01 About
I have spent three decades inside the systems I now write about
IBM, then the University of Plymouth, then an organisation delivering programmes in some of the most difficult settings there are for keeping people and data secure.
That route shapes how I work. I start from what an auditor, a regulator or an attacker would test, not from what a supplier's brochure promises.
02 Work
Five problems take up most of my working week
- Supplier dependence and exit plansWho controls your data, under whose law, and what leaving would take→
- AI governance and assuranceDecision logs, model risk and evidence a board can rely on→
- Certification that survives the auditISO 27001 and Cyber Essentials Plus, run as working controls→
- Data protection in practiceThe Data Protection Officer's desk: DPIAs, rights requests and processors→
- Security where the ground is unstableStaff, devices and data in fragile and conflict-affected settings→
03 Papers
Two papers make the case in full
AltLibre Papers · No. 1
Your AI Answers to a Foreign Government
What two governments have already done with the power that AI dependency gives them, what European law does and does not change, and what Europe has built to answer it.
AltLibre Papers · No. 2
A UK Digital Sovereignty Act
A proposal for the statute beneath Britain's data laws: ending silent dependence on foreign-controlled digital infrastructure.
04 Contact
You can write to me directly
I read everything that arrives, and I reply to anything that is not selling me something. LinkedIn works too, if you would rather start there.
adrian at altlibre dot com