top of page
Screenshot 2022-07-08 at 13_edited_edite

Dr. Vourganas

I build the organisational capability required to deploy AI where failure has consequences.

From board-level AI strategy to information-system architecture, governance, cybersecurity and deployment, I work across the full transformation rather than treating technology, risk and compliance as separate programmes.

​

I have operated across regulated financial services, clinical AI, cybersecurity, critical infrastructure and public-sector innovation, designing AI governance, leading complex technology programmes, building applied AI and bespoke information systems, and advising executives on consequential adoption decisions.

​

My role is often to answer four questions before substantial investment or deployment proceeds:

​

What should we build?
Can the underlying organisation support it?
Can we govern and defend it?
Can we actually deploy it?

​

I then help design the strategy, systems, controls and delivery path required to make the answer yes.

Where I Operate

I work where AI strategy, system architecture, governance, and delivery converge, particularly in regulated environments where technical failure, weak accountability, or poor implementation can create material operational, financial, clinical, or regulatory consequences.

​

My work spans seven interconnected areas:

​AI Governance & GRC
I design governance, risk, assurance, and accountability structures that make AI systems defensible in practice, not merely compliant on paper. This includes decision rights, control frameworks, model risk, auditability, human oversight, and evidence structures capable of withstanding regulatory and executive scrutiny.

​

Executive AI & CAIO Mandates
I advise CEOs, boards, CTOs, CROs, and senior leadership on AI strategy, operating models, investment priorities, governance boundaries, and deployment decisions. In organisations without mature AI structures, this often means establishing the decision framework itself before individual technology choices can be made.

​

Advisory & Consulting
I assess whether proposed AI initiatives, platforms, and operating models are technically credible, appropriately governed, commercially defensible, and operationally deployable. My work includes readiness assessments, vendor evaluation, proof-of-concept governance, regulatory risk analysis, and executive go/no-go recommendations.

​

Digital Transformation
I design transformation programmes in which AI, data, information systems, governance, and organisational change are treated as one operating problem. The objective is not simply to introduce new technology, but to change how information is captured, decisions are made, processes operate, and accountability is maintained.

​

Programme & Project Delivery
I lead complex technology and AI programmes from concept through architecture, roadmap, workstream coordination, risk management, stakeholder alignment, regulatory milestones, and deployment. My experience spans multidisciplinary teams, funded programmes, clinical environments, public-sector initiatives, and multi-organisation consortia.

​

Applied AI Research & Development
I develop and evaluate AI systems where explainability, robustness, bias, cybersecurity, reproducibility, and governance are engineering requirements. My work spans trustworthy AI, explainable AI, intrusion detection, clinical decision support, model-risk analysis, and governance-aware machine-learning architectures.

​

Bespoke Information Systems & Enterprise AI Integration
I design information systems around the decision, data, workflow, and accountability structures they need to support. This includes AI-enabled clinical platforms, enterprise AI integration, cybersecurity systems, data architectures, monitoring and audit mechanisms, and governance-by-design controls embedded directly into the system architecture.

Where I Have Operated

Across these environments, I work across the full AI transformation lifecycle, from executive strategy and governance through applied AI development, information systems architecture, programme delivery, organisational transformation, and regulated deployment. I do not treat these as separate disciplines because, in high consequence environments, each constrains the others.

Cybersecurity and Critical Infrastructure

I have designed and evaluated AI capabilities for cybersecurity and critical infrastructure environments where failure can expose operational systems, institutional assets, and essential services.

​

My work combines applied AI research, explainable threat detection, intrusion detection, anomaly identification, risk prediction, information systems architecture, cybersecurity engineering, and governance design. I have developed methods for determining not simply whether an AI model performs, but whether it remains robust when data changes, an adversary adapts, the system is challenged, and an operator must defend the resulting decision.

​

I translate those technical findings into governance controls, assurance requirements, deployment criteria, and executive decisions. This means connecting model behaviour, attack surface, information flows, human oversight, auditability, and operational resilience into a single system view.

The result is not simply a better security model. It is a governable security capability that can be integrated into a wider information system and trusted under hostile operating conditions.

Digital Health

I have led the strategy, architecture, development, governance, programme delivery, and regulated deployment of AI enabled clinical systems within real patient care environments.

​

As CTO of a regulated digital health platform, I held executive responsibility for technology strategy, AI development, engineering direction, information architecture, clinical integration, security, regulatory readiness, and deployment. I led the platform from concept to regulated pilot operation while coordinating clinicians, engineers, researchers, institutional partners, and governance stakeholders.

​

I designed the information systems, risk structures, audit mechanisms, data controls, and accountability frameworks required to support AI enabled clinical decision support. I also contributed to applied AI research and patented approaches for diabetes management, translating clinical requirements into technically defensible and commercially viable system designs.

​

My work with cancer patients and healthcare organisations also exposed weaknesses in how clinical information was being collected and represented. I traced those weaknesses to the underlying data collection process, developed strategies for improving future data capture and governance, and contributed to the design of new information systems capable of supporting better analysis and decision making.

​

Clinical AI is one of the hardest tests of responsible deployment. The model must perform, but the organisation must also be able to explain the recommendation, trace the evidence, protect the patient, support the clinician, and defend how the system operates.

Financial Services

I work with financial organisations where AI adoption sits inside a wider system of regulatory accountability, cybersecurity, operational risk, data governance, technology architecture, and executive responsibility.

​

My work includes executive AI advisory, governance architecture, GRC, enterprise readiness assessment, third party AI evaluation, proof of concept programmes, model and data risk, information systems governance, cybersecurity assessment, and transformation roadmap design.

​

I translate obligations including the EU AI Act, revFADP, GDPR, ISO 42001, ISO 27001, and relevant financial sector expectations into operating structures that executives and delivery teams can actually use. This includes ownership, approval authority, risk classification, evidence requirements, human oversight, auditability, implementation controls, and deployment criteria.

​

I have advised CEOs directly on AI strategy, regulatory exposure, technology choices, organisational readiness, and investment priorities, including situations where no prior AI governance or operating structure existed.

​

I also evaluate technology vendors and AI platforms through structured technical, governance, security, and operational assessment, converting technical evidence into clear executive decisions on whether a capability should proceed, be redesigned, or be rejected.

​

The objective is not regulatory documentation. It is to determine whether the organisation can responsibly own, operate, secure, govern, and defend the AI capability once it becomes part of the business.

Digital Transformation and Enterprise AI

I lead AI transformation as an enterprise operating model problem rather than a technology acquisition exercise.

​

I start by establishing what the organisation is trying to change, which decisions AI will influence, who owns those decisions, how information moves through the organisation, which systems support the process, where risk and bias enter, and whether the existing operating model can sustain the intended capability.

​

I then connect executive strategy, AI governance, information systems design, cybersecurity, data architecture, programme delivery, organisational readiness, vendor selection, applied AI capability, and regulatory obligation into a single transformation model.

​

This frequently involves building capability where little or none previously existed. I design governance structures, readiness methodologies, system requirements, transformation roadmaps, programme priorities, accountability models, deployment gates, and executive decision frameworks. Where required, I also contribute directly to the architecture and development of bespoke AI enabled information systems rather than treating transformation as a procurement exercise.

​

I manage the transition from concept to implementation through structured programmes with defined scope, milestones, technical dependencies, risk ownership, stakeholder alignment, and deployment criteria.

​

The result is an organisation in which AI strategy, information systems, governance, risk, technology delivery, and operational accountability function as one capability rather than seven disconnected workstreams.

The common thread

Whether the environment is financial, clinical, cyber, infrastructure, or enterprise wide, my role is fundamentally the same.

​

I determine what should be built, whether the organisation can support it, how the underlying information system must operate, how the AI should be governed, what risks must be controlled, how the programme should be delivered, and whether the resulting capability is ready to be deployed.

​

That is the combination of executive AI leadership, governance, advisory, transformation, programme delivery, applied AI, and information systems engineering that defines my work.

Systems I Have Built
Private LLM Systems for Regulated Fintech

Large language models deployed in-house within a regulated payments perimeter, isolated from the cardholder data environment, with no public egress. A policy-enforcement gateway sits ahead of the model, handling identity and purpose validation, prompt-injection and data-loss controls, and tool authorisation; retrieval is confined to approved, access-controlled knowledge; consequential actions require human approval; and every interaction is written to an immutable audit trail. Designed from scratch to hold under PCI DSS and the EU AI Act.

Agentic AI Oversight System

A governance layer between autonomous AI agents and enterprise systems. Every consequential action an agent attempts, moving money, changing a customer record, accessing regulated data, is intercepted and evaluated by a deterministic policy engine against the agent's delegated authority, data classification, jurisdiction, financial impact, and current security posture, then allowed, restricted, routed for human approval, denied, or suspended. Approved actions execute under a single-use authorisation bound to the approved parameters, and the full decision and execution chain is recorded for audit. The system also discovers unauthorised Shadow AI across the organisation. Designed, built, and tested end to end.

Etheras. AI Cybersecurity & Governance Platform

An AI-driven cybersecurity and governance platform, conceived and built end to end. Explainability, bias detection, and real-time Tier 1 and Tier 2 auditing operate at its core, extended with counterintelligence, a layered governance-by-design architecture, zero-day detection, and an integrated attack-simulation lab. Governance is a structural property of the system, not an added control.

AI Governance Assessment Engine

An assessment engine built on a formal governance model. It scores an AI system across four structural dimensions, algorithmic fairness, model transparency, data governance, and human oversight, through a non-compensatory geometric scoring engine with sector-specific thresholds and a gate condition requiring every dimension to clear its floor. Each control is mapped to the specific obligation behind it across the EU AI Act, GDPR, ISO/IEC 42001, NIST AI RMF, and Swiss revFADP, and the output is a deployment determination with an executive action plan.

Explainable AI and Model-Audit System

An explainability and model-audit system that exposes a model's reasoning, surfaces bias, and produces a traceable evidence record. Designed and built end to end, hardware to model, and proven in a regulated clinical setting: a home-based rehabilitation platform that guides patient recovery and detects 17 comorbidities while remaining interpretable and clinically defensible. This work established the principle, interpretable and auditable AI, that runs through the systems above.

Continuous Assurance and Regulatory Intelligence System (FCRAS)  (In Development)

A platform that turns compliance from a periodic audit into a continuous operational process. Governed evidence pipelines ingest telemetry from across a fintech's estate, identity, SIEM, cloud, payment systems, AI registries, and an assurance engine tests whether controls are operating in real time, distinguishing a genuine control failure from missing or unreliable evidence rather than reporting false green. A regulatory-intelligence engine monitors legislation, supervisory guidance, and standards, isolates what changed, and maps each obligation to the affected systems, controls, and owners through a regulation-to-evidence knowledge graph. Currently at prototype stage.

Aegis AI Engineering and Assurance Platform (In Development)

An integrated system that develops advanced AI capability and continuously proves it remains reliable, secure, explainable and authorised for the environment it operates in. Algorithms are designed, challenged in simulation and adversarially tested before any operational use, and each approved capability is issued a validated operating envelope defining the tasks, data conditions, confidence thresholds and human oversight under which it may act. In operation, a control plane checks consequential outputs against that envelope and reduces authority automatically when assurance conditions are no longer met, while continuous monitoring detects drift, attack, behavioural change and explanation instability, triggering requalification rather than periodic review. Currently in development for a private defence client.

Does Your AI System Pass Governance Scrutiny?

Most organisations find out their governance has gaps at the worst possible moment, during regulatory review, audit, or after a deployment failure.


This executive assessment evaluates your AI system's readiness across four structural dimensions,  producing a deployment determination and executive action plan aligned with EU AI Act, ISO/IEC 42001, and Swiss revFADP.


No registration. No consultation required. Run it now.

​

​[Run the Assessment →]

Have a Governance Question?

Unsure how EU AI Act obligations apply to your system? Need to understand revFADP requirements for your deployment? Navigating FINMA expectations for AI in financial services?


The AI Governance Assistant provides structured, governance-aligned responses, grounded in international regulatory frameworks and real deployment experience across financial services, healthcare, cybersecurity, and critical infrastructure.
No registration. No consultation required. Ask now.

​​

[Ask the Assistant →]

c5cc93e7-f468-495a-9b2b-b2db8d667971 up.png
Applications of Machine Learning in Cyber Security: A Review

Journal of Cybersecurity and Privacy (MDPI), 2024​​

A structured review of ML and AI in cybersecurity, examining real-world applicability gaps and their implications for trustworthy, auditable AI governance.​​​​​​

[Read the paper →]

Responsible AI for Home-Based Rehabilitation
Sensors (MDPI), 2021​​​​

An ethical AI framework for home-based rehabilitation, introducing a hybrid machine learning model demonstrating governance-by-design in regulated clinical environments.​

[Read the paper →]​

Contact Information

  • LinkedIn

Thanks for submitting!

© Copyright
Research and applied experience spanning:

University of Cambridge · University of Strathclyde · Abertay University · University of Glasgow · University of Law
Industry partnerships across:

IBM · Siemens · European Space Agency · NHS · Macmillan Cancer Support · Intel
Government appointments across:
​
Hellenic Ministry of Development and Investments · Hellenic Air Force Academy · Hellenic Military Academy
bottom of page