Andrew Stevens / Amsterdam, Netherlands / San Francisco, USA
AI governance, cloud architecture, and security. Operator, board member, and investor. Fifteen years building systems in regulated and high-growth companies.
I have spent most of my career as a founder, CTO, and CISO, usually in companies whose systems had not caught up with how fast they were growing. I now publish open control frameworks for governing AI agents, together with the code that implements them.
Fifteen years as an operator, now spent mostly on how AI systems are governed.
I have spent most of my career as an operator. Founder, CTO, CISO, usually in companies whose systems had not caught up with how fast they were growing. A lot of that work was cloud, data, and security architecture. More of it than I expected turned out to be governance: deciding what a system is allowed to do, and being able to show afterwards that it did only that.
That question is now the interesting one in AI. Teams can usually get an agent working quickly. Far fewer can say what it touched, under whose authority, or how they would stop it mid-task. I think this gap, rather than model capability, is what actually holds enterprise AI back, and since 2025 most of my work has gone into closing it, as published control frameworks with running code behind them.
I co-founded Sakura Sky, a cloud, data, and AI consultancy, and I sit on the board of Distinct Star. I write regularly, and I release the frameworks openly so people can argue with them.
Books, papers & frameworks.
The Executive AI Playbook
Strategy, governance, and execution - a working guide for leadership teams operationalising AI across regulated and high-growth businesses.
The Governed Agent Trust Environment (GATE)
A reference framework of controls for enterprise-grade trustworthy AI agents - closing the gap between agent capability and operational accountability. Published with working code.
The Trustworthy Agentic AI Blueprint
Design principles, missing primitives, and the human-in-the-loop patterns required to deploy autonomous agents responsibly inside the enterprise.
The Autonomous Horizon
A strategic white paper for the executive team - the operating model, the architecture, and the leadership decisions that will define the next decade.
Signal-to-Noise
A practical checklist for evaluating AI security tools - built around the four-stage funnel from finding to actionable vulnerability.
Still Dangerous: A Practitioner's Guide to Strength, Composure, and Capability for Executives Over Forty
A book on martial arts - discipline, practice, and the long road. Forthcoming this year.
Working reference implementations.
Everything below is published as a specification plus the code that implements it, under an open licence, with versioned releases, conformance checks, and the scope limits written down. Where a control is only partly automatable, the documentation says so. I would rather people run these and find the holes than agree with me in principle.
Governed Agent Trust Environment
Twenty controls across four layers for governing agent runtimes: identity and integrity, runtime enforcement, observability and forensics, and orchestration. Ships JSON Schema contracts, OPA/Rego policy and invariant bundles, Python and Rust reference libraries, a conformance runner, and operational runbooks. Informative mappings to NIST AI RMF, ISO/IEC 42001, OWASP AISVS, MITRE ATLAS, and NIST SSDF. Ten repositories. Not a product and not a hosted service.
AI gateway and spend-control proxy
Prices every LLM request by token, reserves the budget before the call, and returns a hard 402 before the request reaches the provider. Per-key and global limits, tokens-to-cost accounting, an append-only Postgres ledger, hot counters in Valkey, a read-only console, and Terraform for Cloud Run. Anthropic and Vertex adapters. Pre-1.0 and openly labelled as such.
An ontology language for AI systems
A version-controlled language for declaring what exists in a domain, how it connects, and what may be done to it, by whom, with what trace. One file in a git repo is the authoritative artifact; compilers emit thin projections for the systems that need them. The specification is a contract, never a runtime. What it refuses to do is part of the design.
Policy engine for LLM-generated SQL
Deterministic policy evaluation for SQL produced by a model, multi-dialect via sqlglot. Answers a narrow question well: whether a generated statement is permitted to run, decided the same way every time, before it reaches the warehouse.
Selected essays on AI, governance & cloud architecture.
- May, 2026 The Regulatory Stack, Parts 1-6: Where AI regulation meets the runtime, and what boards and engineers have to build to close the gap. Series
- April, 2026 The Mythos Ledger, Parts 1-5: The Firefox Watershed and the New Baseline of Vulnerability Series
- April, 2026 The Autonomous Horizon, Parts 1-6: Beyond Digital Transformation Series
- Apr 23, 2026 GATE: The Missing Infrastructure Layer for Agentic AI Essay
- Dec 01, 2025 Engineering the Trustworthy Autonomous Enterprise Essay
- October, 2025 The Missing Primitives for Trustworthy AI Agents, Parts 0-17 Series
- Dec 11, 2024 Reflections on the 2024 DORA Report Essay
- Nov 28, 2024 EU AI Act: Implications for Data and Cloud in Banking, Ecommerce, and Gaming Essay
Operating across founder, executive & board seats.
Board Member · Distinct Star
A permanent-capital partnership I helped establish, acquiring and backing high-quality cloud, data, security, and AI services firms while founders stay in the business. Long-term strategy, diligence on prospective member companies, and operating perspective at board level.
Co-Founder · Sakura Sky
Global consultancy focused on cloud, data, and AI. Growth strategy, hyperscaler partnerships, repeatable delivery systems, and enterprise AI & platform programmes across NA, EMEA, and APAC.
Chief Technology Officer · Orbx
Modernised commerce and platform systems across simulation, ecommerce, and digital content. Cloud-native architecture, DevOps and SRE maturity, and the foundations for AI-first systems.
Co-Founder / CISO · HereToday
Blockchain venture for digital legacy and asset succession. Zero-trust architecture, ML-assisted threat modelling, and compliance readiness across GDPR, CCPA, ISO 27001, and emerging digital asset regulation.
Head of Data Security · Canopy
Built cloud security, governance, and AI lifecycle controls for a regulated wealthtech platform. Reported to executive and board stakeholders on risk, resilience, and security strategy.
Co-Founder · Jiku.io
Cross-platform content and commerce for publishers and retailers - Channel Nine, Pacific Magazines, and others. Product direction, customer delivery, and early-stage growth.
Chief Information Officer · APC Global Systems
Digital transformation across global mining operations - telemetry, edge computing, early ML and computer vision, and IT/OT integration into executive dashboards.
Chief Mobile Officer · HotelsCombined
Owned the mobile roadmap, product, and growth across iOS and Android for a global hotel comparison platform, during its expansion across APAC. Booking Holdings acquired the business in 2018.
CTO / Head of Product · CarAdvice
Product and technology strategy for one of Australia’s largest automotive media properties, aligning editorial, commercial, and engineering behind a single roadmap. Nine Entertainment Co. (ASX:NEC) acquired a majority stake in 2016.
Always interested in what’s next.
Open to board and advisory conversations, investment opportunities, and selective operating roles where strategy, capital, and timing align. Also open to pro‑bono and volunteer work in human rights, privacy, and social action.