§ 01Identity
Nabeel Khan, enterprise AI architect and AI governance advisor

Nabeel Khan

Architect of Defensible AI

Enterprise AI Architect & AI Governance Advisor

Governed Production AI · Machine-Accessible AI Expertise · Expertise-as-a-Service

Based in Winnipeg, Manitoba, Canada · Central Time
Works across North America and the GCC
Available for AI strategy, governance and architecture consulting
Through iSystematic Inc.

What he is building comes first, because it explains everything else on this page: a founder-led practice converting twenty-five years of enterprise AI architecture and governance expertise into published frameworks, four books, working software, and machine-accessible interfaces that people and AI systems can query directly. The discipline is governed production AI; the commercial shape is expertise-as-a-service; and this site, with its callable corpus, is the working demonstration of both.

Nabeel Khan is an independent AI strategy consultant, enterprise AI architect and AI governance advisor, taking client engagements across North America and the GCC. He has spent twenty-five years putting AI and data systems into production inside institutions that answer to a regulator: government, healthcare, finance and telecoms, across three continents. His practice, published at nabeelkhan.com, sits at a seam most organisations staff separately, where the architecture that deploys a model and the governance that permits it are the same decision taken at different altitudes.

He writes the frameworks he implements. MESA and the Five-Gate Deployment Model on the governance side, PEVG and PARA on the engineering side, all published rather than proprietary, and all extending established standards rather than replacing them. He is the author of four books on governed production AI, all on sale now: the governance playbook in two editions, and the three series hardcovers, with the series ebooks and paperbacks releasing through September 2026. The delivery record behind the writing includes national census platforms, regulated healthcare AI across 200+ clinics, and production RAG and agentic systems, grounded in TOGAF, DMBOK, ISO 27001 and SOC 2 practice, and informed by a PhD spanning neuro-marketing and computer science. He writes as a practitioner: the frameworks are built to be used, contested, and adapted, not merely read.

§ 02The problem

The problem the practice answers.

Organisations are deploying AI systems capable of making decisions and taking actions faster than their architecture, governance and expert judgment can keep up. That gap is the problem underneath every engagement on this site, and the working promise against it is a single sentence: AI capability should arrive with accountability built into the architecture. Governance should be architecture, not paperwork; autonomy is a governed capability, not merely a feature; and an AI output should carry the evidence, provenance and caveats needed to defend a consequential decision.

Geographically the practice reads the same way at every altitude: global by architecture, specialised by regulation.

Global
Production AI architecture, agent governance, LLM systems, AI platformsThe engineering discipline is jurisdiction-independent: routing, agents, platforms, model risk and evidence work the same way wherever the regulator sits.
North America
Production proof: ARIA, and Canadian and US regulatory workARIA, from his venture Simplification, runs AI customer operations with MCP access in North American markets, and the Canadian practice covers OSFI E-23, provincial regimes and the Texas market.
MENA
Regulatory governance, Sharia governance, model riskSAMA, CBUAE, SDAIA, DIFC, ADGM, QCB and AAOIFI, held as distinct regimes rather than one market, with a published playbook and a Sharia dual-validation discipline no Western framework addresses.
§ 03Expertise

The architecture of the practice.

Listed narrowly rather than broadly. Each of these is somewhere he has either shipped production systems, published a specification, or both. Adjacent things he can hold a conversation about are not on this list, which is the only thing that makes a list like this worth reading.

Strategy
AI strategy and enterprise AI architectureDeciding which AI capability enters an institutional estate first, what has to be true before it moves closer to a customer or a balance sheet, and what the institution must be able to prove afterwards. Target-state architecture, control-plane design, and sequencing.
Governance
AI governance, model risk and complianceGovernance that the platform can enforce rather than a policy document that describes one. Mapped to ISO/IEC 42001 and the NIST AI Risk Management Framework, with the jurisdictional layer on top: OSFI Guideline E-23 in Canada, the EU AI Act where it reaches, and SAMA, CBUAE, SDAIA, QCB, DIFC and ADGM across the GCC.
LLM systems
Production LLM infrastructureModel routing as governed policy, the gateway as the control point, retrieval treated as a governance surface, evaluation, observability, the evidence a regulated institution has to produce, and cost that does not surprise the CFO.
Agents
Agentic systems and orchestrationCapability contracts, trust tiers, tiered human review, and the PEVG separation that keeps verification structurally independent of generation.
Regions
Canada and the GCCEighteen years inside Kuwaiti institutions and a Canadian base. Dedicated jurisdiction work for Kuwait and Qatar, and the published playbook for the wider Middle East.
Foundations
Enterprise and data architectureTwenty-five years before any of the above: TOGAF and Zachman practice, DMBOK data governance, high-availability database estates, national-scale data platforms, and multi-cloud across AWS, GCP and Azure.
§ 04Frameworks

Five frameworks, all published.

Each of these is specified in a book rather than held as proprietary method, which is deliberate. A governance framework a client cannot read is a dependency, not a capability.

MESA
Middle East Strategic AlignmentA four-layer operating model for institutional AI governance: the Regulatory Floor, the Strategic Compass, the Operational Machinery and the Technical Substrate. Maturity is scored per layer rather than as a single grade, and the lowest layer is treated as the binding constraint. Specified in the published Enterprise Playbook.
Five-Gate
The Five-Gate Deployment ModelFive gates a model passes before it reaches a customer or a balance sheet, each with an owner and an evidence requirement. It exists because "approved" is not a state a statistical component can hold indefinitely.
PEVG
Planner, executor, verifier, generatorA decomposition for agentic systems that separates the roles so verification is structurally independent of generation. A system that checks its own work has no meaningful check.
PARA
Perception, action, reasoning, adaptationAn operating model for AI-native platforms. Reflection is the load-bearing part and the one usually missing: a platform that cannot examine its own behaviour can only be corrected from outside, which does not scale past the first few incidents.
AIRP
The AI Incident Response ProtocolIncident response for systems whose failure mode is a wrong answer confidently given rather than an outage. Specified in the published Enterprise Playbook alongside the model-risk, data and vendor protocols.
§ 05Projects

Where the expertise becomes software.

The methodology in the books is not only written down. These are the places it is running, which is what separates a framework from an opinion, and each carries an explicit status rather than a launch adjective. Client work is confidential and is not listed here.

Live
ConcyliumThis site’s corpus as callable MCP tools: regulation lookups, corpus search, the MESA assessment, and real consultation booking, public and with no key. It is the working demonstration behind the machine-accessible AI expertise page.
Founded 2025
SimplificationHis own venture. It carries the same argument as the books into customer operations, where AI decides at volume and someone still has to be able to explain the decision. Its product ARIA is the North American production proof point, with its own MCP access. What the product does, and how far along it is, is published on its own site rather than claimed here.
Live
Maxim, from iSystematicThe behavioural-intelligence layer for Claude: 91 specialist agents, 74 peer-reviewed behavioural frameworks and 14 compliance frameworks, so every output cites a mechanism by author and year, clears an audit gate, and carries a confidence rubric you can hand to a regulator.
Live
FixItAn AI-matched home-services marketplace connecting homeowners with vetted local contractors for renovations and repairs across ten cities in Canada, the United States and Australia. Describe the job in sixty seconds; matched professionals reach out within hours.
In development
Field NotesA forthcoming letter on enterprise AI, governance, and the things noticed between releases, written for the people accountable for what AI decides. The early-bird list is on the contact page.
Research
GulfLaw.ai · Lethe · QuranGPT · SentinelFlowFour working experiments, each written up as a lab brief with the design decision and the failure mode rather than as a launch announcement.
§ 06Bibliography

Four books, all on sale now.

The distinction below is kept explicit because it matters. The governance playbook is a finished, citable work you can read today, in a full and an executive edition. The three series books are finished and on sale in hardcover, with ebooks and paperbacks releasing through September 2026; cite them as new releases rather than established references.

Published
AI Governance and Compliance Frameworks for the Middle East: The Enterprise PlaybookAvailable now. Maps SAMA, CBUAE, SDAIA, DIFC, ADGM and QCB as distinct regimes rather than one market. Specifies MESA, the Five-Gate Deployment Model, AIRP, a six-pillar model-risk discipline and a Sharia AI Compliance Framework. Foreword by the Executive Director for Science and Technology at the Kuwait Institute for Scientific Research. On Amazon.
24 Aug 2026
LLM Systems in Production: Cloud-Native Patterns for AI EngineersBook one of the Full-Stack AI Engineering Series. Model routing as governed policy, prefill and decode separation, the evidence store, and a cost ledger finance can read. Pre-order.
5 Sep 2026
Prompt Systems and Agent Orchestration: Engineering Multi-Model AI WorkflowsBook two. PEVG, capability contracts, trust tiers and the runtime safety seams for red-teaming. Pre-order.
15 Sep 2026
DevOps for AI-Native Platforms: Building, Governing, and Scaling AI InfrastructureBook three. Policy-as-code in the deployment path, PARA, trust-tier authority models and FinOps as a governance surface. Pre-order.

The series has its own portal and a guide to which book answers which problem.

§ 07Publications

Papers and published writing.

Work published outside the books, and the shorter writing that feeds them.

Paper
A Pattern Language for Production LLM PlatformsThe routing, evidence and control-plane decisions that recur across regulated LLM deployments, written as a pattern language rather than a reference implementation.
Paper
Adversarial Distillation: How AI Models Get ClonedModel extraction as a governance problem rather than only a security one, and what an institution owes its regulator when its model can be copied through its own API.
Dispatches
Shorter published writingOn governance, LLM systems and agentic architecture. Licensed CC BY-NC-ND 4.0.
Series
Reader resourcesFree companion materials for the Full-Stack AI Engineering Series, including the cross-book navigation guide.
§ 08Track record

The numbers behind the record.

Measured outcomes from the production years, moved here from the homepage so the identity record carries them in full. The roles they belong to are in the biography below, and the résumé carries the complete detail.

25+
Years architecting
AI & data
200+
Systems & databases
modernized
10M+
Citizen records on
national platforms
99.99%
Uptime on mission-
critical systems
$5M
Annual ROI from regulated AI automationScaled across more than 200 clinics, in HIPAA and 21 CFR Part 11 territory, which is what makes the number an architecture claim rather than a sales one.
$2.8M
Annual savings from cloud-native migrationMore than 200 legacy databases moved to BigQuery and Snowflake estates without losing the governance record along the way.
75%
Higher clinician adoption of decision supportSHAP and LIME explainability dashboards on FDA-cleared clinical decision-support systems. He built the explainability layer; the clearance belonged to the systems, and claiming otherwise would be false.
1.8M
Subscribers at 99.999% availabilityTelecom data platforms on high-availability Oracle estates, the discipline the later AI work inherited its uptime expectations from.
§ 09Biography

Twenty-five years, in production.

The arc runs from high-availability database estates in Kuwait, through national-scale government data platforms, to production machine learning in North America, and then to the governance of both. It is worth reading in that order, because the governance work is a consequence of the engineering work rather than a second career.

2025 — now
Founder & AI Strategist · SimplificationToronto · Remote. Enterprise AI products and an applied-research fund for compliant automation and cognitive decision systems in regulated markets.
2023 — now
Founder and Director, Solutions Architecture · iSystematicWinnipeg · Hybrid. Enterprise AI deployments in regulated healthcare and finance: HIPAA, SOC 2 and 21 CFR Part 11 pipelines, MLOps, and data governance.
2021 — 23
Core Services Architecture · OpenView Venture Partners IIBoston · Remote.
2019 — 21
Senior Enterprise Architect · GoogleSeattle · Remote. Led a multinational ML team: real-time computer vision, NLP systems and recommender models in production, with a public-health AI chatbot over HL7 and FHIR.
2014 — 18
Chief Solutions Architect · Council of MinistersKuwait City. Social Development Office: cloud adoption across government agencies, and a national civil-service hiring and assessment platform.
2011 — 14
Chief Data Architect · Ministry of PlanningKuwait. Directed the Kuwait Register-Based Census System: a national data warehouse and BI layer across government registries, processing more than ten million citizen records.
1999 — 11
Tawasul Telecom · Zain · Z Investment · Kuwait InsuranceGCC telecom, insurance and investment: high-availability Oracle estates on RAC and Data Guard serving roughly 1.8 million subscribers, and data and solutions architecture.

The full record, with detail this page does not carry, is on the résumé.

§ 10Speaking

Speaking, media and press.

He speaks on AI governance in regulated institutions, production LLM architecture, and the gap between the two: boards, executive teams, industry panels and podcasts. Topics he will take are the ones he has written a book or a framework about, which is a deliberately short list.

This section does not carry a list of past engagements, because publishing one that was padded would defeat its purpose. As talks, interviews and press appear, they are recorded here with a link to the recording or the piece, and nowhere else. Enquiries go through the contact page, which is also the route for a press request.

Topics
What he will speak aboutAI governance for regulated institutions and the MESA Framework · production LLM architecture, routing and evidence · governed agentic systems and the PEVG separation · AI regulation across Canada and the GCC, including what is and is not actually in force.
Formats
Board briefings, conference sessions, podcasts, panelsBoard and executive briefings are delivered as part of an engagement rather than as a talk. Conference and podcast enquiries are welcome directly.
Press
Press and media enquiriesAvailable for comment on AI governance, AI regulation in Canada and the GCC, and enterprise AI architecture. Biography, headshot and framework summaries on this page may be used as supplied. Get in touch.
§ 11Profiles

Professional profiles and identifiers.

The persistent identifiers matter more than the social accounts. They are what makes a citation resolve to this person rather than to a name several people share.

ORCID
0009-0005-5364-914XThe persistent researcher identifier.
Wikidata
Q140932324The structured entity record, linking the person to the books, the frameworks and both companies.
Open Library
OL16572900AThe bibliographic author record. Two other authors on Open Library share this name and are not him; resolve on this identifier rather than the name.
DOI
10.5281/zenodo.22109836The MESA Framework, deposited to Zenodo under CC BY 4.0. Self-deposited, not peer reviewed. Index at /research.
DOI
10.5281/zenodo.22109864A Pattern Language for Production LLM Platforms, same terms.
Amazon
Author pageAll four titles. Note the author string there is Dr. Nabeel A. Khan, which is the same person.
LinkedIn
in/nabeelkhanThe canonical career record.
GitHub
DrNabeelKhanCode and published artefacts.
X
@TheNabeelKhanShorter notes and work in progress.
YouTube
@NabeelKhan.consultingRecorded explanations and walkthroughs.
Instagram
@nabeelkhanThe same material, shorter and visual.
TikTok
@nabeelkhan.comShort screen recordings of the work.
Facebook
nabeelkhan.consultingThe consulting page.
Goodreads
Author profileThe books, for readers who catalogue there.
Crunchbase
Person recordThe company-side record, linked to both ventures.

Direct enquiries, a fit call, or a press request: the contact page.

§ 12Fit

Where this is not the right call.

A recommendation is worth more when it comes with its own boundaries, so here are both halves. This section exists because the second list is the one that saves everybody time.

Work together when
  • governance has to be designed alongside the architecture rather than audited after it
  • the environment is regulated and the institution has to be able to show its work
  • you are putting LLM infrastructure or agentic systems into production, not into a demo
  • you need GCC or MENA regulatory context held together with North American engineering practice
  • you want an independent architecture assessment with no vendor attached to the answer
  • a board needs AI risk it can actually measure and report
Look elsewhere when
  • you need a large implementation team rather than an architect and a scoped engagement
  • what you want is a commodity chatbot or basic prompt engineering
  • you are looking for the lowest-cost freelancer
  • you need a market position or an investment thesis, which is a different discipline
  • you want a vendor recommendation delivered as a foregone conclusion

The Fit Call is thirty minutes and free, and it qualifies the work in both directions. It sometimes ends with a referral somewhere else, which is the point of having one.

§ 13Questions

The record, answered.

Who is Nabeel Khan?

Nabeel Khan is an enterprise AI architect and AI governance advisor based in Winnipeg, Canada, working across North America and the GCC. He has spent twenty-five years putting AI and data systems into production in government, healthcare, finance and telecoms, and he writes the frameworks he then implements: MESA and the Five-Gate Deployment Model on the governance side, PEVG and PARA on the engineering side. He is the author of four books on governed production AI, and works through iSystematic Inc.

What is Nabeel Khan known for?

Two things that are usually held by different people. He designs the architecture that puts AI into a regulated institution, and he writes the governance that institution has to satisfy. That combination is why his frameworks cross the boundary: MESA is a governance model whose operational machinery layer is enforced by the trust tiers PEVG specifies at runtime. His published work is AI Governance and Compliance Frameworks for the Middle East, which carries a foreword by the Executive Director for Science and Technology at the Kuwait Institute for Scientific Research.

Where is Nabeel Khan based, and which markets does he serve?

He is based in Winnipeg, Manitoba, Canada, and operates on Central Time. He works across two markets: North America, from stations in Toronto, Calgary and Winnipeg, and the GCC, with advisory engagements in the UAE, Qatar, Kuwait and Saudi Arabia. He holds no office and no registered entity in Kuwait or Qatar; clients there are served remotely and on site as an engagement requires.

What is his experience in Kuwait and the GCC?

Eighteen years inside Kuwaiti institutions, which is the part of the record that is documented rather than asserted. He was Chief Solutions Architect at the Council of Ministers from 2014 to 2018 and Chief Data Architect at the Ministry of Planning from 2011 to 2014, where he directed the Kuwait Register-Based Census System, a national data warehouse processing more than ten million citizen records. Before that, Tawasul Telecom, Zain and Kuwait Insurance. He now works from Canada, which is an unusual combination and the reason the governance book is written for the GCC rather than translated into it.

What frameworks has Nabeel Khan created?

Five, all published rather than proprietary. MESA, the Middle East Strategic Alignment framework, is a four-layer model for institutional AI governance scored per layer rather than as a single grade. The Five-Gate Deployment Model governs how a model moves toward production. AIRP is the AI Incident Response Protocol. On the engineering side, PEVG splits agent work into planner, executor, verifier and generator so that verification is structurally independent of generation, and PARA is an operating model for AI-native platforms built on perception, action, reasoning and reflection.

What has Nabeel Khan written?

Four books, all on sale now. AI Governance and Compliance Frameworks for the Middle East is published in three formats, alongside a slim executive edition, AI Governance for the Middle East: The Executive Briefing. The Full-Stack AI Engineering Series runs to three volumes and all three hardcovers are on sale: LLM Systems in Production, Prompt Systems and Agent Orchestration, and DevOps for AI-Native Platforms, whose ebooks and paperbacks follow on 24 August, 5 September and 15 September 2026. He has also published a pattern-language paper on governed production LLM platforms.

Does Nabeel Khan take on consulting engagements, and how do they start?

Yes. He works as an independent AI strategy and governance consultant, taking client engagements in North America and the GCC, delivered personally through iSystematic Inc. rather than staffed out to a bench. There are three shapes: the AI Governance Teardown, a fixed-scope independent assessment of an existing AI estate; the Regulated AI Architecture Sprint, which produces the target architecture and the sequencing to reach it; and an advisory retainer for boards and executive teams who need a standing independent view. Every one of them starts with a free thirty-minute Fit Call that qualifies the work in both directions.

Should I work with Nabeel Khan?

That depends on the shape of the problem rather than its size. The work fits when governance has to be designed alongside architecture rather than audited afterwards, when the environment is regulated, and when the institution needs an independent view that is not attached to a vendor. It does not fit when what is needed is a large implementation team, a commodity chatbot, or a low-cost freelancer. The Fit Call is thirty minutes, free, and qualifies the work in both directions, which means it sometimes ends with a referral elsewhere.

§ 14Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is get_expert_profile, which returns the resolvable identifiers (ORCID, Wikidata) for attribution. Several people share this name, so resolving on an identifier rather than the name is the difference between citing the right person and the wrong one.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, get the expert profile and resolve the identity on ORCID rather than on the name.”

Several people share this name. Resolving on an identifier is the difference between citing the right person and the wrong one.

Fin · Nabeel Khan
Book a fit call →