Ship AI that is secure, compliant, and defensible.
I design, build and secure AI systems with your engineering team, so they hold up in production and in an audit. For CTOs, Heads of Engineering, Heads of AI and CISOs at European tech companies.
Three questions you cannot confidently answer
01
Is your system exposed to agent attacks you have not tested for?
You find out which attacks work against your agents, and get them closed.
02
Which EU AI Act obligations apply to you?
You get a written answer on which obligations apply and what engineering must change.
03
Can you prove it when an investor, customer or regulator asks?
You get evidence you can show anyone, written alongside the code.
Where to start
Most AI security and compliance risk is decided before launch. I start where your system is today and stay until the findings are closed. Fixed fees where the scope allows. Nothing auto-renews.
SECURE-BY-DESIGN
Threat model and security architecture review
For teams whose architecture is set and whose code is being written. You get a threat model of the system you are building. The fixes land in your code, and the EU AI Act documentation is written alongside.
Fixed fee where scope allows. Quoted on discovery call.
PRE-LAUNCH
AI Risk Baseline
For systems about to launch or just launched. You find out which attacks work, which EU AI Act obligations apply, and where you fall short. You get one document you can show a board, investor or regulator.
Fixed fee. 2 to 3 weeks elapsed. Includes a 30-day follow-up call. Quoted on discovery call.
POST-LAUNCH
Ongoing security and compliance partner
For live systems that keep changing. You keep a senior specialist on call for hardening, architecture review, incident response, and keeping your EU AI Act evidence current.
Monthly retainer. 3-month minimum. Quoted on discovery call.
DESIGN & DELIVERY
AI architecture and build
For teams that need an architect who ships code. You get a working AI system built with your team: agents, retrieval over your own data, model serving. Security, governance and evaluation are in from the first commit.
Fixed-fee scope or milestone-based. Quoted on discovery call.
Most engagements start at one of these and grow from there. Designing and building the system is a full engagement in its own right.
Findings get closed in your code
A threat model handed over as a report leaves you with the same risk you started with. I sit with your engineers, fix the specific weaknesses and write the compliance evidence alongside the code. I stay until the system holds up to scrutiny. If what you need is outside my scope, I will say so.
Four disciplines, one practice.
Most specialists cover one or two of these. I work across all four.
AI GOVERNANCE FLUENCY
Regulation, read as engineering
You get the EU AI Act and ISO/IEC 42001 requirements that apply to your system, mapped to the controls in your code. NIST AI RMF where US rules apply.
AGENT RED-TEAMING
Adversarial testing of AI agents
You find out how your agents can be misused: chained tools, trust built up over several steps, agents misleading each other. I test with Ziran, the open-source tool I maintain.
PRODUCTION AI ARCHITECTURE
Systems that have shipped
I led the work on the AI reference architecture at PostNL (2024 to 2026), a 30,000-person organisation. It covered machine learning, generative and agentic AI, and AI at the edge. Before that, I architected enterprise AI systems at IBM. I know what breaks in production and why.
OPEN-SOURCE CREDIBILITY
Open-source work
Contributor to NVIDIA Garak and Hugging Face Transformers. Published on AI agent security and AI governance.