Twenty-five years of enterprise technology leadership, now spent building and governing production autonomous systems: agentic AI platforms, resilient guardrail engineering, blockchain infrastructure and the certification frameworks that let a board sleep at night.
Most technologists sit on one side of the line — build or govern, strategy or hands-on. My work lives across all of it, in production, every day.
A production AI operator with real-time voice and text, retrieval over a 2,300-note knowledge base, a task dispatcher, and ~30 runtime skills — built solo, running around the clock.
Fleets of independent engines under a hard governance layer: exchange-grounded circuit-breakers, killswitches, drawdown halts and reconcilers that enforce the rules faster than a human could react.
A 24/7 BlockDAG mining operation: validator / QNG node, multi-port mining pool, block explorer and live telemetry — plus Solidity smart contracts and a React/Next.js dApp front end.
Production infrastructure-as-code across Azure (AZ-305), AWS and Cloudflare, with secure WireGuard networking spanning three continents and a hardened Microsoft security estate.
The controls that make autonomous AI defensible: model-approval, audit logging, human-in-the-loop gates and a written framework aligned to UAE PDPL, the UAE AI Charter and DIFC Regulation 10.
Group CIO then CTO of a Tier-1 telecoms services group: an ITSM platform at 35k+ tickets/month and 99.9% availability, ISO 27001 certification, and an R90M budget with full P&L.
The hardest part of an autonomous system isn't the intelligence — it's proving it's under control. Here is the design philosophy that runs through everything I build.
My systems don't trust their own claims — and neither should you. Every autonomous action is logged, every state transition is checkable, and a guard layer halts any engine the moment it breaches its own rules, faster than a human could intervene.
DIFC Regulation 10 is enforceable now, and enterprise procurement increasingly requires ISO/IEC 42001 or a documented roadmap. I bring something rare to it: I have built and governed the systems the standard describes.
An inventory of every AI system you run, an honest risk classification, a gap analysis against ISO/IEC 42001 and DIFC Regulation 10, and a prioritised roadmap — in a board-ready summary.
The full AI management system — policy, risk register, model-approval and change control, audit logging, human-oversight design and supplier controls — through to certification-body audit readiness.
Technical controls for autonomous systems: circuit-breakers, killswitches, escalation paths, human-in-the-loop gates and audit trails — built with your engineers, not handed over as a PDF.
A named, accountable governance lead for boards and regulators without a full-time hire — aligned to the Regulation 10 Autonomous Systems Officer role, with quarterly reporting and incident review.
Plain-English pieces on building and governing AI you can actually defend.
The plain-English version of what Regulation 10 now requires — and where ISO 42001 fits.
The three controls that made an autonomous production platform safe — start with the boundary, not the brain.
I have spent twenty-five years in enterprise technology — from service delivery at a global integrator, through group IT operations on a €250M consolidation, to Group CIO and CTO of a Tier-1 telecommunications services business, where I delivered ISO 27001 certification, designed the Zero Trust framework and owned an R90M budget with full P&L.
Today I run a self-funded technology venture from the UAE, building and governing production autonomous systems hands-on. The discipline is the same one I have always cared about: make powerful systems, then make them accountable. ISO/IEC 42001 is that discipline pointed at AI — and I offer it to the firms that now need it.
I am based in Ras Al Khaimah, where I live with my family. When the systems are running themselves — which is the point — I am usually with them, or somewhere near the water.
Thirty minutes, no charge: I'll map where you'd stand against ISO/IEC 42001 and DIFC Regulation 10, or talk through an autonomous-systems build. If it's useful, we go further. If not, you keep the map.