AEGIR - Agentic Explainable Governance and Incident Reasoning: A Logic-Constrained Multi-Agent Architecture
AEGIR: An Agent-Based Framework for Cybersecurity Automation.
The integration of Information Technology (IT), Operational Technology (OT), and the Internet of Things (IoT) has created hybrid environments where industrial control systems, enterprise networks, and distributed sensors share infrastructure, expanding the attack surface. Despite this convergence, security management remains fragmented, often requiring manual correlation between security events and governance requirements. Organizations must mitigate cyber threats rapidly while demonstrating compliance with regulations such as the EU NIS2 Directive.
AEGIR addresses this challenge through a coordinated multi-agent architecture for cybersecurity automation. Specialized AI agents operate in a structured pipeline from threat identification to cross-framework control retrieval and explainable audit-chain generation under human oversight. A formal compliance verification engine annotates each recommendation, producing legally defensible audit trails. All training, inference, and compliance evaluation run on premises and are validated in industrial testbeds.
Research Area
- Data- och informationsvetenskap, Datorteknik
Research environment / Institution
- Övrig forskning
- Institutionen för ingenjörsvetenskap
Project leader
Research Partner
- RISE
- Gästrike Vatten
- Radtonics AB
- Energiföretagen
- Mätarenergi
Research funding
- Vinnova
Project time
2026 - 2028