Expertise
AI Governance & Responsible AI
AI incidents are climbing and new laws land every year. I build AI that's responsible by design — risk, compliance, and evaluation built in from day one, not bolted on after a breach.
Governance isn't the thing that slows you down. It's the thing that lets you actually ship — because a system you can't defend doesn't reach production, it reaches the news.
Why governance isn't optional
The numbers keep moving in the wrong direction. Stanford's 2025 AI Index recorded a record 233 documented AI incident reports in 2024 — up 56% year on year — and 131 new US state AI laws plus 59 federal rules in a single year. Leaders consistently name inaccuracy, regulatory exposure, and cyber risk as their top concerns with AI.
This isn't paperwork. It's the difference between a system you can defend in front of a regulator and one that defends you in front of one. The teams that treat governance as a launch gate, not an afterthought, are the ones still standing a year later.
Responsible AI isn't a constraint on what you can build. It's the precondition for being allowed to keep building it.
Responsible by design, not by audit
The Human Endeavours build shows the pattern in full. The goal was a diagnostic report drafted in minutes — but the design constraint was responsibility, and it shaped every decision:
- The model writes from your material. It reads the actual interview transcript and the actual questionnaires. It's not inventing a person — it's organising what's already true.
- A clinician is always the author of record. The 15 minutes produces a draft. The psychologist's judgement, voice, and accountability remain the final word. The model drafts; the person decides.
- Privacy and consent are non-negotiable. Sensitive health information stays within the controlled environment; participants are told how their data is used. This mirrors the responsible-AI stance NDIS thinkers like Team DSC are pushing — AI as a tool that frees clinicians for participant-facing work, never as a replacement for human judgement.
Human-in-the-loop wasn't a constraint we added at the end. It was the whole point.
What I actually put in
Governance is a set of engineering practices, not a document. Here's what lands in a build:
- Evaluation harnesses that test outputs against your real cases before they ship — and on every change after.
- Bias and hallucination testing against the actual edge cases your domain throws at it, not a generic benchmark.
- Guardrails on inputs and outputs, so the wrong question is caught before it becomes the wrong decision.
- Audit-ready documentation — what the system does, on what data, with what controls — that a reviewer can actually read.
- Red-teaming for adversarial inputs, because the person who finds your gap won't be friendly about it.
Compliance without paralysis
I map the build to your regulatory context — NDIS, privacy law, your industry's rules — and keep it practical. The goal is a system you can operate and prove, not a binder nobody reads. Done wrong, governance is a tax. Done right, it de-risks the build so it actually reaches production; the alternative is a breach or a regulator at the door, which is slower by far.
If you're sitting on a workflow where the valuable people are buried in synthesis work and the stakes are real, that's exactly where responsible AI earns its keep. The fix isn't a bigger model or a cleverer prompt — it's treating the work as a system problem, with a human back in front of the result.
Frequently asked
What is responsible AI?
AI that is accurate, fair, private, and accountable — with a human responsible for the outcome. It's designed in from the start, not patched in after something goes wrong.
Do you work in healthcare or NDIS?
Yes. For Human Endeavours I built the AI pipeline that drafts neuroaffirming diagnostic reports in 15 minutes, with the clinician always in control. Sensitive health data stays in a controlled environment.
How do you handle data privacy?
Data stays within your controlled environment, participants are told how it's used, and nothing is sent to a third party for training. Consent is non-negotiable.
Doesn't governance slow delivery?
Done wrong, yes. Done right, it de-risks the build so it actually reaches production — the alternative is a breach or a regulator at the door, which is slower by far.