Jakob Lange

Independent consultant — AI systems · sovereignty · security behaviour

AI systems that hold up. In production, under audit, and with the people who use them.

I help European organisations design, build and govern AI and platform systems — from tokenization and context architecture to DORA-grade resilience and the human behaviour that decides whether security works.

Location
Leipzig region, Germany · remote across the EU
Availability
Limited — on request only
Languages
English · German
Formats
Assessment · Advisory · Build · Training

01 Fields of work

Six fields, one standard.

All services

Every engagement is judged by the same question: will this still hold up in production, under audit, and with the people who have to use it?

  1. 01 AI

    AI Engineering & Architecture

    From tokens to production: context architecture, retrieval, agents and deployment that survive contact with real data.

    Tokenization and context engineering: budgets, chunking, structured promptsRetrieval-augmented generation (RAG) and knowledge-management AIAgent architectures, tool use and orchestration
  2. 02 SOV

    Sovereignty & Compliance

    DORA, data integrity, data sovereignty and EU-conform hosting — designed into the system, not audited in afterwards.

    DORA: ICT risk management, third-party risk, resilience testing, incident reportingData integrity: lineage, immutability, verification and evidence trailsData sovereignty: where data lives, who can reach it, and under which law
  3. 03 SEC

    Security Behaviour

    Security fails at the keyboard. Assess how people actually behave under pressure, then train and design for it.

    Security behaviour assessments: observation, interviews, simulated attacksSocial engineering resilience: phishing, pretexting, AI-generated deceptionHuman-in-the-loop evaluation of security-critical and AI-assisted workflows
  4. 04 PLT

    Platforms & Infrastructure

    Internal platforms, IT infrastructure and deployment pipelines built to be owned — by your team, on your terms, in your jurisdiction.

    Internal platform and tooling developmentIT infrastructure architecture: compute, storage, networking, identityVirtualisation and containerisation strategies, incl. GPU workloads
  5. 05 UX

    Enterprise UX & Workflow Design

    Dashboards, internal software and AI-assisted workflows that people use because they work — researched, accessible, measured.

    UX research for internal tools: contextual inquiry, task analysis, usability testingDashboard and information design for operations, risk and managementWorkflow optimisation and process redesign around real work
  6. 06 STR

    AI Strategy & Business Development

    Where AI creates value for your organisation, what it costs, and how to build the capability — decided on evidence, not on vendor decks.

    AI use-case discovery and prioritisation with business casesBuild, buy or partner decisions and vendor due diligenceOperating models: roles, governance, capability building

02 How I work

Assess. Decide. Build. Verify.

  1. 01

    Assess

    Every engagement starts with evidence: architecture reviews, interviews, log and data inspection, a look at how people actually work. No slide-ware before there is a diagnosis.

    • Current-state map
    • Risk and opportunity register
    • Decision memo
  2. 02

    Decide

    Options are laid out with their trade-offs — cost, sovereignty, compliance exposure, operational load — so the decision is yours and defensible in front of a board or an auditor.

    • Target architecture
    • Roadmap with checkpoints
    • Build / buy / partner call
  3. 03

    Build

    I work inside your team, not above it: prototypes that become production code, documentation that AI agents and humans can both read, and controls that are designed in rather than bolted on.

    • Working system
    • Runbooks and ADRs
    • Evaluation harness
  4. 04

    Verify

    Behavioural tests, resilience exercises, red-team style reviews and follow-up measurements. If something did not hold up, we learn why and fix the cause — not the symptom.

    • Test evidence
    • Audit-ready documentation
    • Training and handover

04 Principles

What I optimise for.

  • Sovereignty by default

    Data, models and infrastructure stay under your control unless there is a deliberate, documented reason otherwise. EU hosting is the baseline, not the premium tier.

  • Evidence over hype

    Every AI recommendation comes with an evaluation, a cost model and a failure analysis. If the numbers do not support it, I will say so.

  • Humans in the loop

    Security fails at the keyboard, not in the firewall. Systems are designed around how people behave under pressure, and people are trained for the systems they get.

  • Build for the audit

    Documentation is a product, not a chore. Decisions, controls and tests are written down as they happen — readable by your auditors and by your coding agents.

Contact

Start with a conversation.

No forms, no funnels. Write me a short note about your situation — I answer personally, usually within two working days.

Mon – Fri, 18:00 – 20:00 CET