Delfen.ai
The Practitioner's Playbook
AI-era technology decisions, worked through to a verdict. Named tools. Real failure modes. No abstraction.
Who owns AI governance? The team already running your security
A regulator's own enforcement order named a data breach and an AI-governance failure in the same document — because they were the same failure. Most organizations still staff, budget, and report on AI governance and security governance as if they were unrelated.
Technical debt belongs in the purchase price, not the appendix
TSB's board decided how to hit Sabadell's promised £160 million in IT synergies: build the new platform through Sabadell's own delivery arm, never formally checked and never reassessed for two-plus years. The migration failed, and cost £330 million.
The approved module library — the runway your AI actually runs on
The policy gate from part three will pass a clean S3 module every time an AI assistant writes one — however many times the same pattern gets reinvented from scratch. The gate catches wrong. It doesn't catch waste. That's a different problem, and it isn't solved with another check.
NIS2 liability doesn't stay with the seller — it transfers at closing
On 15 August the Dutch Cyberbeveiligingswet takes effect — no grace period, board members personally in scope, and the supervisor's own guidance names a merger as an event that starts a two-week regulatory clock. If you buy a company in one of its 18 sectors, you buy its compliance state.
Shadow AI: why bans fail and what a real policy looks like
A Dutch municipality's staff uploaded over 1,000 documents to public chatbots in one month, children's BSN numbers among them — the city asked OpenAI to delete the data and never got confirmation it happened. Nobody involved was malicious; they were getting work done.
AI due diligence: every acquisition is now an AI acquisition
IBM assembled Watson Health for at least $3.6 billion in disclosed acquisitions; six years later the data assets went out the door for $1.1 billion. Every target now contains AI — in the product, the tooling, or the vendor stack — and standard due diligence asks zero questions about it.
Digital sovereignty is a mapping problem, not a vendor problem
Five Dutch regulators just told organizations to build real freedom to switch IT vendors. One of the five already measured how far off that is — and found that a compliance policy on paper and a contract that actually enforces it are not the same thing.
The policy-as-code gate — where infrastructure safety actually lives
Article 2 said Category 2 configurations need non-negotiable validation. But 'you should run Checkov' is advice, and advice does not survive contact with AI generation speed. Validation only protects you when it is a gate that cannot be skipped. Here is how to build one — and the five ways teams build one that doesn't hold.
OT due diligence: the blind spot in manufacturing M&A deals
Ransomware froze the target's plants in four countries while the deal waited for regulatory clearance — and the SEC filing that followed literally defines the term 'Cyberattack Amendments.' Here's the layer technical due diligence keeps missing, and the five questions that find it.
AI Governance: What It Actually Is (and How It Really Works)
A Meta AI-safety director typed 'stop' to her own agent — it kept deleting emails anyway. That's what 'AI governance' actually has to mean, and why the AI Act's phase-in makes it non-optional.
ChatGPT vs Claude vs Gemini vs Copilot: A Scored Comparison for Regulated and OT Teams
Every 'ChatGPT vs Claude vs Gemini' comparison scores pricing and features. None of them ask whether the tool can run air-gapped, who's really behind the model, or what happens when the vendor is a foreign state's regulatory target. Here's the version that does.
How AI Changes the Enterprise Architect Role
AI already queries your dependency graph and drafts your Terraform. The real question was never whether it replaces you — it's which half of the job just changed, and which half didn't move at all.
What to let AI automate — and the two questions that draw the line
AI can generate any infrastructure configuration you ask for. The question isn't whether it can — it's which tasks belong to the machine and which ones require a human gate. A five-category map and two decision questions for enterprise architects.
How to Evaluate a New AI Tool Before It Enters Your Stack
Your engineers are already using it. The real question was never whether the tool is good — it's what it touches, and whether you can defend letting it in. A six-question framework to decide with your eyes open.
The 10x enterprise architect isn't the one who prompts fastest
AI generates infrastructure configurations in seconds. The architect's job isn't to prompt faster — it's to lead what the machine produces. And those two things are not the same.