars. Knowledge without Agency produces understanding without power. Agency without Knowledge produces power without direction.

A Delphi panel of eight experts spanning regulatory, technology, academic, consulting, and executive domains reached unanimous consensus across all 21 assessment items, with seven of eight recommending pilot testing.

Read the thesis in the institutional repository

Defended with no revisions required. KARMA is the subject of Indian provisional patent application 202611072022, filed June 2026, sole inventor.

Governance imperative Operational pillar K Knowledge What the system can and cannot do Pillar 2 Lifecycle Governance When is assessment required? A Agency Binding authority to intervene Pillar 1 Governance Architecture Who decides? R Responsibility Accountability to named individuals Pillar 3 Accountability and Assurance How is governance verified? MA Machine Accountability Technical limits on system behavior Pillar 4 Control Standards What constrains the system itself?

Most argument about AI governance is really an argument about how capable the models are. That is the wrong axis.

An institution's control over a system has never come from understanding it. It comes from keeping someone with the authority to stop it, and the evidence to justify stopping it. Approval is a moment. Deployment is continuous. The failures worth studying sit in the gap between the two, and that gap widens every time a system becomes more capable, more autonomous, or more dependent on a supplier the institution does not control.

Writing.

Forty-three essays published since 2025 in Forbes, India Today, CNN News18, and CNBC-TV18, on AI governance, model integrity, institutional resilience, and technology policy. Filter by theme or by outlet.

Theme
Outlet

Find and cite my work.

These are the authoritative records of my academic, professional, and public policy work. If you are verifying an identity or checking a citation, start here.

Background.

Education

  • Executive Doctorate of Business AdministrationSaint Mary's University, Sobey School of Business, 2026
  • Master of Science, Management and SystemsNew York University, 2016
  • BS/BA, Management Information Systems, Economics and MarketingDrexel University, 2013

Fellowships and professional bodies

  • Fellow, Institution of Engineering and TechnologyFIET
  • Fellow, BCS, The Chartered Institute for ITFBCS
  • Fellow, Institution of Electronics and Telecommunication EngineersFIETE
  • Senior Member, IEEEProfessional grade
  • Ambassador, FINOSThe Linux Foundation

Recognition and service

  • Durland Family Doctoral Convocation AwardSaint Mary's University, 2026
  • Judge, QS Reimagine Education Awards2025
  • LinkedIn Top VoiceLeadership and IT Strategy, 2024
  • Outstanding Recent Alumni AwardDrexel University
  • Distinguished Young Alumnus AwardNew York University, 2020
  • Reviewer, Research Ethics BoardSaint Mary's University, TCPS 2
  • Alumni BoardDrexel University, LeBow College of Business

Three ways to work together.

I welcome conversations with researchers, regulators, journalists, and institutions working through the same questions.

Speak at your event

Keynotes, panels, and closed-door briefings on agentic AI, model risk, and governance in regulated institutions.

Send an invitation

Collaborate on research

Joint papers, institutional case studies, and framework development with academic and industry partners.

Propose a project

Ask for comment

Background or on-the-record commentary for reporters covering AI governance and systemic risk.

Get in touch
A bio you can copy

For conference programs, journal contributor notes, and panel introductions. Please use this rather than paraphrasing.

Dr. Aditya Vikram Kashyap is an AI governance researcher and practitioner working at the intersection of artificial intelligence, financial services, institutional accountability, and enterprise transformation.

His work focuses particularly on how organizations govern AI once it moves from experimentation into consequential institutional use. His areas of interest include Responsible AI, agentic AI, model risk management, delegated machine authority, governance of AI in regulated institutions, and the organizational controls required to translate AI principles into practice.

Alongside his executive work in financial services, Aditya conducts independent research on AI governance and emerging technology. His doctoral research examined how governance practices developed by leading AI technology organizations can be adapted for regulated financial institutions, resulting in the KARMA Framework for institutional AI governance.

He has more than a decade of experience across financial services technology, innovation, AI governance, regulatory risk, and enterprise transformation. His work has included the design and implementation of AI governance mechanisms, enterprise innovation programs, technology investment frameworks, and regulatory-facing technology initiatives.

Aditya holds an Executive Doctorate of Business Administration from Saint Mary's University, a master's degree from New York University, and a bachelor's degree from Drexel University. He is a Fellow of the Institution of Engineering and Technology (FIET), a Fellow of BCS, The Chartered Institute for IT (FBCS), a Fellow of the Institution of Electronics and Telecommunication Engineers (FIETE), and an IEEE Senior Member.

His broader interests include the governance of increasingly autonomous AI systems, institutional resilience, technological dependence, and the relationship between AI infrastructure, regulation, and state capacity.

The views expressed here are his own and do not represent those of any affiliated institution.