Home/Agentic AI

For regulated businesses

Agentic AI in production, with audit trails regulators accept

Most AI pilots never reach production, and in financial services the blocker is rarely the model - it is governance. I design and build agentic systems with observability, human checkpoints and complete audit trails from the first sprint, because audit trails cannot be meaningfully retrofitted.

Deployed, not piloted

This is not a practice area invented for the AI cycle. As VP of Technology at Intick, a block trading venue for futures and options, I built and ran a Claude-powered incident-triage agent in production: incidents published to Azure Service Bus triggered a tool-using loop that found the root cause and alerted the right people in Slack. Its tools were then extracted into MCP servers used across the company, so colleagues could put the same capabilities into their own work. All of this ran next to a platform where a single failed block order could be existential. That experience shapes everything here: reversibility-classified action spaces, human approval gates for what cannot be undone, and traces a compliance officer can read without an engineer translating.

What I build and review

  • Agentic system design and build: production LLM workflows, evaluation gates, guardrails and fallback paths
  • Audit-trail and observability design aligned to EU AI Act logging obligations and FCA expectations - the high-risk obligations became enforceable on 2 August 2026
  • AI agent security review mapped against the OWASP Top 10 for Agentic Applications: prompt injection paths, tool misuse, credential exposure
  • AI capability assessment: separating shipped systems from demos, for boards and for buyers
  • Claude Code adoption for engineering teams: skills, hooks and review tooling, backed by published open-source work
  • AI workflow adoption: mapping how the team actually works, then shipping agents and MCP servers over the company's own data as shared tools everyone uses
  • Operations automation: incident triage, cloud cost review, backlog preparation and pre-merge review, encoded once and run on demand

The governance dividend

Teams treat audit trails as drag. They are the opposite: the permission slip that lets agents near consequential work at all. A system that can always answer "what did it do, and why" gets deployed into higher-value workflows; one that cannot stays a pilot forever. I have written up the working method in How to audit AI agents and the underlying argument in the agent observability essay.

Pricing

£600 / dayDesign, build and review

Flat rate across advisory, audits and hands-on build work.

2-5 daysAgent audit or security review

Inventory, trace inspection, OWASP-mapped findings and a prioritised fix list.

Sprint-scopedProduction builds

Short sprints with a working, traced system at every checkpoint - no big-bang deliveries.

Have an agent that needs to reach production?

Tell me where it is stuck - the model, the governance or the confidence - and I will tell you what it takes to ship it.

Start a conversation