Services
What I do
Consulting, architecture and hands-on delivery for organisations that need AI and platform systems to be sovereign, compliant and actually used.
01 Fields of work
Six fields, one standard.
- 01 AI Tokenization and context engineering: budgets, chunking, structured promptsRetrieval-augmented generation (RAG) and knowledge-management AIAgent architectures, tool use and orchestrationPrivate and on-premise model deployment, GPU virtualisation, inference servingEvaluation harnesses, observability and cost controlAI-native development practices for engineering teams
AI Engineering & Architecture
From tokens to production: context architecture, retrieval, agents and deployment that survive contact with real data.
- 02 SOV DORA: ICT risk management, third-party risk, resilience testing, incident reportingData integrity: lineage, immutability, verification and evidence trailsData sovereignty: where data lives, who can reach it, and under which lawEU-conform hosting strategies: on-premise, sovereign cloud, hybridEU AI Act readiness: classification, documentation, human oversightAudit-ready documentation as a by-product of engineering
Sovereignty & Compliance
DORA, data integrity, data sovereignty and EU-conform hosting — designed into the system, not audited in afterwards.
- 03 SEC Security behaviour assessments: observation, interviews, simulated attacksSocial engineering resilience: phishing, pretexting, AI-generated deceptionHuman-in-the-loop evaluation of security-critical and AI-assisted workflowsAwareness and behaviour-change training for interdisciplinary, intercultural teamsSecurity culture metrics and reporting for management and regulatorsSecure-by-design review of workflows, roles and permissions
Security Behaviour
Security fails at the keyboard. Assess how people actually behave under pressure, then train and design for it.
- 04 PLT Internal platform and tooling developmentIT infrastructure architecture: compute, storage, networking, identityVirtualisation and containerisation strategies, incl. GPU workloadsDeployment pipelines, environments and release practicesIntegration layers and APIs between legacy and modern systemsMigration from proprietary SaaS to owned or EU-hosted alternatives
Platforms & Infrastructure
Internal platforms, IT infrastructure and deployment pipelines built to be owned — by your team, on your terms, in your jurisdiction.
- 05 UX UX research for internal tools: contextual inquiry, task analysis, usability testingDashboard and information design for operations, risk and managementWorkflow optimisation and process redesign around real workDesigning AI-assisted workflows: trust, oversight, error recoveryAccessibility compliance (WCAG 2.2, EN 301 549, BFSG) for enterprise softwareAdoption and efficiency measurement
Enterprise UX & Workflow Design
Dashboards, internal software and AI-assisted workflows that people use because they work — researched, accessible, measured.
- 06 STR AI use-case discovery and prioritisation with business casesBuild, buy or partner decisions and vendor due diligenceOperating models: roles, governance, capability buildingBusiness development in AI-driven markets and partnershipsResearch and innovation project consulting (public funding, consortia)Executive briefings and board-level decision support
AI Strategy & Business Development
Where AI creates value for your organisation, what it costs, and how to build the capability — decided on evidence, not on vendor decks.
02 Engagement formats
Four ways to work together.
- A
Assessment
2–4 weeks · fixed scope
A focused diagnosis of one system, one process or one compliance question. Ends with a written decision memo and a prioritised roadmap.
- B
Advisory
monthly retainer
Ongoing access for architecture decisions, vendor reviews, regulatory questions and second opinions — for teams that need a sparring partner rather than a project.
- C
Build
6–16 weeks · team embedded
Hands-on delivery of an AI, platform or internal-tool system together with your engineers, including documentation, tests and handover.
- D
Training
half-day to 3 days
Security behaviour workshops, AI-native development practices, DORA for engineering teams. Interactive, measured, and tailored to your organisation.
03 How I work
Assess. Decide. Build. Verify.
- 01
Assess
Every engagement starts with evidence: architecture reviews, interviews, log and data inspection, a look at how people actually work. No slide-ware before there is a diagnosis.
- Current-state map
- Risk and opportunity register
- Decision memo
- 02
Decide
Options are laid out with their trade-offs — cost, sovereignty, compliance exposure, operational load — so the decision is yours and defensible in front of a board or an auditor.
- Target architecture
- Roadmap with checkpoints
- Build / buy / partner call
- 03
Build
I work inside your team, not above it: prototypes that become production code, documentation that AI agents and humans can both read, and controls that are designed in rather than bolted on.
- Working system
- Runbooks and ADRs
- Evaluation harness
- 04
Verify
Behavioural tests, resilience exercises, red-team style reviews and follow-up measurements. If something did not hold up, we learn why and fix the cause — not the symptom.
- Test evidence
- Audit-ready documentation
- Training and handover
Contact
Start with a conversation.
No forms, no funnels. Write me a short note about your situation — I answer personally, usually within two working days.
Mon – Fri, 18:00 – 20:00 CET