AEGIR: Agentic Explainable Governance and Incident Reasoning- A Logic-Constrained Multi-Agent Architecture for Sovereign Security Assurance in IT/OT Networks
| Reference number | |
| Coordinator | Högskolan Väst |
| Funding from Vinnova | SEK 5 000 000 |
| Project duration | September 2026 - September 2028 |
| Status | Ongoing |
| Venture | Advanced digitalization - Industrial needs-driven innovation |
| Call | Digital Resilience, AI and Cybersecurity |
Purpose and goal
The Agentic Explainable Governance and Incident Reasoning (AEGIR) project addresses security fragmentation across IT, OT, and IoT environments. It develops a privacy focused agentic AI framework to automate threat to compliance chain under human oversight, supporting the EU Network and Information Security (NIS2) Directive. All training, inference, and compliance evaluation execute entirely on premises within industrial security boundaries, preserving data sovereignty.
Expected effects and result
AEGIR delivers three TRL 5 components: a modular agentic AI pipeline for real-time threat-to-control reasoning; an explainable NIS2 mapping methodology giving reproducible audit trails; and a sovereign on-premises architecture validated in industrial testbeds. Pilot partners in water, electricity, heating, telecom and IoT gain a deployment package for NIS2 evidence requirements, replacing manual compliance work. Results are transferable across sectors, extensible to the CRA, and released openly.
Planned approach and implementation
AEGIR includes six work packages, TRL 3 to 5. WP1 coordination; WP2 builds expert-validated NIS2-to-framework datasets and an OT ontology; WP3 implements specialized agents for traceable assets to controls chains; WP4 adds a formal logic engine verifying every chain; WP5 validates the integrated system in shadow OT pilots across water, electricity and heating, feeding findings back to WP2/WP4; WP6 handles publications and open-source release. Fallbacks cover LLM performance and testbed access.