Home/Agentic AI

For regulated businesses

Agentic AI in production, with audit trails regulators accept

Most AI pilots never reach production, and in financial services the blocker is rarely the model - it is governance. I design and build agentic systems with observability, human checkpoints and complete audit trails from the first sprint, because audit trails cannot be meaningfully retrofitted.

Deployed, not piloted

This is not a practice area invented for the AI cycle. Agentic AI ran in production trading workflows and operational tooling under my technical authority at a regulated trading venue, where the systems carried real orders with real money behind them. That experience shapes everything here: reversibility-classified action spaces, human approval gates for what cannot be undone, and traces a compliance officer can read without an engineer translating.

What I build and review

  • Agentic system design and build: production LLM workflows, evaluation gates, guardrails and fallback paths
  • Audit-trail and observability design aligned to EU AI Act logging obligations and FCA expectations - the high-risk obligations became enforceable on 2 August 2026
  • AI agent security review mapped against the OWASP Top 10 for Agentic Applications: prompt injection paths, tool misuse, credential exposure
  • AI capability assessment: separating shipped systems from demos, for boards and for buyers
  • Claude Code adoption for engineering teams: skills, hooks and review tooling, backed by published open-source work

The governance dividend

Teams treat audit trails as drag. They are the opposite: the permission slip that lets agents near consequential work at all. A system that can always answer "what did it do, and why" gets deployed into higher-value workflows; one that cannot stays a pilot forever. I have written up the working method in How to audit AI agents and the underlying argument in the agent observability essay.

Pricing

£600 / dayDesign, build and review

Flat rate across advisory, audits and hands-on build work.

2-5 daysAgent audit or security review

Inventory, trace inspection, OWASP-mapped findings and a prioritised fix list.

Sprint-scopedProduction builds

Short sprints with a working, traced system at every checkpoint - no big-bang deliveries.

Have an agent that needs to reach production?

Tell me where it is stuck - the model, the governance or the confidence - and I will tell you what it takes to ship it.

Start a conversation