The day someone asks how you govern AI, you either hand over the evidence — or hold a meeting.
The regulator, the cyber authority, the board — one of them will ask. I spent two decades inside the energy industry building the data systems operators run on. Today, is a must to turn "we're careful with AI" into an inventory, a control set and an evidence trail that stands up when the question is put in writing.
"How do you govern AI?" has one honest answer: five artefacts, or a reassurance.
Deploying AI is the easy part — most teams are past it. The hard part arrives later, when AI reaches production and maintenance decisions and someone with authority asks to see the governance. A reassurance won't hold. Five artefacts will, and either you have them or you don't:
01An inventory
Every model, agent and AI-touched workflow in the estate — including the ones IT never signed off. You can't govern what nothing has counted.
02A control set
The controls that apply, mapped to the frameworks you answer to — not an IT AI policy that stops at the plant fence and an OT standard that never mentions models.
03The evidence
For each control, the artefact that proves it runs. The gap between "we have that control" and the document that shows it is usually the whole finding.
04A named owner
Every model and agent with a person accountable for it. "The team" is not an owner an auditor accepts.
05A written fallback
What the operator does when the model is unavailable or wrong. In critical infrastructure this is the difference between a tool and a single point of failure nobody documented.
Producing those five is not a strategy exercise and it is not a slide deck. It is fieldwork: counting, mapping, and sighting the evidence. That is the work I do.
Engagements
Fixed scope, fixed timeline, and you leave holding the tool.
Each engagement measures something real and hands you the artefact behind the number — a model you can re-run, not a PDF you file. Roughly three weeks, scoped up front, no open-ended retainer to start.
01
AI Maturity Assessment
Where you actually stand — scored against 22 criteria on sighted evidence, not self-report — with a phased 18-month roadmap you can walk straight into a budget conversation.
8–12 days
You keep: the scored model, the evidence index, the roadmap.
02
Data Residency & Sovereignty Audit
Where your data actually travels across all nine stages of an AI pipeline — not just at the model. Most organisations find three or four stages sit outside the boundary they assumed they had.
8–12 days
You keep: the data-class-to-deployment-grade matrix, ready for sign-off.
03
AI Cost & FinOps Diagnostic
What AI is costing you, split by use case, against what it returned. It usually pays for itself — and on the occasions it doesn't, you'll hear that plainly.
5–8 days
You keep: the cost workbook. Re-run it every month.
Maturity and Residency run well together. Shared fieldwork — sixteen days instead of twenty, one set of interviews.
Before we talk, sit with these
Three questions that tell you whether the gap is yours.
01
If your regulator asked tomorrow how you govern AI, what exactly would you hand them?
If the answer is a meeting rather than a document, the inventory and the evidence trail don't yet exist.
02
What is the worst thing an AI agent in your environment could do today?
Most teams can't answer for the agents that already hold write access to real systems.
03
If a model shaped an operational decision and then went down, what does the procedure say the operator does?
The critical-infrastructure question. With no written fallback, the model has quietly become load-bearing.
Energy, utilities and critical infrastructure — and the government entities around them
Energy · Utilities · CNI
Home ground. Very few people in this market can hold a credible conversation about AI at the OT boundary and about sovereign deployment topology at the same time — fewer still having worked inside the operational estate rather than read about it. When AI moves from pilots into production and maintenance, that is where I'm most useful.
Government
AI-native mandates now expect entities to show not only that they deployed AI, but that they governed it. Most can deploy. Very few could hand a cyber authority an inventory, a control mapping and an evidence trail on the day it is asked for. I produce that in three weeks — as evidence, not opinion.
Start with a conversation
A first conversation runs sixty minutes, costs nothing. By the end you'll know whether there's something here worth pursuing — or not.