Overview
Hasan Suzen is the founder and CEO of Hybrid Core, a company he started in August 2020 and runs from Brussels. Since late 2019 he has also been a member of the European AI Alliance at the European Commission, a member of AI4Belgium and a member of the CAIRNE network.
From February to August 2021 he was an associate research fellow at the New Jersey Institute of Technology. He was president of Beyond the Horizon ISSG from October 2016 to August 2023, and before that a senior associate at NATO between 2013 and 2016. His earlier career was spent at GS Strategic Transformation, where he worked as a junior and then senior project manager from 1998 to 2010 and as a strategic transformation programme manager from 2011 to 2013.
Suzen holds a PhD in computational political science from the University of Antwerp, a master's in international relations and affairs from the University of Oklahoma, a master's in international relations and national security studies from the U.S. Army Command and General Staff College, and a bachelor's degree in system engineering from Milli Savunma Üniversitesi.
Career history
Insights & ideas
The through-line
Across energy, defense, finance and logistics, Hasan Suzen returns to the same observation: a regulatory deadline, an emergency meeting, or a crisis event exposes that the underlying picture of a system does not exist anywhere as a single, owned view. Europe restricts vendor access to solar inverters, but "most operators still could not produce, today, a single picture of what sits behind their connection points and who can reach it" [3]. Europe schedules two emergency grid meetings in nine days, but "hydrology, thermal derating, storage and the evening ramp still live in separate institutions" [1]. The pattern repeats in cargo crime data [10], border data [5], settlement risk [6], fraud liability [2], and defense mobility [8][12]. Over the run of posts (late July through August 2026) this hardens from a general sovereignty argument about compute and data [13][14] into a sharper, repeated claim: the fix is not more sensors, more compliance paperwork, or more infrastructure spend, but a rehearsed, fused, sovereignly-controlled "decision layer" sitting above whatever hardware or vendor stack already exists [4][12][13].
On the decision layer
Suzen's central claim is that sovereignty is not won at the infrastructure layer but above it. On Europe's €30 billion sovereign compute commitment: "The decision layer, where critical sectors actually operate, is still where sovereignty is won or lost. That is the layer we build at Hybrid Core" [13]. On the five flagship EU defense projects: "The hardware is the visible half; the harder half is the software layer where fusion, C2 security and accountable decisions live" [12]. On the Leipzig drone incident: "You cannot buy that gap closed. You have to design the decision layer" [4]. Applied to trading desks, the same logic becomes a product thesis: "If your most differentiated data cannot travel, then the only intelligence layer that can ever use it is one that comes to the data. That conviction shaped Hybrid Core's Aurex" [14].
On visibility gaps
The recurring diagnostic move is to show that an institution's supposed picture of its own operations is fragmented or absent. On cargo crime: "We are trying to direct an €8.2 billion problem with a map that is mostly blank" [10]. On border data: "Most operators hold four true fragments of that picture, in four systems, owned by four parties. None holds the joined one" [5]. On T+1 settlement: the shortened cycle "exposes how little visibility most institutions have across counterparties, agents and market infrastructures" [6]. On grid cybersecurity reporting: "fragmented evidence is the real exposure" [7]. The framing is consistent: the gap is discovered by a deadline or crisis, not created by it.
On regulatory deadlines versus real exposure
Suzen treats postponed compliance dates as a test of intent rather than relief. On the AI Act's high-risk deadline moving to December 2027 for credit scoring: "Does an extra sixteen months make a bank safer, or just later?" and "The exposure didn't" move with the deadline [11]. On the same shift paired with the post-quantum timeline that did not move: "Which of your 2026 commitments were architecture, and which were calendar?" [9]. On the PSR's fraud provisions: "Authentication has worked, so fraud moved to the one surface it cannot protect: the authorised customer," and pooling fraud intelligence "only works on infrastructure you actually control" [2].
From the stage
In the NGI Explorers interview, Suzen frames his work in terms not present in the written posts: hybrid intelligence as a deliberate combination of artificial intelligence with human intelligence, built to address gaps in algorithmic decision systems around accuracy, explainability, and human oversight [16]. The LinkedIn posts apply the decision-layer argument sector by sector; the interview states the underlying design premise behind Hybrid Core itself, that AI alone is not treated as sufficient and human oversight is a structural component rather than a compliance add-on [16].
Takeaways
- Before treating a compliance deadline as resolved, check whether the underlying visibility gap it was meant to expose has actually closed, as with the AI Act's deferred high-risk obligations [11] and the moved-but-not-moved post-quantum clock [9].
- Map who can reach your generation, settlement, or logistics chain end-to-end before a regulator or incident forces you to; most organizations cannot currently produce that single picture [3][5][6][10].
- Pooling fraud, threat, or crisis intelligence across institutions only works if you can prove what data left your own infrastructure, which requires infrastructure you control [2].
- Treat sovereign compute or hardware investment as necessary but insufficient; the software/decision layer that fuses and governs what runs on that infrastructure is where sovereignty is actually contested [12][13].
- Rehearse compound, cross-domain scenarios (e.g., hydrology plus thermal derating plus evening ramp, or a chokepoint reroute) before the week they occur, rather than assembling the picture by hand during the event [1][15].
Media & appearances
- NEXT GENERATION INTERNETYouTubeHasan Suzen | NGI Explorers 2nd Expedition: Meet the ExplorersHasan Suzen discusses his roles as founder of Beyond Horizon International and CEO of Hybrid Core, a company developing hybrid intelligence technology that combines artificial intelligence with human intelligence to address gaps in algorithmic decision systems regarding accuracy, explainability, and human oversight.
In the news
- Europe is about to publish a number that will be read as a defeat: its chip self-sufficiency target for 2030, missed by nearly half. I think that number answers a question it was never built to answer. Fabs are a decade-long industrial project, and the forecast reflects that honestly. The sovereignty of the reasoning running on the chip is a separate question — answerable this year, not in 2030. We built Smart Navigator on that distinction deliberately. I would like to know if others in deep tech see the two questions as
- In two weeks, an EU steel import needs a birth certificate: the country where it was actually melted, not just where the invoice says it shipped from. What strikes me about "melt and pour" is what it quietly asks for. Every mill certificate, heat number, customs filing and bill of lading sits with a different party. Each looks complete alone, while the pattern across all of them — the one that reveals a shipment routed to dodge a tariff — stays invisible, because no single document shows it. That's a network problem wearing a
- Nineteen. That's how many providers the EU now formally treats as critical to the financial sector's own technology. What strikes me isn't the number — it's what produced it: a formal admission that concentration in EU financial infrastructure reached a level regulators call systemic, in providers several of which sit outside the EU's own jurisdiction. 2026 is the year that oversight framework moves from collecting data to issuing recommendations. European Banking Authority (EBA) AMLA - The EU Anti-Money Laundering Authority
- Four days ago, a 24-hour clock started running on every connected device in Europe's energy fleet. That is what the EU Cyber Resilience Act's reporting obligation means in practice: a manufacturer somewhere reports an actively exploited vulnerability, and an operator has hours — not weeks — to know whether it runs on their grid, and what to do about it. My honest read is that for most operators today, that answer still gets assembled from spreadsheets. I've written up what fusing the notification against your own asset picture,
- Twenty-six EDF calls close on 29 September. Twenty-six consortia will each build something good. How many of those will talk to each other afterward? That's the question I can't stop asking while reading this year's Work Programme. The Fund rightly insists on European-controlled IP and multi-country consortia — but nothing in a single-topic grant obliges the quantum-networking project and the AI-situational-awareness project to share a data model once both are done. The article is about why I think the composing layer, not the
- If your explainability programme just slowed down because a deadline moved, what was it really for? That is the question I keep coming back to since the AI Omnibus deferred the AI Act's high-risk obligations to December 2027. Fifteen months of runway — and I suspect some teams will spend them. In the rooms I sit in, nobody has ever asked whether a system is compliant by August. They ask why it said what it said, and whether the data left the building. Those questions predate the regulation and will outlast the deferral.
- Could your organisation show a regulator which clause it relied on — for one consignment, on one date? That question has been on my mind since the EUDR date moved again, to 30 December. Everyone is watching the deadline. Almost nobody is looking at what the obligation does to the systems underneath it. Search-based compliance tools return the passage closest to your question. They cannot tell you what they left out. At consignment volume, that gap is the whole risk — and the plot data you collect is a precise map of your own
- Which of your exposures share a river? It is not a question a credit model was built to answer, and it is close to what the EBA's draft 2027 stress test methodology now puts to sixty-three European banks — flooding across EEA Member States at the same time, layered on a policy shock. What strikes me is that cutting the data points by around 55 per cent does not make the exercise lighter. It moves the weight from reporting to modelling, and modelling is the part that cannot be outsourced to a template. #RiskManagement #DORA
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.







