Governance-first AI engineering · regulated enterprise

The model is the easy part. The plumbing is what kills you.

70% of AI pilots die before production — at the governance layer, not the model layer. I build the layer that ships: identity, auditability and kill switches for agents operating under real regulators.

Book a 20-minute call Banking · Insurance · Pharma · Energy · Government

Most governance consultants have zero real deployments. The receipts are the moat — four regulated systems, in production.

Verified deployments

Four regulated systems, shipped.

Each one anchors a pillar of the method. Figures are as delivered — attribution is fixed, never reassigned.

Insurance · SAMA-regulated · Saudi Arabia Constrained Identities
Najm Insurance
Vision AI under the Gulf's strictest financial regulator
6,000+
Daily cases
40+
Cities
SAMA
Regulated

Monolith-to-microservices migration with kill thresholds, immutable audit logs and an Agent Accountability Envelope — every architectural choice carries an ADR.

Government · Cultural infrastructure · India Attributable Actions
Government of India / NMML
Prime Ministers' Museum, New Delhi · delivered with DevGap India / Digital Dali Labs
€10M+
Contract value
180+
AV / AR-VR endpoints
99.9%
Uptime SLA

End-to-end immersive AV and AR/VR estate synchronised from a central control engine, on sovereign data residency with 24/7 kill-switch monitoring and a 5-year O&M term.

Public transit · EU · Belgium Human-in-the-Loop Gates
De Lijn
Board-approved EU AI Act roadmap across the organisation
5,000+
FTE in scope
Board
Approved
GDPR
Guardrails

An EU AI Act classification and roadmap with GDPR guardrails and human authorization gates on high-stakes actions — velocity preserved, exposure contained.

Hospitality intelligence · United States Kill Threshold Monitoring
US Restaurant Intelligence
LangGraph multi-agent system replacing a manual operation
200 → 3
FTE to agents
~90%
Cost reduction
Multi-agent
LangGraph

A multi-agent pipeline governed by telemetry that auto-suspends on runaway loops, cost spikes and error spikes — autonomy with a hard backstop.

The method · compliance by design

The 6 Pipes — governance topology.

We isolate model processes inside strict containment layers — shielding your core databases from hallucination and runaway execution cost. Four non-negotiables, built on six pipes.

Intelligence is rented. Piping is owned.

Non-negotiables · Pipes 1–4 // the four trust pillars
01
Constrained Identities
Scoped AccountsSEC-1

No agent inherits broad admin privileges. Every system runs least-privilege service accounts with strict database limits and zero default write permissions.

PreventsBlast radius when an agent misbehaves.
Anchor case
Najm Insurance · SAMA
Vision AI under the strictest Gulf financial regulator, 6,000+ daily cases.
02
Attributable Actions
Clear LogsAUD-1

Every decision, database query and citation is logged on a read-only ledger. Any AI action is traceable — and reversible — in under 30 seconds.

Prevents"We don't know why it did that."
Anchor case
Government of India / NMML
€10M+, 180+ endpoints, 99.9% SLA, sovereign data residency.
03
Kill Threshold Monitoring
Safety Stop LimitsLMT-1

Continuous monitoring evaluates speed and error volume. If the agent begins looping or spends too much, it suspends automatically — before damage.

PreventsRunaway loops and cost spirals running unchecked.
Anchor case
US Restaurant Intelligence
LangGraph multi-agent, 200 FTE → 3 agents, ~90% cost reduction.
04
Human-in-the-Loop Gates
Human Sign-OffHITL-3

High-stakes actions pause immediately and wait for manual approval. The agent cannot execute financial or legal tasks on its own.

PreventsIrreversible autonomous action with no human in the decision.
Anchor case
De Lijn
EU AI Act roadmap, 5,000+ FTE, board-approved.
Enterprise-fit · Pipes 5–6 // containment topology
05
Legacy Insulation
Safe ConnectionsISO-2

Old core mainframes sit behind strict gateway layers. The agent works with insulated, hashed data feeds — never the direct core databases.

PreventsDirect AI reach into systems of record.
Containment
API gateway wrap
Insulated feeds isolate legacy systems from agent execution.
06
Learning Loop
Fixes & RecordsGRC-4

Every workflow error and human override is documented. Each one updates the system's core rules via ADR — an evolving defense moat, not patching.

PreventsSilent recurrence of the same failure.
Containment
ADR-driven evolution
Written once, an ADR fights forever — institutional memory that compounds.
// Design artifact: the 6 Pipes — governance topology
THE 6 PIPES — GOVERNANCE TOPOLOGY
├── NON-NEGOTIABLES (Pipes 1–4)
│   ├── 1. Constrained Identities    ->  least-privilege service accounts
│   ├── 2. Attributable Actions      ->  logged, reversible, traceable <30s
│   ├── 3. Kill Threshold Monitoring ->  telemetry + auto-suspend on breach
│   └── 4. Human-in-the-Loop Gates   ->  high-stakes actions pause for a human
└── ENTERPRISE-FIT (Pipes 5–6)
    ├── 5. Legacy Insulation         ->  API gateway wraps legacy systems
    └── 6. Learning Loop             ->  ADR-driven evolution, not patching
The executive frame · why algorithms aren't enough

The 10-20-70 model.

Why agentic AI requires more than algorithms. The visible model is the tip; the value — and the risk — sits below the waterline, in the data, the operating model and the governance. The 6 Pipes live in the 90% you can't see.

10%
AlgorithmsThe visible tip
Agentic AI capabilities that enable automated insight and faster decision-making. The part everyone buys — and the part that's commoditised. A new model lands every six months; chasing it is not a strategy.
  • Agentic reasoning and decision logic
  • Model selection & prompt design
20%
Technology & dataBelow the surface
The agent-ready data and technology stack that actually supports the business — where Pipes 1, 2, 5 and the kill switch are wired in. Without it the demo never becomes a deployment.
  • Agentic-AI-ready data foundations
  • Business-context services
  • Orchestration, monitoring & lifecycle tooling
70%
People & processesThe deep mass
An agent-first operating model carried by talent and change management — where the human-in-the-loop gates and the learning loop become organisational reality. The largest mass, the most ignored, the reason pilots die.
  • North Star & strategy for agent execution
  • Agentic-AI-first process reimagination
  • Roles, responsibilities & ecosystem partnerships
  • Talent enablement, culture & change management
  • Responsible use of data and AI agents
10% algorithms · 20% tech & data · 70% people & processes 10-20-70 model after Andreas Horn · mapped to the 6 Pipes
Where the pipes sit: the four non-negotiables and the two enterprise-fit pipes are almost entirely a 20%-and-70% job. That's the whole argument — buying a better algorithm improves 10% of the system; the other 90% is the plumbing the model doesn't give you.
// Control console: risk simulation

Active Infrastructure Board.

Test the physical safety valves. Simulate a runaway cost loop, or trigger a divergence error to see how the system halts before delivering bad outputs.

// Telemetry interface v1.0 · System flow map SYSTEM NORMAL // EGRESS OPEN
INLET
ingest
HASH
[V1]
ENGINE_A
reason
ENGINE_B
verify
GATE_VALVE
ARMED // ARD-3
EGRESS
deliver
FLOW RATIO
1.0X
GATE VALVE
ARMED
ISOLATION
MONITORED
INTELLIGENCE IS RENTED · PIPING IS OWNED
Live audit logging read-only ledger
How to engage

Three tiers. One conversation.

Read-only audit, full implementation, or end-to-end orchestration. Scoped to the size of the system, not the hours.

Tier 1
Governance Assessment

Read-only audit, EU AI Act classification and a risk register. The artifact a board can act on.

€30k–€75k 4–6 weeks
Tier 2
Trust Engine Implementation

The four pillars built into production systems — constrained identities, attributable actions, gates and kill thresholds, live.

€100k–€300k 3–6 months
Tier 3
Orchestration

Multi-system, multi-client governance across the full lifecycle — the operating layer for an enterprise agent estate.

€300k–€1M+ Engagement-scoped
Read it, then install it

The method in long form — and in your runtime.

The book
The AI Plumber

The four pillars written long-form, each chapter anchored to one verified deployment. The 70% pilot-death problem, and the four non-negotiables that decide whether AI ships.

Read the framework →
Open source
Kleiber

The open-source layer that enforces the four pillars in your agent runtime. aiplumber.dev is the consultancy and the method; Kleiber is the installable proof.

Install the layer →
Koen Van Lysebetten AI Architect & Governance Advisor · DevGap

Regulatory currency: EU AI Act high-risk (Annex III) obligations apply from 2 August 2026 (operative date; subject to pending Digital Omnibus revisions — verify current status before relying on it).

Find the layer that's killing your pilot.

Book a 20-minute call