KTU / CYBER SUPERINTELLIGENCE VISION

Trustworthy cyber
superintelligence.

Turn sovereign AI computing capacity into trustworthy, auditable and controlled cyber intelligence.

KTU Cybersecurity Superintelligence and Assurance Hub

SI is a long-term research direction. This is a proposed integration of capabilities.

Connect secure AI, cyber defence, digital forensics, quantum-safe technologies, cyber-physical experimentation and AI governance in an auditable system.

01 / INTEGRATION

Computing becomes intelligence through assurance.

Centre capabilities form a loop in which every action has verification, evidence and defined limits on autonomy.

DATA AND COMPUTING / FOUNDATION

Sovereign data and computing capacity

Domain data, HPC and a secure AI execution environment.

CENTRE / INTEGRATION

Models, agents and verification

Sandbox, DFIR, the laboratory, Quantum, DigiDefence, human decisions and CAISO.

SI / RESEARCH DIRECTION

Trustworthy domain intelligence

Explainable decisions. Verifiable actions. Governed autonomy.

A controlled improvement loop

SELECT A STEP IN THE LOOP

01 / IN THE SI SYSTEM

Forms risk scenarios and human decisions

Generate risk scenarios and human decision reference points for studying agentic-system behaviour and the limits of its autonomy.

INPUT

A risk scenario and a team decision

OUTCOME

Scenarios comparing human and AI decisions

Learn more

Quantum security and human control apply across the whole system. Results return to the Sandbox and inform the next model or agent version.

Cyber Agent Fabric

Proposed specialist agents would share tasks and evidence, while an orchestrator would build a common incident situation model.

SOC AgentCTI AgentDFIR AgentMalware AgentOT AgentRisk AgentCompliance AgentPQC AgentRed Team AgentBlue Team Agent
Connection to SI

02 / CENTRE CAPABILITIES

Eight capabilities. One system.

Existing capabilities would develop into interconnected functions within the cyber superintelligence system.

01 / 08

AI Sandbox

Assurance gates for models and agents, from security testing to verification of human control.

ROLE IN SI

Assurance gates

Connection to SI
02 / 08

AI-native DFIR

Reconstruct agent actions and connect context, tools and outcomes through a verifiable chain of evidence.

ROLE IN SI

A chain of action evidence

Connection to SI
03 / 08

Cyber-Physical AI Forensics Laboratory

Faraday cage and ISO 5 zone for controlled validation of the digital and physical effects of AI decisions.

ROLE IN SI

Physical-effect validation

Connection to SI
04 / 08

Quantum-Safe Intelligence

QKD, PQC and crypto-agility connect long-term communications security with AI infrastructure management.

ROLE IN SI

A secure cryptographic foundation

Connection to SI
05 / 08

DigiDefence Use-Case Layer

FinTech, CTI, OT, IoT and information-space research provide domains for specialist models, agents and scenarios.

ROLE IN SI

Domain application scenarios

Connection to SI
06 / 08

[NE]rizikuok AI Edition

AI incident simulations compare team and agent decisions and feed scenarios back into the Sandbox.

ROLE IN SI

Human-AI decision interaction

Connection to SI
07 / 08

CAISO Framework

An AI security governance framework linking risk, agent permissions, incident response and permitted autonomy.

ROLE IN SI

Governance of autonomy limits

Connection to SI
08 / 08

Human-AI Teaming

Human resilience and decision comparison define the human role in governed agentic defence.

ROLE IN SI

The human role in autonomous defence

Connection to SI

03 / EVOLUTION

From assured AI to governed autonomy.

Three development stages. Capability growth remains tied to evidence, human control and assurance.

01 / STAGE

Assured AI

Can we trust AI?

  • AI Sandbox 2.0 and standardised AI red teaming
  • CAISO Framework and an AI-native DFIR evidence schema
  • A secure AI environment and initial CERT and telemetry models
  • [NE]rizikuok AI Edition

02 / STAGE

Agentic Cyber Intelligence

Can we allow AI to act?

  • Integration of SOC, CTI, DFIR, OT and PQC agents
  • Agentic-system assessment in the AI Sandbox
  • The laboratory as a cyber-physical validation environment and the first PQC pilot
  • CAISO consulting and training services

03 / STAGE

Trustworthy Domain Superintelligence

How much autonomy can safely be granted to a system whose domain capabilities could exceed those of an individual human expert?

  • Integration of detection, correlation, investigation and hypothesis generation
  • Simulation, planning and recommendations
  • Research into acting under bounded conditions and verifying results
  • Action explanations and a forensically verifiable chain of evidence

Proposed integration direction

AI Sandbox

CURRENT CAPABILITY / FOUNDATION

Technical audits of AI models, including bias, resistance to manipulation and cybersecurity assessment.

PROPOSED DEVELOPMENT

Develop the AI Security and Superintelligence Sandbox: test models, RAG, MCP, agents and complete agentic systems before granting permission to act.

PURPOSE IN THE SI SYSTEM

Provide evidence for deciding the conditions and degree of autonomy that can be granted to a system developing towards domain superintelligence.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Prompt injection, RAG poisoning and model supply-chain testing
  • Assessment of MCP, tool use and agent permissions
  • Multi-agent behaviour and autonomous action safety testing
  • Verification of human override, kill switches and graceful degradation

Proposed integration direction

AI-native DFIR

CURRENT CAPABILITY / FOUNDATION

Collection and analysis of electronic evidence through digital forensics services.

PROPOSED DEVELOPMENT

Develop the AI-Native Forensics Platform and an AI evidence schema, correlating decision context, agent actions and digital and physical outcomes.

PURPOSE IN THE SI SYSTEM

Enable verification of what the system actually did, reconstruction of its action sequence and assessment of its decision explanation against collected evidence.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Correlation of prompts, system context, RAG sources and model versions
  • Analysis of agent memory, MCP actions, API calls and IAM decisions
  • Reconstruction of tool execution, file changes and network traffic
  • A model for generating forensic timelines and investigative hypotheses

Proposed integration direction

Cyber-Physical AI Forensics Laboratory

CURRENT CAPABILITY / FOUNDATION

A Faraday cage with an ISO 5 zone for isolated, repeatable studies of electronics, communications, sensors and security equipment.

PROPOSED DEVELOPMENT

Extend the laboratory into a forensics and cyber-physical validation environment for AI, IoT, RF, satellite terminals, quantum communications and edge devices.

PURPOSE IN THE SI SYSTEM

Experimentally test whether the system's recorded digital action matches its real physical effect, returning evidence for assessment.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Studies of AI edge, IoT and embedded AI devices
  • Studies of RF systems, mobile devices and satellite terminals
  • Studies of quantum communications hardware and AI-controlled sensors
  • Validation of effects produced by drones and autonomous systems

Proposed integration direction

Quantum-Safe Intelligence

CURRENT CAPABILITY / FOUNDATION

QKD, post-quantum cryptography and EuroQCI activities, including Lat-LitQN and PIONIER-Q-SAT, SpinQ and quantum algorithm research.

PROPOSED DEVELOPMENT

Connect QKD, PQC and quantum-assisted security research with sovereign AI infrastructure, investigate AI-managed crypto-agility and conduct PQC pilots.

PURPOSE IN THE SI SYSTEM

Protect critical communication and control channels of the intelligence system and support cryptographic migration planning under quantum risk.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • QKD protection for critical AI infrastructure channels
  • Cryptographic asset inventory and quantum-risk assessment
  • PQC migration plans and interoperability tests
  • Migration-status monitoring and security research using quantum algorithms

Proposed integration direction

Cyber Agent Fabric

CURRENT CAPABILITY / FOUNDATION

A proposed new agentic layer connecting existing research areas with planned models.

PROPOSED DEVELOPMENT

Develop the Cyber Agent Fabric with a KTU Cyber Intelligence Orchestrator to assign tasks, collect evidence and build a shared incident situation model.

PURPOSE IN THE SI SYSTEM

Combine individual model capabilities into coordinated domain intelligence, with permissions defined by Sandbox evidence and CAISO rules.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Collaboration between SOC, CTI, DFIR, Malware and OT agents
  • Contributions from Risk, Compliance, PQC, Red Team and Blue Team agents
  • Task allocation and evidence collection through an orchestrator
  • A shared model of a real or synthetic situation

Proposed integration direction

DigiDefence Use-Case Layer

CURRENT CAPABILITY / FOUNDATION

Cyber, OT, CTI, FIMI and related research through CyberFiRD, CTI-balanced, HIPSTER, OSOTS, AICP-FIMI, AFFECTS and EPMwDC.

PROPOSED DEVELOPMENT

Use the projects' research areas as a basis for specialist models, agents and evaluation scenarios, incorporate approved data into the cyber domain knowledge base.

PURPOSE IN THE SI SYSTEM

Supply concrete domain problems and scenarios against which the capabilities of integrated cyber intelligence can be evaluated.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • FinTech and cyber threat intelligence use cases
  • OT, IoT and critical-infrastructure research areas
  • Hybrid-threat, FIMI and information-space scenarios
  • A research basis for espionage prevention and specialist agents

DIGIDEFENCE APPLICATION DOMAINS

  • CyberFiRD

    Cybersecurity research and development for the FinTech sector.

  • CTI-balanced

    A cyber threat intelligence initiative based on a sectoral and national collective cybersecurity system of balanced incentives.

  • HIPSTER

    A management system for hybrid, information, psychological and societal threats designed for public security professionals, companies and education.

  • OSOTS

    An operational technology sensor designed to improve cyber incident detection and response in order to ensure the stability, reliability and protection of critical and industrial infrastructure systems.

  • AICP-FIMI

    An AI-driven cloud platform for combating FIMI in elections and delivering an early warning service for identifying social media bots and troll farms.

  • AFFECTS

    Smart, sensory, self-learning and adaptive buildings.

  • EPMwDC

    Research and development of a monitor with integrated espionage prevention and malicious activity detection modules.

Proposed integration direction

[NE]rizikuok AI Edition

CURRENT CAPABILITY / FOUNDATION

Organisational training in information-security risk awareness, tabletop exercises and decisions under uncertainty.

PROPOSED DEVELOPMENT

Develop incident scenarios involving AI and autonomous systems, and a Human-AI Decision Research Platform comparing team and agent decisions.

PURPOSE IN THE SI SYSTEM

Generate risk scenarios and human decision reference points for studying agentic-system behaviour and the limits of its autonomy.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Shadow AI, GenAI data-leakage and supply-chain incident scenarios
  • Agentic-system, deepfake and critical-infrastructure AI incidents
  • Simulations of incorrect AI decisions and PQC migration crises
  • Comparison of team decisions with those of an AI agent

Proposed integration direction

CAISO Framework

CURRENT CAPABILITY / FOUNDATION

Chief AI Security Officer is identified as a proposed organisational role for managing AI risk.

PROPOSED DEVELOPMENT

Develop a methodology for AI security across its lifecycle: the CAISO Framework, Maturity Model, Academy and a CAISO as a Service consulting direction.

PURPOSE IN THE SI SYSTEM

Define institutional control rules, agent permissions and permitted autonomy based on risk and assessment evidence.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Governance of the secure AI lifecycle and model supply chain
  • A methodology for agent identity, permissions and AI monitoring
  • AI incident response, red teaming and failure-and-fallback planning
  • Maturity assessment, training and consulting services

Proposed integration direction

Human-AI Teaming

CURRENT CAPABILITY / FOUNDATION

The Human Cyber Shield direction, focused on human resilience in cybersecurity.

PROPOSED DEVELOPMENT

Develop Human-AI teaming research into interactions between human and AI decisions, human control and the human role in agentic defence.

PURPOSE IN THE SI SYSTEM

Help determine when the system should recommend, when a human decision is required and how a human can take control.

PROPOSED RESEARCH AND TESTING DIRECTIONS

  • Integration of human resilience into AI incident scenarios
  • Research into interactions between human and AI-agent decisions
  • Verification of human override within the Sandbox
  • Analysis of the human role and autonomy limits