Verified deployments · fixed attribution

Four regulated systems, shipped.

Each one anchors a pipe in the method. These are delivered systems under real regulators — not pilots, not slideware. Figures are as delivered; attribution never moves between cases.

Insurance · SAMA-regulated · Saudi Arabia
Najm Insurance
Vision AI under the Gulf’s strictest financial regulator. Delivered with DevGap.
Anchors · Constrained Identities
6,000+
Daily cases
40+
Cities
SAMA
Regulated
ADR
Every decision

A vision-AI claims system operating at national scale, where one over-privileged agent could breach the strictest financial regulator in the Gulf.

The problem

Najm processes thousands of motor-accident claims a day across Saudi Arabia, and wanted vision AI in that pipeline — automated damage assessment at national scale. The governance gap: the platform was a monolith with broad database access, so dropping an autonomous agent into a SAMA-regulated environment meant any over-privileged process could reach the wrong record. At that scale, an agent acting without a trace isn’t a bug — it’s a reportable breach.

Pipes deployed
SEC-1Pipe 01
Constrained Identities
Every agent scoped to a least-privilege service account, zero default write. Destructive actions blocked at the keyring, not by instruction.
ISO-2Pipe 05
Legacy Insulation
Monolith broken into microservices behind gateways — agents work on insulated feeds, never the core claims database.
AUD-1Pipe 02
Attributable Actions
Immutable audit log on every decision — traceable and reversible in under 30 seconds for a SAMA examiner.
What we shipped
ADR / decision
Every architectural call recorded
Monolith → microservices
Production vision-AI claims system
Live since 2024
Continuous SAMA-grade governance
// pull-ready · the receipt

6,000 claims a day, under the Gulf’s strictest financial regulator — and not one agent with admin rights.

What this means if you run regulated financial services

Your exposure was never the model. It’s the service account behind it — and one agent with broad write access is one audit finding from a breach.

Claims, underwriting, KYC, fraud — the moment an agent can reach a system of record, the regulator’s question is no longer “is it accurate?” but “who authorised that, and can you prove it?” We scoped every identity to its blast radius before a single model went live. The AI Plumber Day maps your agent identities to your regulator’s requirements in a single day.

Government · Cultural infrastructure · India
Govt of India / NMML
Prime Ministers’ Museum, New Delhi. Delivered with DevGap India / Digital Dali Labs.
Koen Van Lysebetten with the India delivery team
India delivery team · New Delhi
Anchors · Attributable Actions
€10M+
Contract value
180+
AV / AR-VR endpoints
99.9%
Uptime SLA
5-yr
O&M term

A sovereign cultural estate where every automated action must be attributable — and survive the scrutiny of a national government.

The problem

The Government of India commissioned an end-to-end immersive AV and AR/VR estate for the Prime Ministers’ Museum — 180+ endpoints synchronised from a central control engine. The governance gap: the infrastructure cannot leave the country, and at ministry scale “we don’t know why the system did that” is not an answer you give a national government. Attribution and sovereignty weren’t features — they were the terms of the contract.

Pipes deployed
AUD-1Pipe 02
Attributable Actions
Every decision and action on a read-only ledger — built to survive a regulator, not to satisfy a dashboard. Traceable and reversible in under 30 seconds.
ISO-2Pipe 05
Legacy Insulation
Runs entirely on in-country infrastructure — no data path touches a foreign cloud.
LMT-1Pipe 04
Kill Threshold Monitoring
24/7 kill-switch monitoring across the synchronised estate — any anomaly halts and escalates.
What we shipped
€10M+ delivery
Full design, build & integration
180+ endpoints
Under a 99.9% uptime SLA
5-year O&M
Operations & maintenance term
// pull-ready · the receipt

180+ endpoints under a national government — every automated action traceable to a single ledger entry in under 30 seconds.

What this means if you run government or public infrastructure

The question isn’t whether your AI works. It’s whether you can explain every action to a minister, a court, or an FOI request — and whether the data ever left the country.

Most public-sector AI can answer neither. We built the audit trail to survive a regulator and ran the whole estate on sovereign infrastructure, so attribution and residency were architectural, not promised. A Board Briefing gives your leadership a decision-ready governance posture for public-sector AI — strategy, risk and a proposal they can sign.

Public transit · EU · Belgium
De Lijn
A board-approved EU AI Act roadmap across the organisation.
Anchors · Human-in-the-Loop Gates
5,000+
FTE in scope
Board
Approved
GDPR
Guardrails
EU AI Act
Classified

A 5,000-person public body adopting AI without handing irreversible decisions to a system no human signed off on.

The problem

De Lijn — Flanders’ public transport operator, 5,000+ staff — wanted to move on AI across the organisation. The governance gap: under the EU AI Act and GDPR, a public body cannot hand irreversible decisions to a system no human signed off on. But blanket caution kills the velocity that makes AI worth adopting. They needed both — defensibility and speed — and a posture leadership could put their name to.

Pipes deployed
PRIORGate · before build
EU AI Act Classification
Every use case risk-classified and mapped to its EU AI Act tier before a line of code ran — not bolted on after.
HITL-3Pipe 04
Human-in-the-Loop Gates
High-stakes actions pause for a human authorisation token — but only where the regulation demands it, so throughput survives.
AUD-1Pipe 02
GDPR Guardrails
Data-category mapping and logged provenance on every AI decision touching personal data.
What we shipped
Classification + roadmap
EU AI Act tiering across the org
Board-approved
Across 5,000+ FTE in scope
129% projected ROI
On the prioritised roadmap
// pull-ready · the receipt

A 5,000-person transit authority got a board-approved AI roadmap — EU AI Act-classified, 129% projected ROI.

What this means if you run EU-regulated infrastructure

The EU AI Act isn’t a checkbox you bolt on later. It decides what you’re allowed to build at all — and classifying after you’ve built means you rebuild.

Transit, utilities, public services — get the classification right first and you ship with the board’s name on it; get it wrong and you’re unwinding a system the regulator won’t accept. We classified every use case up front, then placed human gates only where the Act requires them. A Board Briefing turns your EU AI Act exposure into a decision your board can actually sign.

Hospitality intelligence · United States
US Restaurant Intelligence
A LangGraph multi-agent system replacing a manual operation.
Anchors · Kill Threshold Monitoring
200 → 3
FTE to agents
~90%
Cost reduction
Multi-agent
LangGraph
Auto
Suspend on breach

A multi-agent pipeline with real autonomy — and a hard backstop that fires before a runaway loop becomes a runaway bill.

The problem

A US hospitality-intelligence operator ran a 200-person manual operation gathering and structuring restaurant data, and wanted to replace it with a LangGraph multi-agent system. The governance gap: unattended agents loop, spike cost and drift at 3 AM with nobody watching. At multi-agent scale, a single runaway loop can burn a month’s budget before anyone logs in — the economics only work if failure is contained automatically.

Pipes deployed
LMT-1Pipe 03
Kill Threshold Monitoring
Continuous telemetry on speed, spend and error volume — automatic suspension the moment any threshold is breached. The agents run free inside a boundary they can’t cross.
AUD-1Pipe 02
Attributable Actions
Every agent action logged — so a suspension comes with the trace that explains exactly why it fired.
HITL-3Pipe 04
Human-in-the-Loop Gates
On breach, the pipeline escalates to a human instead of delivering a bad output downstream.
What we shipped
LangGraph multi-agent
Replaced the manual operation
200 FTE → 3 agents
Same output, fraction of the headcount
~90% cost reduction
With failure contained automatically
// pull-ready · the receipt

200 people replaced by 3 agents at ~90% lower cost — with a kill threshold that fires before a runaway loop becomes a runaway bill.

What this means if you run a US commercial enterprise

The upside of agents is obvious. The downside is invisible until the invoice arrives — and autonomy without a backstop isn’t efficiency, it’s an unmonitored liability that happens to be cheap until the night it isn’t.

Back-office automation, data ops, customer workflows — the agents that save you 90% are the same ones that can spike spend or drift at 3 AM. We gave them real autonomy inside a boundary they can’t cross, with telemetry that suspends them on breach. The Build Sprint takes one of your processes from manual to a governed agentic prototype — on your data — in two days.

Your system is the fifth case study.

Book a 20-minute call