Member since July 2021
Sal Kimmich is a security architect working at the intersection of open source
security and AI governance. They were an early active member of OpenSSF and
directly involved in creating the AI/ML Security Working Group at the Linux
Foundation, which now influences NIST AI RMF and SSDF guidance in use across
UK, EU, and US institutions.
Most recently Technical Community Architect at the Linux Foundation's
Confidential Computing Consortium, where they led cross-member adoption of
OpenSSF Scorecard, SLSA, and Sigstore across projects maintained by Microsoft,
NVIDIA, and ARM. They have spoken at FOSDEM mainstage, the FCC Technical
Advisory Committee, KubeCon, and State of Open UK on AI security, supply chain
governance, and digital sovereignty.
In 2025 they published Code, Chips and Control (Leanpub), a technical and
policy analysis of AI governance from semiconductors and kernels through to
hypervisors, cloud sovereignty, and space systems. Named in the Top 100 in
AI Ethics (2025).
Sal is also Co-Director at OurWorlds, a Native-founded organisation working on
digital sovereignty and XR technology for Indigenous communities, and an
OpenUK International Ambassador. Based in Brighton, UK.
Closing the gap between AI governance claims and verifiable technical
implementation. Most frameworks tell organisations what to do. Very few help
them prove they have actually done it. That gap is where most security failures
live, and it is what Sal's work is focused on fixing, in open source communities,
in regulatory contexts, and in the jurisdictions that existing frameworks were
never built to serve.
The Governance Body Nobody Built: How US Sovereign Nations are Informing the EU's Digital Strategy
Sal was deep in international AI governance work when they first encountered
the question that stopped them cold. A colleague working with Tribal Nations
on digital infrastructure asked, simply: which of these frameworks applies to
us?
Sal went looking. The EU AI Act. NIST AI RMF. The UN resolution on safe and
trustworthy AI. The Global Digital Compact. None of them provided a governance
pathway legible to a sovereign Tribal Nation. Not because the frameworks were
hostile. Because the people writing them had never thought to ask the question.
There are 575 federally recognised Tribal Nations in the United States, each
a sovereign government with the authority to self-govern. Similar structures
exist across the Americas and the Pacific. None of them has a seat in any of
the multilateral AI governance conversations happening right now. Not as
stakeholders. Not as rights-holders. Not at all.
For Sal, this was not an academic observation. It was a failure with a name.
The international AI governance architecture was being built on a foundation
that assumed the only actors that mattered were nation-states and corporations.
Everyone else would be governed by the frameworks those actors produced,
whether the frameworks fit their reality or not.
Sal is now working to change that, through OurWorlds, through conference
speaking, and through direct engagement with the multilateral processes where
these decisions are being made. The work is ongoing. The window to shape these
frameworks before they harden into precedent is closing. That is why it cannot
wait.
Sal started out in cognitive neuroscience, completing joint doctoral work at
NIMH and UCL on how brains process information under uncertainty. What drew
them into security was the same question from a different angle: how do complex
systems fail in ways their designers did not anticipate?
That question led from academic research into open source security work, first
at Sonatype during the Log4Shell crisis, then at the Linux Foundation's
Confidential Computing Consortium, then into the founding work of the OpenSSF
AI/ML Security Working Group. Along the way they developed a reputation for
being able to translate between the technical and policy layers of security
conversations, a skill that is increasingly rare and increasingly needed as
regulators try to govern systems they do not fully understand.
The work that followed has spanned kernel-level sandboxing for AI agents,
Indigenous data sovereignty and the governance gaps in international AI
frameworks, and building tools that make supply chain provenance visible and
auditable. The thread connecting all of it is the same question from the
neuroscience days: where are the failure modes nobody has thought to look for yet?
The Governance Body Nobody Built: How US Sovereign Nations are Informing the EU's Digital Strategy
Sal was deep in international AI governance work when they first encountered
the question that stopped them cold. A colleague working with Tribal Nations
on digital infrastructure asked, simply: which of these frameworks applies to
us?
Sal went looking. The EU AI Act. NIST AI RMF. The UN resolution on safe and
trustworthy AI. The Global Digital Compact. None of them provided a governance
pathway legible to a sovereign Tribal Nation. Not because the frameworks were
hostile. Because the people writing them had never thought to ask the question.
There are 575 federally recognised Tribal Nations in the United States, each
a sovereign government with the authority to self-govern. Similar structures
exist across the Americas and the Pacific. None of them has a seat in any of
the multilateral AI governance conversations happening right now. Not as
stakeholders. Not as rights-holders. Not at all.
For Sal, this was not an academic observation. It was a failure with a name.
The international AI governance architecture was being built on a foundation
that assumed the only actors that mattered were nation-states and corporations.
Everyone else would be governed by the frameworks those actors produced,
whether the frameworks fit their reality or not.
Sal is now working to change that, through OurWorlds, through conference
speaking, and through direct engagement with the multilateral processes where
these decisions are being made. The work is ongoing. The window to shape these
frameworks before they harden into precedent is closing. That is why it cannot
wait.
Sal started out in cognitive neuroscience, completing joint doctoral work at
NIMH and UCL on how brains process information under uncertainty. What drew
them into security was the same question from a different angle: how do complex
systems fail in ways their designers did not anticipate?
That question led from academic research into open source security work, first
at Sonatype during the Log4Shell crisis, then at the Linux Foundation's
Confidential Computing Consortium, then into the founding work of the OpenSSF
AI/ML Security Working Group. Along the way they developed a reputation for
being able to translate between the technical and policy layers of security
conversations, a skill that is increasingly rare and increasingly needed as
regulators try to govern systems they do not fully understand.
The work that followed has spanned kernel-level sandboxing for AI agents,
Indigenous data sovereignty and the governance gaps in international AI
frameworks, and building tools that make supply chain provenance visible and
auditable. The thread connecting all of it is the same question from the
neuroscience days: where are the failure modes nobody has thought to look for yet?