No independent evidence on whether Scotland's AI strategy is being delivered.
If any of this sounds familiar, we should talk.
These are the recurring, expensive, hard-to-scale problems I take on. If one is costing your team time or money, that's the conversation to start.
Repetitive admin
Email, documents, data entry and routing that eats hours every week.
Unreliable AI
Demos that work and production that doesn't. Hallucinations, drift, no guardrails.
Knowledge retrieval
Answers buried in documents your team can't search or trust.
Integrations
AI that doesn't connect to the CRM, inbox or systems you already run.
Agents & automation
Workflows that need orchestration, approval gates and audit trails.
Governance & control
Who can the AI touch, and what happens when it's wrong?
AI systems built for reality. Not just the demo.
Design, implementation and hands-on technical ownership for UK organisations that want AI to remove work, improve decisions and connect to the systems they already use. Fixed-scope implementation first — larger programmes only scale into dedicated delivery after the economics and the need are real.
AI Opportunity & Automation Audit
Process review, data readiness, prioritised opportunity map, 90-day roadmap.
£1,500–£2,500 · 1–2 weeksAI Workflow Automation
Email/document intake, classification, decision routing, CRM updates, human approval steps.
£5,000–£12,000 · 2–4 weeksInternal AI Knowledge System / RAG
Document ingestion, retrieval architecture, source-grounded answers, permissions, citations.
£7,500–£15,000 · 3–6 weeksAI Sales & CRM Intelligence
Lead health signals, meeting prep briefs, CRM summarisation, opportunity risk alerts, management digests.
£8,000–£18,000 · 3–6 weeksAgentic Operations System
Tool/API integration, state orchestration, approval gates, least-privilege access, audit trail.
£12,000–£30,000 · 4–8 weeksAI MVP Productionisation / Rescue
Architecture review, security/secrets review, error handling, observability, deployment hardening.
£5,000–£20,000 · 2–6 weeksAI Governance, Permissions & Control Review
Data access mapping, role/permission review, human approval points, agent tool authority, audit/logging.
£4,000–£10,000 · 2–4 weeksBespoke AI Platform / Integration
Custom build: discovery, architecture, web/backend engineering, AI/ML components, cloud deployment, data pipelines, QA, handover.
From £20,000 · scope-ledIndicative prices are subject to discovery, scope, delivery risk and requirements. Third-party licences, model/API usage and cloud costs are excluded unless specifically included. AI systems are probabilistic; where consequences matter, appropriate human review and control should remain part of the design.
Built, tested and published.
Every build publishes the problem, the stack, the result and the failure modes. No manufactured certainty.
Client Systems
Scotland AI Observatory
Evidence-led observatory tracking all 10 national AI commitments with sources and dates.
10 commitments tracked · adoption index · SME diagnostic
Cloudflare Pages · Workers · D1
Open Source
AgentInterdict
Autonomous AI agents can take unsafe actions with no runtime enforcement.
Runtime enforcement engine: trust context, verify authority, interdict unsafe action.
96.5% block rate on a 200-attempt injection suite
Python · Cloudflare Workers · D1
SovereignRoot
AI agents have no human-owned boundary they cannot cross.
Signed sovereignty.json constraint policy, local-first and vendor-neutral.
Free · private · cryptographically signed
Static · local-first
Assentia
Browser agents silently grant more consent than their user delegated on cookie and tracking interfaces.
Local delegated-consent enforcement layer giving agents a policy decision point before consent UI.
Fail-closed · zero-network by default · MIT
Python · FastMCP · optional local Ollama
CatalogLock
Agents discover MCP and ARD catalogs, then connect blindly. Stable identity is not stable capability; reviewed state drifts.
Deterministic pre-connect security gate: validates ARD entry sources, snapshots MCP surfaces under explicit profiles, freezes reviewed state into a CI-diffable lockfile.
135/135 tests passing · zero runtime dependencies · flags critical drift like a newly added delete_invoice tool
TypeScript · GitHub Action · SARIF output
Build Lab
ShieldedID
Identity systems store PII that becomes a breach target.
Zero-knowledge identity protocol with pairwise subject IDs.
Zero PII storage · Bulletproofs ZK in WASM
WASM · ZK proofs
STCL
LLM context windows fill up with redundant tokens, raising cost and latency.
Semantic Token Compression Layer, provider-agnostic pre-inference compression.
~38.2% average token cut · ~3.5ms overhead
Provider-agnostic
UnitedLines
Social networks are not privacy-preserving by design.
Encrypted social network as a working build.
Privacy-preserving communication
Encryption-first
What I can build
Hands-on applied AI and full-stack engineering. I build working systems end-to-end — from local LLM orchestration to production web apps on the Cloudflare free tier — and I publish the method, cost and failure modes.
Applied AI & LLM systems
Local LLM orchestration (Ollama), model selection, prompt engineering, RAG and vector retrieval, agent workflows, semantic compression. AI that runs on your own hardware — no vendor lock-in.
Full-stack web & WebGL
Static-first sites on Cloudflare Pages, serverless Functions, Three.js/WebGL immersive scenes, progressive enhancement, SEO, accessibility and performance budgets. This site and the Observatory are built this way.
Automation & data pipelines
n8n workflows, scheduled cron jobs, data ingestion and ETL, vector databases (Chroma), Redis, email automation via SMTP, analytics and conversion tracking. Systems that run themselves.
Privacy-preserving engineering
Zero-knowledge proofs (Bulletproofs in WASM), pairwise identifiers, zero-PII storage, encrypted communication. Privacy is a design requirement, not an add-on.
Evidence over claims
Every build publishes the problem, baseline, stack, time, cost, result and failure modes.
No manufactured certainty
I test claims, including my own, and report limitations honestly.
Cost-disciplined engineering
I prove the workload cheaply on free tiers and local hardware first, and only scale infrastructure when the economics justify it.
Track what Scotland promises. Measure what it delivers.
I run an independent, evidence-led observatory for Scottish AI: national strategy delivery, adoption data and public-sector progress. All 10 commitments in Scotland's AI Strategy are tracked against observable evidence with sources and dates.
Implementing AI into your business, answered.
Straight answers on cost, scope, safety and ownership. No jargon, no manufactured certainty.
How much does it cost to implement AI into a business?
AI implementation in Scotland typically starts at £1,500 for an opportunity and automation audit, £5,000–£12,000 for workflow automation, and £7,500–£15,000 for an internal RAG knowledge system. Larger agentic systems and bespoke platforms run £12,000–£30,000+. Every engagement is fixed-scope and evidence-led.
What AI services are available for Scottish businesses?
AI services for Scottish business include opportunity and automation audits, workflow automation, internal knowledge systems (RAG), sales and CRM intelligence, agentic operations systems, AI governance reviews, and bespoke AI platform integration. All are delivered fixed-scope from Perth, Scotland.
How do I implement AI into my business?
Implementing AI into a business starts with an opportunity and automation audit: process review, data readiness, and a prioritised 90-day roadmap. Then a fixed-scope build — workflow automation, a knowledge system, or an agentic system — with human approval gates and audit trails where consequences matter.
Can AI run on my own hardware without vendor lock-in?
Yes. I build AI that runs on your own hardware using local LLM orchestration (Ollama), so you avoid vendor lock-in and recurring API costs. This is part of a cost-disciplined approach: prove the workload cheaply first, then scale infrastructure only when the economics justify it.
Is AI implementation safe and governed?
Yes. Every build includes appropriate human review and control where consequences matter: data access mapping, role and permission review, human approval points, agent tool authority, and audit/logging. AI systems are probabilistic, so governance is part of the design, not an add-on.