Aashis LuitelD.Eng., MPA
Aashis Luitel, D.Eng., MPA

Public-sector security and AI governance, built in practice and taught in the classroom.

Associate Professor of Artificial Intelligence at the University of the Cumberlands and Lead Technical Program Manager for Public Sector Security at N-able. Previously led Responsible AI, privacy and federal readiness work across Microsoft Security Copilot and cloud and AI security.

Portrait of Aashis Luitel

Former Microsoft Security · Harvard Kennedy School MPA · U.S. Navy Veteran · Doctor of Engineering, George Washington University

Builder. Owner. Educator.

I work where AI policy becomes system design, security controls and evidence an auditor can test.

i.

Builder

Product and program leadership on Microsoft Security Copilot and the early agents built on it, covering Responsible AI review, privacy engineering and sovereign cloud readiness. No precedent existed for how trust should be built into a generative AI security product, so the team wrote one.

The practice →
ii.

Owner

Public-sector security program execution at N-able, including FedRAMP Moderate and CMMC 2.0 Level 2, from control implementation through evidence collection and assessment readiness. Ownership means the audit finding lands on your desk, not someone else's.

Program work →
iii.

Educator

Designed Ethics in Responsible AI for the University of the Cumberlands' first PhD in Artificial Intelligence cohort. Teaches and advises doctoral students working on AI governance, responsible AI and cybersecurity.

Teaching and research →
Recent writing

Commentary on AI regulation, security assurance and the gap between them

Independent · Aug 13, 2026

Your artificial intelligence agent could go rogue and spend your money(opens in a new tab)

A look at how a verification system could be designed offers some insight into some of the technical challenges AI agents are poised to introduce

The Conversation · Aug 13, 2026

An AI agent spent your money – can anyone prove you authorized it?(opens in a new tab)

What happens if your bot buys something you didn’t tell it to?

Colorado Politics · July 29, 2026

Clock is ticking on Colorado's new AI rules(opens in a new tab)

What compliance with Colorado's automated decision-making law actually requires of the organizations inside its scope, and how little time remains to build it.

InformationWeek · July 7, 2026

Why AI-built tools are threatening SaaS vendor renewals(opens in a new tab)

Internal teams can now build in days what they used to license. The renewal conversation has changed, and most vendors have not noticed.

The Colorado Sun · May 14, 2026

Colorado's small defense suppliers are about to disappear(opens in a new tab)

CMMC compliance costs fall hardest on the smallest firms in the defense industrial base. The state has options, and a narrowing window to use them.

University of the Cumberlands · June 4, 2026

Bridging AI and ethics: a vision for trustworthy innovation(opens in a new tab)

A profile on carrying Responsible AI work from Microsoft Security Copilot into doctoral teaching. Ethics as an engineering discipline rather than a reading list.

Aashis Luitel speaking on a panel
Speaking

Translating governance for the people who have to implement it

The hard part of AI governance is rarely the principle. It is the meeting where an engineer, a lawyer and a contracting officer discover they mean different things by the same word. I speak to technical, academic, policy and executive audiences about Responsible AI, CMMC, FedRAMP and what security assurance requires in operational environments.

Recent appearances include the Federal News Network Risk & Compliance Exchange in 2026, on closing the CMMC evidence gap.

Open to speaking, collaboration and commentary

Panels and keynotes, academic collaboration, media commentary on AI governance and public-sector security, or a straightforward professional conversation.