
AI Security Architecture
Secure-by-design architecture for enterprise AI: threat models mapped to enforceable mitigations, deny-by-default gateway policies, and reusable control baselines across LLM, RAG, and agentic deployment patterns.

AI Security Architecture · Enterprise AI Architecture · Applied AI
I architect and secure production AI and agentic systems for regulated enterprises, currently as Global Head of AI & Data at Iberdrola, Europe's largest energy utility with 100M+ customers.
Representative examples focused on artifacts and acceptance criteria.
Papers, talks, and standards contributions on agentic AI security and governance.
Roles, credentials, and the operating context where this work was applied.
Working with






Secure production AI architecture that operates reliably at scale, with bounded authority and evidence that can be verified.
I design enterprise AI systems where security, governance, and assurance are architectural decisions, built into reference architectures, control planes, and release gates from day one, not layers added after deployment.
My approach builds on more than a decade designing and securing regulated energy and critical-infrastructure platforms. I apply the same disciplines (least privilege, access boundaries, traceability, resilience and control evidence) to LLM, RAG and agentic systems.
In large organizations, AI stalls for predictable reasons. Prototypes move quickly but break at scale when security boundaries are unclear, controls fragment across teams, and audit evidence has to be recreated on every deployment. I make scale deliberate by defining the architecture before the first line of code, with threat models, enforcement points, and acceptance criteria that teams can actually follow.
A major part of the work is security: threat modeling against OWASP LLM and agentic AI guidance, MITRE ATLAS, CSA MAESTRO, and NIST AI RMF; enforcing retrieval boundaries, tool permissions, and identity-scoped execution; building evaluation gates and assurance packages that satisfy audit and regulatory requirements including the EU AI Act.
When systems are already live, I assess them through adversarial testing and assurance reviews, delivering severity-rated findings, remediation criteria, and audit-ready evidence.
The case studies reflect this lifecycle: production AI architecture, AI security architecture, agentic AI controls, independent assurance assessment, compliance readiness, and value discovery.