Software Engineering | Trustworthy Agentic AI | AI Assurance
Barcelona, Spain
I work at the intersection of software engineering, trustworthy agentic AI, and AI assurance. My current work focuses on runtime assurance, policy-gated operational authority, multi-agent reliability, failure containment, human oversight, and auditable autonomous systems.
My background combines software engineering, telecommunications systems, university teaching, and reproducible AI/ML evaluation. Current research and technical work also explores how assurance and governance mechanisms can be applied to DevSecOps and increasingly autonomous 5G/6G systems.
- Trustworthy agentic and multi-agent systems
- AI assurance and runtime governance
- Policy-gated and bounded operational authority
- Failure propagation, containment, and recovery
- Human oversight, escalation, and abstention
- Auditable autonomous systems
- Software dependability
- AI-assisted 5G/6G network automation
A deterministic technical-governance prototype investigating when an AI software-engineering agent should be permitted to move from proposing an action to performing a consequential DevSecOps action.
The implementation separates capability from operational authority using explicit authority levels, evidence requirements, policy decisions, human-approval boundaries, reason codes, audit records, predefined scenarios, and automated tests.
GATE-5G explores a governance boundary between AI inference and operational authority in AI-assisted 5G/6G network management.
The work combines recovered experimental evidence from trust-aware fault-classification studies with a separate governance prototype that evaluates whether available evidence and policy justify a requested level of operational authority.
A bounded, deterministic, simulation-based research demonstrator for studying failure propagation, observability, containment, escalation, isolation, and recovery in multi-stage agentic workflows.
The project uses predefined scenarios, structured traces, explicit evidence and context states, deterministic controls, failure-propagation metrics, trusted-state rollback, automated evaluation, and CI-based reproducibility checks.
Intentional Agent Monitoring Lab A conceptual modelling and monitoring demonstrator connecting agent roles, tasks, goals, verification states, monitoring signals, and goal-satisfaction status with observable agentic workflows.
AI Lead Qualification & Human-Reviewed Follow-Up Automation A functional workflow automation MVP in which an LLM performs structured interpretation, deterministic rules perform qualification and routing, and a human retains authority over external communication.
Before AI Can Merge or Deploy: Minimum Governance Controls for Autonomous Agents in DevSecOps Pipelines Yasir Siddiq and Sadaf Anwar, 2026. Policy Memo, Version 1.0. DOI: 10.5281/zenodo.21888494
GATE-5G: From Prediction to Permission in AI-Assisted 5G Networks Yasir Siddiq and Sadaf Anwar, 2026. Policy Memo, Version 1.0. DOI: 10.5281/zenodo.21855481
Large Language Models in AI-Augmented DevSecOps Pipelines: Exploring Secure Software Engineering Practices and Architectural Challenges Co-author. International Journal of Advanced Research, 2026.
A Leakage-Safe Study of Trust-Aware Fault Classification in ns-3/5G-LENA Using QoS-Derived Features First author, with Sadaf Anwar. Accepted for WECE 2026; publication pending.
User-Centered Design Practices in Scrum Development Process: A Distinctive Advantage? Co-author. IEEE INMIC, 2014.
- MS Software Engineering — NUST-CEME
- BS Software Engineering — University of Engineering & Technology Taxila
- Former university lecturer in Computer Science / Software Engineering
- Previous telecommunications engineering experience with Alcatel-Lucent, Huawei, and SOMTEL
- Microsoft Certified: Azure Administrator Associate (AZ-104) and Azure Fundamentals (AZ-900)
LinkedIn · ORCID · Hugging Face
Research artifacts on this profile are described according to their demonstrated scope. Research prototypes, simulations, technical demonstrators, policy outputs, and production systems are not treated as interchangeable categories.
