
AI Security Architecture
Secure-by-design architecture for enterprise AI: threat models mapped to enforceable mitigations, deny-by-default gateway policies, and reusable control baselines across LLM, RAG, and agentic deployment patterns.
Reference architecture and operating model for production AI across a multi-cloud enterprise: shared entry points, cost attribution, onboarding standards, and EU AI Act evidence built into the delivery path.
AWS Summit Madrid 2025: Scalable AI Adoption at Iberdrola (speaker, ES)
New teams onboarded through the standard path instead of building bespoke platform components from scratch, which cut both duplication and time to first deployment.
Model usage and cost attribution became visible across business units for the first time, which changed how leadership made capacity and investment calls.
Governed entry points became the default route for new GenAI and agentic workloads — shadow AI dropped, and security enforcement got consistent without turning into a bottleneck.
Reference architecture and operating model for production AI in a federated multi-cloud enterprise: shared controls with distributed ownership.
A European energy group had multiple teams running independent AI experiments across several cloud accounts and providers. Each team was solving the same platform problems — gateways, identity, logging, cost tracking — on its own, in parallel, mostly without knowing the others were doing it too. The result was duplicated infrastructure, zero central visibility into model consumption, and no consistent way to enforce security or governance at scale. Centralizing everything wasn't the goal; I needed a shared architecture teams could adopt at their own pace, with clear ownership boundaries and enough room for local adaptation that it wouldn't just get bypassed.
New teams onboard through the standard path without bespoke platform intervention.
Telemetry captures interaction traces consistently for security and cost attribution across business units.
Ownership boundaries reflected in delivery standards and review checkpoints.
EU AI Act evidence generated as part of the standard release gate process.
Exception paths documented and governed for teams with legitimate local adaptation needs.