The market is paying for governed agents, not generic model-building.
Public hiring and product evidence from Stripe, Notion, Brex and Adyen shows the highest-value AI roles inside fintech are about guardrails, auditability, policy enforcement, fraud and risk controls, and secure agent execution — not pure model-building. That is precisely the discipline a bank’s SWIFT administrator, ISO 27001 lead auditor and trade-finance compliance owner already practises every day.
I design and implement governed autonomous agents for high-trust financial operations: scoped permissions, approval gates, audit trails, policy engines, runtime monitoring, and secure fallback on constrained infrastructure.
AI Security team builds tooling against prompt injection, jailbreaks and tool misuse; a separate SGRC role covers ISO 27001, PCI DSS, SOX and NIST control evidence.
Agents enforce expense policy, auto-approve low-risk cases, escalate exceptions by risk level and monitor spend continuously — compliance experts become “workflow designers and policy engineers.”
Framed around explicit mandates, tokenization, SCA compliance, authentication and fraud prevention for merchant-controlled agent transactions.
Custom agents start with zero permissions, layered prompt-injection mitigations, runtime monitoring and mandatory confirmation for risky actions.
I am a mechanical engineer by training. For nearly seventeen years my machines have been a bank's — cash and general banking, credit, foreign trade, SWIFT, compliance — and today, as Assistant General Manager, I am the sole SWIFT administrator for the entire bank network.
Mechanical engineers mechanise things. I did not learn to code my way into AI; I mechanised DevOps. The substrate changed from steel to pipelines, agents and runtimes — the discipline did not change at all. That is how a trade finance AGM came to build his own autonomous AI infrastructure, alone, in the evenings, on a 2 GB VRAM laptop.
NINA is a personal, local-first autonomous AI infrastructure: a multi-agent orchestration system I designed, built and operate independently, built to run continuously on consumer hardware under strict resource constraints — every change passing through a governance layer as a governed transaction rather than a blind edit.
Stated plainly: NINA is not a product, not for sale, and not production-grade. She is a capability project under active development. What she proves is one thing, and proves it well — that I am tech-native: able to research, design, build and govern working AI systems with my own hands. I research, build, repeat.
Every tier of what I deliver, from operational survival to competitive moat.
The hierarchy is the argument: this profile operates at every level at once, not just the top or the bottom.
Organisations working with me build intellectual property that cannot be bought off a shelf. Governed autonomous AI plus custody-grade compliance in one architecture is a moat most companies will spend years trying to acquire.
ISO 27001 Lead Auditor. SWIFT administrator. Seventeen years of board-level memoranda. I give enterprises the language and the evidence to defend an AI deployment to auditors, central banks and risk committees — not just to engineers.
Most organisations have people who understand one side. The translation between “we built it” and “we can prove it is safe and auditable” is where projects die. That translation is the work.
Defined precedence rules. Differentiated trust levels per component. Explicit isolation of sensitive data. Bounded automated actions. Every change a governed transaction rather than a blind edit. Built for organisations that cannot afford a rogue agent.
Tiered inference — local models first, low-cost external second, premium providers only as fallback, re-evaluated on every call. The claim is simple: I reduce the inference bill from day one, and I can prove it from my own system’s logs.
NINA is the proof of concept. The product is a repeatable capability.
I research, build, repeat — governed, auditable systems an organisation can both trust and defend. Six problems that show up in every serious AI programme, and what I do about each.
Local and low-cost paths are preferred before anything paid, and the choice is re-evaluated continuously rather than configured once.
Nineteen providers behind one abstraction with local-first fallback. No single point of commercial or technical failure.
Precedence rules, differentiated trust levels and bounded actions, enforced at runtime rather than written in a policy nobody reads.
Sensitive data handled through a dedicated component under stricter isolation; local-first deployment for data-residency constraints.
Work specified precisely enough to dispatch and verify. Sustained delivery cadence without growing headcount.
Automated failure detection and recovery, thermal and resource guards, auto-restart supervision. Software plus physical safeguards.
Same question, three frontier models, three independent answers — none of them written by me. Each panel is raw output from a live CLI session, asked to assess the system without disclosing its internals. Computed system metrics — repository age, module and test counts, backlog, governance — are published separately in the NINA updates log.
Honest scoping is the first skill of anyone selling governance.
Strengths that are genuinely rare, weaknesses named rather than buried, opportunities that are time-sensitive, and threats already mitigated in the architecture.
Unique intersection. SWIFT administration, ISO 27001 lead audit and autonomous AI architecture in one person — this does not exist off a shelf.
Governance as runtime. Not a document. Enforced, auditable, versioned.
Constrained-environment mastery. A real commit history under a 2 GB VRAM ceiling proves resource discipline rarely found in cloud-native engineers.
NINA is not production-grade. A personal capability project under active development.
Solo operator. No team and no institutional backing; velocity depends on one person’s evening hours.
Bandwidth. A full-time executive role limits me to structured, scoped engagements.
Enterprise AI governance. Regulators increasingly require documented frameworks; few practitioners can build one from first principles.
Banking-sector adoption. Every bank is building AI. Almost none have someone who understands both the SWIFT network and the model layer.
Data-residency pressure. Local-first architecture expertise is scarce and getting scarcer.
“Just use a cloud vendor.” Local-first architecture proves vendor-independent capability; the moat is methodology, not model weights.
Credential inflation. Everyone claims AI expertise. Answered with a public dated repository and independent assessments, not slides.
Role conflict. Answered with structured, scoped engagements and clear boundaries.
The repository is private. That limits what a stranger can independently check, so here is the honest split rather than an implied claim that everything is auditable.
The deployment clock at the top of this page is fetched from GitHub’s public API by your browser, not served from mine — open developer tools and watch the request. The live architecture graph, the raw metrics feed, and the two published essays are all open to inspection. So is the GitHub profile behind them.
Commit counts, module and element totals, and gate results are computed by a script inside a private repo and published here. You cannot audit them from outside, and I am not going to pretend otherwise. What I will do is walk any of it live in a screen-share, in whatever depth you want, and answer questions from the code rather than from a slide.
A number you cannot check is worth exactly what you paid for it. I would rather name that limit than let it be discovered.
These addresses are permanent. Content is updated in place, so the links never expire or change.