Ship AI that is secure, compliant, and defensible.

I design, build and secure AI systems with your engineering team, so they hold up in production and in an audit. For CTOs, Heads of Engineering, Heads of AI and CISOs at European tech companies.

Three questions you cannot confidently answer

01

Is your system exposed to agent attacks you have not tested for?

You find out which attacks work against your agents, and get them closed.

02

Which EU AI Act obligations apply to you?

You get a written answer on which obligations apply and what engineering must change.

03

Can you prove it when an investor, customer or regulator asks?

You get evidence you can show anyone, written alongside the code.

Where to start

Most AI security and compliance risk is decided before launch. I start where your system is today and stay until the findings are closed. Fixed fees where the scope allows. Nothing auto-renews.

SECURE-BY-DESIGN

Threat model and security architecture review

For teams whose architecture is set and whose code is being written. You get a threat model of the system you are building. The fixes land in your code, and the EU AI Act documentation is written alongside.

Fixed fee where scope allows. Quoted on discovery call.

PRE-LAUNCH

AI Risk Baseline

For systems about to launch or just launched. You find out which attacks work, which EU AI Act obligations apply, and where you fall short. You get one document you can show a board, investor or regulator.

Fixed fee. 2 to 3 weeks elapsed. Includes a 30-day follow-up call. Quoted on discovery call.

POST-LAUNCH

Ongoing security and compliance partner

For live systems that keep changing. You keep a senior specialist on call for hardening, architecture review, incident response, and keeping your EU AI Act evidence current.

Monthly retainer. 3-month minimum. Quoted on discovery call.

DESIGN & DELIVERY

AI architecture and build

For teams that need an architect who ships code. You get a working AI system built with your team: agents, retrieval over your own data, model serving. Security, governance and evaluation are in from the first commit.

Fixed-fee scope or milestone-based. Quoted on discovery call.

Most engagements start at one of these and grow from there. Designing and building the system is a full engagement in its own right.

Findings get closed in your code

A threat model handed over as a report leaves you with the same risk you started with. I sit with your engineers, fix the specific weaknesses and write the compliance evidence alongside the code. I stay until the system holds up to scrutiny. If what you need is outside my scope, I will say so.

Four disciplines, one practice.

Most specialists cover one or two of these. I work across all four.

AI GOVERNANCE FLUENCY

Regulation, read as engineering

You get the EU AI Act and ISO/IEC 42001 requirements that apply to your system, mapped to the controls in your code. NIST AI RMF where US rules apply.

AGENT RED-TEAMING

Adversarial testing of AI agents

You find out how your agents can be misused: chained tools, trust built up over several steps, agents misleading each other. I test with Ziran, the open-source tool I maintain.

PRODUCTION AI ARCHITECTURE

Systems that have shipped

I led the work on the AI reference architecture at PostNL (2024 to 2026), a 30,000-person organisation. It covered machine learning, generative and agentic AI, and AI at the edge. Before that, I architected enterprise AI systems at IBM. I know what breaks in production and why.

OPEN-SOURCE CREDIBILITY

Open-source work

Contributor to NVIDIA Garak and Hugging Face Transformers. Published on AI agent security and AI governance.