Skip to content
View JKasteele's full-sized avatar

Block or report JKasteele

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JKasteele/README.md

Hi, I'm Jesse 👋

Cyber Security Engineer @ NewCold · Breda, Netherlands 🇳🇱

I moved from securing systems to governing them. Cybersecurity protects your data; AI governance protects your decisions. I work in the overlap — AI security, AI risk assessment and EU AI Act readiness — and I build the tooling that turns frameworks into things engineering teams can actually implement.

🤖 AI Act Companion — open source

PyPI Live demo License: MIT

JKasteele/ai-act-companion — a local-first, explainable EU AI Act risk classifier that cites the exact Article and Annex behind every verdict, and generates what comes after the classification.

  • Deterministic rule engine, not an LLM guessing — prohibited / high-risk / limited / minimal tiers, every verdict cited
  • 21 governance & assurance reports — DPIA, FRIA, Annex IV technical documentation, conformity tracking, post-market monitoring plan, control catalogues, red-team plans
  • AI security built in — architecture-aware severity mapped to OWASP LLM Top 10 (2025) and MITRE ATLAS, with an offence↔defence loop linking each red-team test to the control that verifies it
  • Runs where you work — CLI, Python API, MCP server / Claude Code plugin, GitHub Action, or the live demo
  • 270 automated tests · 95% coverage · MIT · pip install ai-act-companion

🛡️ What I do

Owner of five security competencies at NewCold: AI Security, Security Operations, Email Security, Endpoint Security and Security Awareness. On the AI side, that looks like:

  • EU AI Act readiness — risk classification, Article 15 gap analysis, Annex III / IV scoping, and the templates that make it repeatable
  • End-to-end AI risk assessments — STRIDE threat models, likelihood × impact risk registers, DPIAs, control catalogues, prioritised remediation
  • Adversarial testing — prompt injection, jailbreaking and data extraction, mapped to the OWASP Top 10 for LLM Apps and MITRE ATLAS
  • Frameworks → controls — NIST AI RMF, ISO/IEC 27001:2022 and NIST CSF 2.0, translated into things engineering teams can implement
  • Earlier: delivered a full EU AI Act high-risk assessment for an AI-powered HR app — risk assessment · DPIA · bias audit

Reading the EU AI Act is the easy part. The work is producing the artefacts that survive contact with a real system, then sitting down with the engineers who have to act on them.

🎓 Credentials

  • CompTIA SecAI+ (CY0-001) — securing AI systems, adversarial testing, AI governance
  • Associate of ISC2 — CISSP exam passed
  • AI Security Foundation (S-AISF) — SECO-Institute
  • BSc Cyber Security & Cloud — Hogeschool Utrecht

🧰 Tech

Python · PowerShell · Docker · LLM red-teaming (Garak / PyRIT) · agentic AI & MCP · Microsoft Defender XDR / SIEM · Microsoft Intune

📫 Connect

LinkedIn

Dutch and English · EU citizen · based in the Netherlands, working across CET.

Always glad to talk with people working on AI assurance, AI security or EU AI Act implementation. It's a small field and it's moving quickly.

Pinned Loading

  1. ai-act-companion ai-act-companion Public

    Local-first, explainable EU AI Act risk classifier with risk-assessment/DPIA/bias/AI-security generators (NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS) - runs as a Claude Code plugin.

    Python 2