AI is uncharted water. I’ve already sailed it.
Most consultants advising on AI have read about it. I’ve built with it — hands-on, every frontier lab’s models since late 2025, and an entire one-man software factory: 4,751 commits in its first five months. Combine that with 18 years leading complex IT programmes, and you get something rare: a senior programme leader who actually knows what AI does under pressure — because I’ve been burned by it, built the rails for it, and shipped with it. I don’t sell you a deck. I navigate you through. Available now.
Your navigator through the AI transition.
Every organisation is sailing into AI right now — most without anyone on board who has actually done it. That’s the role I take: the senior programme leader who leads your AI initiative from idea to working delivery — realistic scoping, the right guardrails, honest calls on what agents can and can’t do, and the delivery discipline of 18 years in regulated environments. Interim or freelance, via broker or direct. Written, verifiable references on the site; personal referees at offer stage. (Need something built rather than navigated? That’s my factory: BygMedAI.)
Broker or agency? Everything you need → AI governance services →The situations I’m called into.
The status report says amber. Everyone knows it’s red.
The SteerCo meets monthly to watch it get worse, the vendors point at each other, and the board is starting to ask whose name is on it.
The compliance date is already behind you.
NIS2 or DORA is in force, the controls exist on paper, and no one actually owns making them operate before the regulator asks for evidence.
The migration froze two quarters ago.
Validated systems no one dares touch, QA and IT talking past each other, and a go-live date that keeps moving to the right.
I don’t hand you a slide deck. I show you exactly how I’d take each of these apart — the method, the tools, and the political reality nobody writes down.
Not sure if yours is actually red? Seven honest questions — no email, runs in your browser.
Show, don’t tell. Pick your situation.
Four scenarios drawn from 18 years in regulated delivery — and from the Danish programmes everyone remembers. No confidential client detail; the pattern is the point. Each one walks through how I’d approach it.
The red programme you just inherited
Multiple vendors, an SKI framework that locks you in, a nervous board, and a governance structure that stopped working months ago. The first 90 days, step by step.
Walk the first 90 days →The stalled GxP datacenter migration
Production can’t go down, validated systems are frozen, and QA holds a veto everyone respects and no one enjoys. It’s validation debt, not servers.
See the approach →The NIS2 deadline you’re already past
In force since 1 July 2025. Controls on paper, ownership nowhere — and a Danish transposition that left out personal liability, so no one’s neck is on the line.
See the approach →The carve-out separating two entities
A fixed business date, 1,500+ interdependent decisions, and a parent company with no incentive to help you leave. Day 1 readiness, ruthlessly defined.
See the approach →Denmark has a whole shelf of Rigsrevisionen reports on programmes that failed. They almost never fail on technology. They fail because decision rights are unclear, accountability is diluted — and because, by the time it’s red, the real question in the room is whose name is on it.
The org chart tells you who’s accountable. The corridor conversations tell you who actually decides. I read both — and I rebuild governance that’s connected to delivery instead of performing it. That is the difference between a recovery plan and a recovery.
Where governance meets delivery.
Programme turnaround
Taking over red, stalled or politically stuck programmes — re-establishing decision rights, resetting vendor governance and recovering the timeline.
Transition & migration
Datacenter, mainframe and cloud transitions in production-critical, regulated environments — including GxP-validated pharma estates (MES, SCADA, PAS-X).
Regulatory delivery
NIS2, DORA, ISO 27001 and GxP made operational — turning controls-on-paper into evidence a supervisory authority will accept.
Carve-out & separation
IT separation and TSA exit across multiple entities, workstreams and geographies — Day 1 readiness planned as a governed backlog, not discovered late.
Pharma & life science · Financial infrastructure · Telecom · Public sector & healthcare · Critical infrastructure
The regimes I operate across.
Regulated delivery means the compliance regime is the constraint. Pick one to see what it governs, which sectors it hits, and what I do with it. — or see every key date in the deadline tracker.
NIS2
Cybersecurity risk-management measures and incident reporting for Essential and Important Entities — in force in Denmark since 1 July 2025, with penalties up to €10M or 2% of global turnover.
Turn the directive into an operating programme with named owners and evidence a supervisor accepts — not a binder of policies nobody runs.
DORA
ICT risk management, third-party oversight, incident reporting and resilience testing for financial entities — applicable across the EU since 17 January 2025.
Stand up ICT-risk governance and third-party oversight that hold up under a resilience test — stacked cleanly on top of NIS2 where both apply.
GxP / EU GMP
Computerised-system validation and data integrity (ALCOA+) in regulated manufacturing — governed by EU GMP Annex 11, GAMP 5 and 21 CFR Part 11.
Run migrations and transitions that keep validated systems (MES, SCADA, PAS-X) audit-ready — migration and validation evidence landing together.
PCI-DSS
Security controls protecting cardholder data across people, process and technology — assessed on a recurring recertification cycle.
Bring card-data environments through recertification without stalling delivery — governance and scope kept tight around the CDE.
ISO 27001
A risk-based information-security management system (ISMS) — the control backbone that most of the regimes above lean on.
Use it as the shared control backbone under NIS2 and DORA programmes — so evidence is produced once and reused, not rebuilt per regime.
What the people I’ve delivered for say.
“Steven joined when things were not moving in the right direction. In a very short time of six weeks he was able to bring the project on track.”
Abhaprakash Praharaj, PMPProject Manager, Tata Consultancy Services
“His experience in programme governance, planning, risk and dependency management was invaluable… detailed reporting brought together in a stakeholder-friendly way.”
Alan ToddGlobal Programme Director (managed Steven directly)
Got a programme that’s gone quiet at the top?
If it’s red, stalled, or a compliance date has already slipped, I can help. Interim or freelance, via broker or direct. References from previous clients available on request.
Available now — AI navigation and regulated programmes across Denmark and the Nordics.