Home/Agentic AI
For regulated businesses
Agentic AI in production, with audit trails regulators accept
Most AI pilots never reach production, and in financial services the blocker is rarely the model - it is governance. I design and build agentic systems with observability, human checkpoints and complete audit trails from the first sprint, because audit trails cannot be meaningfully retrofitted.
Deployed, not piloted
This is not a practice area invented for the AI cycle. As VP of Technology at Intick, a block trading venue for futures and options, I built and ran a Claude-powered incident-triage agent in production: incidents published to Azure Service Bus triggered a tool-using loop that found the root cause and alerted the right people in Slack. Its tools were then extracted into MCP servers used across the company, so colleagues could put the same capabilities into their own work. All of this ran next to a platform where a single failed block order could be existential. That experience shapes everything here: reversibility-classified action spaces, human approval gates for what cannot be undone, and traces a compliance officer can read without an engineer translating.
What I build and review
- Agentic system design and build: production LLM workflows, evaluation gates, guardrails and fallback paths
- Audit-trail and observability design aligned to EU AI Act logging obligations and FCA expectations - the high-risk obligations became enforceable on 2 August 2026
- AI agent security review mapped against the OWASP Top 10 for Agentic Applications: prompt injection paths, tool misuse, credential exposure
- AI capability assessment: separating shipped systems from demos, for boards and for buyers
- Claude Code adoption for engineering teams: skills, hooks and review tooling, backed by published open-source work
- AI workflow adoption: mapping how the team actually works, then shipping agents and MCP servers over the company's own data as shared tools everyone uses
- Operations automation: incident triage, cloud cost review, backlog preparation and pre-merge review, encoded once and run on demand
The governance dividend
Teams treat audit trails as drag. They are the opposite: the permission slip that lets agents near consequential work at all. A system that can always answer "what did it do, and why" gets deployed into higher-value workflows; one that cannot stays a pilot forever. I have written up the working method in How to audit AI agents and the underlying argument in the agent observability essay.
Pricing
Flat rate across advisory, audits and hands-on build work.
Inventory, trace inspection, OWASP-mapped findings and a prioritised fix list.
Short sprints with a working, traced system at every checkpoint - no big-bang deliveries.
Tell me where it is stuck - the model, the governance or the confidence - and I will tell you what it takes to ship it.