AI Governance · Security · Risk

Adopt AI with confidence.

I help agencies and enterprises govern and secure their AI — standing up oversight under NIST's AI Risk Management Framework, and controlling the fastest-growing risk in security: AI agents and machine identity. Move fast, without it blowing up.

Former DHS HART Deputy Director 30+ Years Federal Cybersecurity #32 BookAuthority Author Veteran-Owned · SAM-Registered
The Governance Gap

AI is moving faster than anyone's ability to govern it.

Agencies and companies are pushing AI and autonomous agents into production while their oversight, risk, and identity controls lag years behind. Regulators and boards have raised the bar — and most organizations have no working answer.

The hardest part is identity. AI agents are non-human actors operating inside your trust boundary with credentials you issued them — and almost no one can see, count, or govern them.

~100:1Machine identities now outnumber humans — most of them AI agents
18%Of organizations can confidently govern AI-agent identities
91%Run autonomous agents in production today
70%Grant AI systems more access than a human doing the same job
What I Do

Advisory that turns AI ambition into a program you can trust.

1

AI Governance Readiness Assessment

A fixed-scope, NIST AI RMF-based gap assessment of your AI use and oversight — with an AI inventory, risk register, and a prioritized roadmap.

2

Retained AI Governance Advisory

Ongoing senior guidance to stand up and run your AI governance program — policy, oversight, and the frameworks that keep you defensible.

3

AI Agent & Machine-Identity Governance

Discover, control, and monitor non-human and AI-agent identities — the spearpoint of modern identity security.

4

RMF / ATO Support for AI Systems

Bring AI-enabled systems through the Risk Management Framework and authorization — NIST 800-53 and the GenAI profile, done right.

5

Executive & Board Briefings

Clear, credible briefings that translate AI risk into decisions leadership can act on — boardroom to program office.

6

ISO 42001 & AI Compliance

Prepare your AI management system for ISO/IEC 42001 and the mandates your customers and regulators require.

Explore Services →
How Engagements Work

Start small, prove value, scale into a program.

STEP 01

Assess

A fixed-scope readiness assessment maps your AI landscape, risks, and gaps against NIST AI RMF and the rules that apply to you.

STEP 02

Roadmap

You get a prioritized, executable plan — and a clear picture of what governing your AI actually requires.

STEP 03

Advise & Operate

Retained advisory to execute the roadmap, brief leadership, and keep your program current as AI and the rules evolve.

Dr. Derek A. Smith
Dr. Derek A. Smith
FOUNDER & PRINCIPAL ADVISOR
Who You Work With

Federal-grade security, brought to your AI.

I spent 30 years inside federal cybersecurity and law enforcement — including as Deputy Director and Technical Program Manager of DHS's HART biometric program, leading 300+ personnel on one of the nation's most sensitive identity systems. I bring that same rigor to how agencies and companies govern and secure AI.

  • Former DHS HART Deputy Director
  • Doctor of Strategic Leadership
  • Certified AI Security Professional
  • C|CISO · CompTIA SecurityX · CySA+ · Security+ · ECSA
  • 5× published cybersecurity author
  • Juris Master in Compliance (in progress)
More About Derek →
The Defensible AI Program by Dr. Derek A. Smith
New Book

The Defensible AI Program

A Leader’s Playbook to Stand Up, Run, and Defend AI Governance — and Adopt AI With Confidence.

Adopt AI fast, leadership says. Stay defensible, oversight demands. Between those two pressures stands the security and governance leader — with no proven playbook. This is the operational field manual for that job: a four-phase lifecycle — Stand Up, Operate, Mature, Defend — one unified control set that reconciles NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OMB M-25-21 into 28 controls you can actually run, and a 90-day stand-up sequence that survives first contact with oversight.

Also by Dr. Smith
The AI-Powered Defender by Dr. Derek A. Smith
The AI-Powered DefenderHow Artificial Intelligence Is Transforming Cybersecurity
Authority

Recognized. Published. Trusted.

The Defensible AI Program — Stand Up, Run & Defend AI Governance
Cybersense — #32, BookAuthority Best Cybersecurity Books
Cloud Security & PAM — Defending the Keys to the Kingdom
The AI-Powered Defender — How AI Is Transforming Cybersecurity
Keynote — Infosecurity North America
Keynote — ISC2 Secure Summits
Featured — CNN · Forbes · Inc.

Federal-ready. Enterprise-trusted.

A veteran-owned small business, registered and ready to contract — as a prime or on your team — and equally at home advising a corporate boardroom.

OwnershipVeteran-Owned Small Business
RegistrationSAM.gov · UEI M4AAHT83AQJ3
NAICS541512 · 541519 · 541690
EngagementsPrime · Subcontract · Direct

Putting AI to work? Let's make sure it's governed.

A 30-minute conversation on where you are and what governing your AI actually takes.

Book a Consultation

Get new briefs in your inbox

Practical AI governance and security notes, sent when there's something worth reading. No spam.