AI governance for regulated European operations

I build LLM systems for regulated sectors, and the evidence layer that lets others audit them: evaluation harnesses, audit trails, AI Act transparency, cost controls.

LV / PRACTICE FILE 2026Utrecht, Netherlands / Seven years in EU-regulated sectors

audit_recordredacted sample
answer_id      a4f1c2e0-9b73-4d1a-8e55-71c0f2ab9d34model_version  pinned, recorded per answersystem_prompt  v14 (live), author != approvertools_called   3 of 26 permitted, schema-validatedfree_form_sql  none permittedtenant_scope   re-verified server-sidetokens         prompt 4,812 / completion 611
§ 01

Figures on record

All figures are from work delivered first-hand.

On record
Commits, sole-authored453

Migrating 246 pipelines and 67 workflows off legacy ETL tooling

Rows in production3B

Across 44 tenant schemas, counting player-level data alongside the analytics facts

Main pipeline runtime1h40m

Down from roughly three hours after re-platforming onto 43 parallel tasks. The player-data pipeline came down from nine hours to three.

AI commits under control1,391

Production commits from AI-assisted development, each logged with pinned model versions and credential reads blocked at the tool level

Security benchmarksClean

AWS Foundational Security Best Practices and CIS benchmark conformance on the infrastructure I operate; independent penetration test, findings remediated and retested

Practice areas

  1. 01

    AI governance readiness

    Evaluation harnesses, audit trails, Article 50 transparency, agent guardrails and disclosure controls. The evidence a regulator or an enterprise buyer actually asks for, generated by the system itself.

  2. 02

    LLM systems engineering

    Retrieval, structured output through forced tool-use rather than parsed prose, regression evaluation against versioned baselines, per-call cost accounting, multi-provider failover.

  3. 03

    Data platform engineering

    Multi-tenant warehouse pipelines and migrations, RBAC and row-level security, append-only audit logging. The substrate every control above depends on.

See how engagements are scoped

Selected work

20-case

eval harness

A production LLM agent with the assurance layer built in

Vector retrieval, structured output through forced tool-use, tagged evaluation baselines with a regression-diff tool, per-call cost accounting persisted per decision, and multi-provider failover.

+5,015

lines, one release

Audit logging, RBAC and tenant isolation

A typed permission-scope vocabulary, page and action level role guards, an append-only audit log enforced by database trigger, and Postgres row-level-security tenant isolation.

246

pipelines migrated

An entire production ETL, moved and re-platformed

Sole-authored migration off legacy tooling across 453 commits, then re-platformed onto 43 parallel containerised tasks: roughly three hours down to one hour forty.

Art. 50

in shipped code

Governance written into the product, and into the agents

EU AI Act transparency reasoning at the point of interaction, guardrails blocking agents from reading credentials, least-privilege tool allow-lists, and backups taken outside model control.

Read the case studies
§ 03

Every answer carries the evidence of how it was produced

What an audit trail looks like

This is the shape of a single record from a governed LLM system: the prompt version, the model that produced it, the tools it was allowed to call, what it cost, and who signed off on the rule that constrained it. Not a policy describing the control. The control, emitting its own proof.

  • Promptversioned, author != approver
  • Modelpinned, recorded per answer
  • Toolsallow-listed, schema-validated
  • Answerstructured, never parsed prose
  • Audit recordcost, latency, evaluation

The governed answer path. Flagged nodes are the ones a regulator asks about first.

§ 04

Also in production

Built outside the governance practice

Machine learning in a live product

Random-forest classifiers predicting product potential with experiment tracking, unsupervised outlier detection flagging irregular terminal performance, churn and high-value customer models, and market-basket analysis using association rules and Markov transition matrices.

Generated product imagery for e-commerce

An image-generation service producing packshots for an online store, with a synchronous and batch path and memory ceilings so it survives constrained hosting.

Structured extraction from social commerce

Product and price extraction from Instagram captions and order threads, running under a strict contract: totals are quoted verbatim from the source, identity fields resolve server-side, and anything uncertain routes to a human rather than to the model's best guess.

The model reads; it does not decide.
Model output is an extraction with an audit trail, never an autonomous decision. Every answer records the model version that produced it. The agents themselves run under least-privilege allow-lists I wrote.

Engagements start with a scoping call. You work with the person who does the work.