I lead engineering teams that build AI platforms. My focus is how to let AI agents act in regulated work and still pass an audit: risk tiers, eval gates, purpose limits and logs an auditor can read.
Before this I led engineering for a logistics platform running in 130 countries at Maersk. Patent application filed (pending) on AI agents for customs clearance.
ISO/IEC 42001 Lead Auditor · ISO/IEC 27001 Lead Auditor · AWS Solutions Architect · Azure Solutions Architect Expert · TOGAF
Each one runs offline in a few minutes, has tests, and says plainly what it does not do. Personal work, built in my own time.
| Repo | What it shows |
|---|---|
| agent-action-tiers | Read, act, spend: three risk tiers for agent actions, a policy gate, and a log that shows if anyone edited it. |
| agentic-os | A larger reference: agents ground plans in a domain graph and request governed capabilities, with every check traced. |
| agent-governance-kit | Reads agent run traces and reports gaps against EU AI Act Articles 12 and 14 and ISO/IEC 42001 Annex A. |
| compliance-as-code | ISO/IEC 42001 and EU AI Act controls as code, with an AI bill of materials. |
| llm-gateway | One API in front of several model providers: routing, fallback, budgets and usage records. |
More at mindfulcto-labs.
Fixes to open-source agent and observability projects, including a merged change to Prometheus Alertmanager and open pull requests to Google ADK for Go, the Claude Agent SDK for Python, Dagster, AWS MCP servers and promptfoo. All pull requests.
themindfulcto.com: AI governance, agent safety, and how engineering teams work with AI. I also post on LinkedIn.
ORCID · Google Scholar · London, UK
Views here are my own and not those of any employer, past or present.