Delegated AI authority
What changes in governance once software can authenticate, write, transact, communicate, and act across institutional boundaries on someone else's behalf.
The Architecture Of Permission CNN News18, July 2026AI governance researcher and practitioner
I work on the institutional questions that arrive when artificial intelligence stops producing recommendations and starts exercising authority inside regulated organizations.
Every agentic action crosses a chain of institutional permissions. Choose a case and watch where accountability actually breaks.
My research sits between two conversations that rarely meet. Technology pioneers write governance frameworks for systems they build and control. Regulated institutions inherit those systems and must answer for them to boards, supervisors, and the public. I work on translating between the two, and on the questions that only surface once a model is permitted to act on its own. I do this alongside executive work in financial services rather than only in the literature, which is why the framework is built to survive contact with a three lines of defense structure rather than to sit politely beside one.
Four questions run through everything I write. Who is authorized to act. Who can stop the action. What happens when a system changes after it was approved. And how an institution keeps meaningful control when the critical capability is supplied by someone else. My doctoral work answered them by comparing governance practice at IBM, Microsoft, Google DeepMind, OpenAI, and Anthropic against what regulated institutions actually do.
What changes in governance once software can authenticate, write, transact, communicate, and act across institutional boundaries on someone else's behalf.
The Architecture Of Permission CNN News18, July 2026Why capability, autonomy, and institutional authority are three separate problems, and why permission design ends up mattering as much as model intelligence.
The Most Dangerous AI Risk Isn't Hallucination, It's Behavioral Drift Forbes, April 2026How approval, validation, monitoring, and change control have to evolve once the systems under management are dynamic, opaque, and externally dependent.
The Dangerous Illusion Of Explainable AI In Modern Finance Forbes, January 2026What organizations and states need in order to govern consequential systems when the models, compute, infrastructure, and evidence all sit outside their direct control.
You Don't Control The Infrastructure Your Bank Runs On Forbes, June 2026Applied against the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SR 11-7 model risk management, and the Three Lines of Defense.
KARMA adapts governance mechanisms that technology pioneers deployed at scale for use inside regulated financial institutions, mapping four governance imperatives onto four operational pillars. Knowledge without Agency produces understanding without power. Agency without Knowledge produces power without direction.
A Delphi panel of eight experts spanning regulatory, technology, academic, consulting, and executive domains reached unanimous consensus across all 21 assessment items, with seven of eight recommending pilot testing.
Read the thesis in the institutional repositoryDefended with no revisions required. KARMA is the subject of Indian provisional patent application 202611072022, filed June 2026, sole inventor.
Most argument about AI governance is really an argument about how capable the models are. That is the wrong axis.
An institution's control over a system has never come from understanding it. It comes from keeping someone with the authority to stop it, and the evidence to justify stopping it. Approval is a moment. Deployment is continuous. The failures worth studying sit in the gap between the two, and that gap widens every time a system becomes more capable, more autonomous, or more dependent on a supplier the institution does not control.
Forty-three essays published since 2025 in Forbes, India Today, CNN News18, and CNBC-TV18, on AI governance, model integrity, institutional resilience, and technology policy. Filter by theme or by outlet.
These are the authoritative records of my academic, professional, and public policy work. If you are verifying an identity or checking a citation, start here.
I welcome conversations with researchers, regulators, journalists, and institutions working through the same questions.
Keynotes, panels, and closed-door briefings on agentic AI, model risk, and governance in regulated institutions.
Send an invitationJoint papers, institutional case studies, and framework development with academic and industry partners.
Propose a projectBackground or on-the-record commentary for reporters covering AI governance and systemic risk.
Get in touchFor conference programs, journal contributor notes, and panel introductions. Please use this rather than paraphrasing.
Dr. Aditya Vikram Kashyap is an AI governance researcher and practitioner working at the intersection of artificial intelligence, financial services, institutional accountability, and enterprise transformation.
His work focuses particularly on how organizations govern AI once it moves from experimentation into consequential institutional use. His areas of interest include Responsible AI, agentic AI, model risk management, delegated machine authority, governance of AI in regulated institutions, and the organizational controls required to translate AI principles into practice.
Alongside his executive work in financial services, Aditya conducts independent research on AI governance and emerging technology. His doctoral research examined how governance practices developed by leading AI technology organizations can be adapted for regulated financial institutions, resulting in the KARMA Framework for institutional AI governance.
He has more than a decade of experience across financial services technology, innovation, AI governance, regulatory risk, and enterprise transformation. His work has included the design and implementation of AI governance mechanisms, enterprise innovation programs, technology investment frameworks, and regulatory-facing technology initiatives.
Aditya holds an Executive Doctorate of Business Administration from Saint Mary's University, a master's degree from New York University, and a bachelor's degree from Drexel University. He is a Fellow of the Institution of Engineering and Technology (FIET), a Fellow of BCS, The Chartered Institute for IT (FBCS), a Fellow of the Institution of Electronics and Telecommunication Engineers (FIETE), and an IEEE Senior Member.
His broader interests include the governance of increasingly autonomous AI systems, institutional resilience, technological dependence, and the relationship between AI infrastructure, regulation, and state capacity.
The views expressed here are his own and do not represent those of any affiliated institution.