Speaking

Agent governance, confidential computing, and what a system can actually prove.

What I speak about

I speak about what agent systems can actually prove, not what they claim. Talks are technical, demo-led, and usually carry a negative result alongside the working one.

Runtime governance for AI agents

Where enforcement sits between an agent's decision and its action, and what a policy gate can express that a prompt cannot.

Hardware attestation, and its limits

Validated on live SEV-SNP, TDX and H100. Including the part most talks skip: no confidential computing silicon is proof against someone who owns the machine.

Verifiable evidence and audit chains

Tamper-evident records a third party can check offline, and the difference between proving what happened and preventing it.

Model weight custody

What changes when the model leaves your data center, and why open weights do not end the custody problem.

Author of Architecting at Scale (Packt, 2026), a field guide to large-scale AI-native system design.

Organising something and think this fits? Get in touch. Contact

Coming up