What I help with
Two tracks. I build AI systems for organizations that have requirements on them, and I assess the decisions that come before the build. Engagements often start in the second track and continue into the first.
I build
Most AI systems can be made to work. The hard part is making them work in a way that holds up when someone asks why the system answered the way it did. This is how I build:
The guardrail runs before the model call
Which model may be used is determined by how the information is classified — and determined before anything is sent, not after. Sensitive data cannot reach the wrong provider through a configuration mistake, because the path does not exist.
The model proposes, the system decides
Where an answer carries consequences, the decision is made by rules a person can read. The language model may surface what the rules missed and raise an alert level — never lower one.
Claims are traced to their source
A quotation that cannot be found in the source text passes straight through most systems. Here it is dropped, and the drop is visible.
The boundary is tested, not promised
The architectural decisions that carry the solution are written as tests. If someone later removes a guardrail, the build fails. That is the difference between a principle in a document and a principle that holds.
Cost has a ceiling
Budget and quota are checked before the call. An AI system without a cost ceiling is an open invoice, and it is always discovered too late.
In practice that means agents and AI services that read, compile and propose inside your own systems — built so the rollout can be explained to the data protection officer, the auditor, and whoever maintains it after me.
I assess
- AI Impact Assessment (AIIA)
- A structured assessment before you introduce AI, from a quick scan of an idea to a full review of a planned system: business impact, the people affected, the legal context including the AI Act, risks, information security, responsibilities and vendor dependencies. The output is a concrete recommendation — go ahead, hold off, or fix these things first.
- AI Strategy
- What should AI actually do in your organization — and in what order? I help you build a strategy grounded in your operations, not in vendor roadmaps. The output is a direction you can defend to your board and your auditors.
- Enterprise AI Architecture
- Before you deploy agents, copilots and AI services, someone has to decide how they fit together: data flows, integration points, security boundaries, human oversight. I design the architecture that comes before the platforms.
- Identity & Security Architecture
- Identity, federation and access are the foundation everything else stands on — and the first thing AI systems put under pressure. Years in complex public sector environments have given me a solid understanding of identity and federation, and I help you set the right requirements before the architecture is locked in.
- Public Sector Digital Transformation
- Swedish municipalities and agencies operate under constraints most consultants have never met: public procurement, systems management models, legal frameworks, political governance. I have spent a large part of my career inside those constraints.
- Technical Due Diligence
- An independent, experienced review of an architecture, a vendor proposal or a procurement before you commit. I have no platform to sell you, which makes my answers simpler.
- AI Governance
- The AI Act, the Cybersecurity Act, ISO 42001 and your existing information security work all land in the same place: your organization. I help you understand which requirements actually apply, which controls you need, and what to put in your procurements — the step before tools like Vanta and Drata become useful.