José Enrique Ibarra
AI Project Manager for regulated sectors
Hi, I’m José Enrique Ibarra, an AI Project Manager. My job is to turn the potential of generative models into results that hold up inside regulated organisations. When everyone is talking about AI, the interesting question isn’t what you can do — it’s what you should do, and under what guarantees.

From systems administration to managing AI
It all started in 1995, administering systems when we still talked about client-server and servers were rebooted by hand on a Sunday morning because there was no other way to do it. In those early years, before the internet had really reached Spain, I was installing 2,400-baud modems so that banking customers could check their accounts over Ibertex — and soon after we jumped to 14,400, which felt like science fiction at the time. Around then we were building the first Novell NetWare networks and the first serious Windows NT rollouts, when a domain was sketched on a whiteboard and PDCs and BDCs (primary and backup domain controllers) were corridor conversation.
I earned my MCSE (Microsoft Certified Solutions Expert) with a specialisation in IT Security — the high-level technical certification that validated experience across Microsoft server, cloud, productivity and data infrastructure. I spent years in the trenches: weekend migrations, storage arrays, the first serious firewalls, infrastructures where failure was not a negotiable option. That stage gave me something I’ve been grateful for every week since: understanding the foundations on which AI is built today. When someone talks to me about a data pipeline or a model in production, I don’t hear it as an abstract concept — I hear it as infrastructure, with its dependencies, its single points of failure and its on-call rotations. The full detail of qualifications and certifications is in credentials and training.
Thirty years, seven paradigms
Since then I’ve watched seven paradigm shifts go by: client-server, web, virtualisation, cloud, mobile, containers and now generative AI. I spent more than twenty years as Chief Technology Officer, and more than six leading senior IT projects in banking, where the cost of getting it wrong is measured in headlines and regulator sanctions. That taught me two things I carry into every project. First: technology alone never solves a problem — the organisation that adopts it does, or no one does. Second: the important question in front of any trend isn’t whether it’s new, but whether it solves something worth solving.
That’s why I moved from administration into management: the value was in bridging technical robustness and the language of the business. Today, from Almería, I’m equally at home discussing architecture with a data engineer and reviewing ROI, regulatory risk and deadlines with a board. That’s what an AI Project Manager really does when it works: translating in both directions, without losing rigour in either.
Track record in numbers
- 30+ years in technology, from 1995 to today.
- 20+ years as Chief Technology Officer in organisations of every size.
- 6+ years leading senior IT projects in the banking sector.
- MCSE (Microsoft Certified Solutions Expert) with a specialisation in IT Security.
- 7 technology paradigms lived through in production: client-server, web, virtualisation, cloud, mobile, containers and generative AI.
- 3 ways of working together available, with a preference for a permanent role on long-term challenges.
Based in Almería, working nationally and internationally for clients in regulated sectors.
My methodology: risk management and applied ethics
Leading AI projects demands a different approach from traditional software: uncertainty is inherent to probabilistic models. My methodology puts risk management first, not last. It’s not about deploying models, but about hardening them. I apply the principles I set out in my guide to risk management in GenAI IT projects. Security is non-negotiable. As I explain in my analysis of IT security in 2026, defence has to be proactive. Ethics, likewise, is not an add-on; it’s a functional requirement to ensure AI leaves a positive footprint on our Digital Society.
And one rule that comes before all the rest: nothing is executed without a prior service-by-service analysis — scope, dependencies, risks, business impact, availability requirements and rollback plan — signed off by every stakeholder involved in that service. It is what turns a deployment into a managed project. You can see how that works in practice in the nine programmes I have run in banking.
Tangible innovation: the AI Forge lab
I believe in experimentation as the engine of learning. Theory has to be validated in practice, and that’s why I run AI Forge, my personal lab where I test, break and rebuild automation tools and autonomous agents before proposing them to a client. That hands-on approach lets me anticipate trends — the ones I analyse each year in my series on IT project management. My added value is the ability to “land” innovation, moving from concept to real, scalable operation.
In AI Forge I also validate how new AI models fit into real workflows. Every experiment is documented and the lessons are published openly. It’s how I avoid proposals based on vendor marketing: the client who hires me gets tested technical judgement, not sales sheets.
What I bring: AI Project Manager and technology leadership
If your organisation needs to navigate the complexity of AI, my profile combines four capabilities.
Hybrid vision: the ability to align the technical goals of AI projects with commercial objectives and regulatory requirements (EU AI Act, DORA, NIS2)
Technical leadership: Effective oversight of engineering teams thanks to a deep technical background.
Governance and ethics: Implementing frameworks that ensure responsible, transparent AI, following standards such as those of the EU Artificial Intelligence Act.
Technology leadership (CIO or interim CIO): more than 20 years running the IT function reporting to the CEO or board. IT governance, technology strategy and departmental budget, vendor management and regulatory compliance. Available both as a permanent hire and on a temporary mandate when the organisation faces a regulatory or AI transformation and needs senior judgement at the highest level.
Thank you for your interest in my career. If you’re looking for leadership that combines technical boldness with strategic prudence, let’s connect.
Nine programmes delivered in banking
Migrating more than 300 servers without stopping the business. A container platform built from the initial idea and cost plan. Identity governance, privileged accounts, DLP, SIEM, Purview, firewalls across three vendors and XDR. All at financial institutions, and all run from start to finish.
Sectors I work in
I work in sectors where AI demands rigorous regulatory frameworks and where an operational error hits clients and critical accounts directly. Banking and financial services are my main ground: there I bring together operational resilience, data governance and AI models under the DORA regulation. Cybersecurity has been with me since my days as a systems administrator; today I apply it to threat detection, NIS2 compliance and third-party risk management.
I also work in other regulated sectors adopting AI under the EU AI Act: healthcare, energy, public administration and telecommunications. In all of them I keep the same method: first, prioritise use cases with clear business value; second, ensure model traceability; third, design auditable systems from day one. That combination defines the work of an AI Project Manager with a hybrid profile.
How we work together on your IT project
When you get in touch, it all starts with a short conversation. The goal isn’t to close anything on that first call: I want to understand the real problem, the timelines and the regulatory context. Many initiatives fail by choosing the technical solution too soon, so it’s worth checking first whether the use case actually needs AI. Sometimes a well-designed classic automation is enough.
From there, the work is structured into short, verifiable blocks: we define the use case, assess risks and build a controlled proof of concept. Then come iterative deployment and the governance plan. Each block has measurable deliverables and a clear decision point. Typical services are DORA programme management, NIS2 advisory and AI agents in regulated environments; I also mentor PMO teams adopting generative AI.
If your project is a fit, write to me with a couple of lines describing the challenge. You’ll get a personal reply, not an automated form. Working with me means close collaboration and direct communication, and full transparency about what AI delivers today and what’s worth waiting for.
What people ask me most
What people ask me most
What kind of clients do you work with?
Mainly with mid-sized and large organisations in regulated sectors — banking, insurance, healthcare, industry with regulatory demands — where AI has to coexist with frameworks like the EU AI Act, NIS2 and DORA. Also with startups that already have traction and want to scale without mortgaging themselves technically.
What does the first contact look like?
A 30-minute call, no strings attached. You tell me the challenge, I tell you whether I can help and how. If it’s not for me, I’ll say so and point you towards someone who can. A reply never takes more than 48 hours.
What engagement models do you offer?
Three, in this order of preference. Permanent role (open-ended employment) if your organisation wants a stable senior profile and a long-term commitment: this is where I add the most value, because understanding a company’s context isn’t done in three months. AI Project Manager or interim CIO (leadership on a temporary mandate) for a specific stage — an AI project with a clear end point, or a period of technology leadership with a defined mandate (regulatory transformation, AI integration, CIO handover). Monthly retainer if you need ongoing judgement without hiring full-time.
How long does it take to get a project started?
From the first call to kick-off, usually between one and three weeks, depending on the engagement model and your internal calendar. Interim and retainer tend to be faster; a permanent role depends on your hiring process, where I’m available for meetings with HR, the board or whoever is needed.
Do you only work with clients in Spain?
Based in Almería, but I work with clients across Spain and remotely with international organisations. European regulation (EU AI Act, NIS2, DORA) applies in every member state, so jurisdiction is rarely a problem.
How do terms and budget fit together?
It depends on the engagement model. For a permanent role, we discuss it with your HR department like any other senior hire — salary band, terms, career path. For interim and retainer, the budget is scoped to the project. The first call lets both of us talk it through openly and not waste anyone’s time.
About this blog: editorial approach
About this blog: editorial approach
This blog publishes practical analysis on applied AI, cybersecurity y project management in regulated sectors. I write in the first person, with judgement and from real field experience, not from a summary of papers.
Publishing cadence: two new posts a week (Tuesday and Thursday) and a full review of the pillar posts each quarter to keep regulatory references current (EU AI Act, NIS2, DORA, GDPR).
Topics:
- AI Project Management — project governance with autonomous AI agents, LLM integration into enterprise data pipelines.
- Regulated cybersecurity — NIS2 and DORA compliance, risk management and modern defensive architectures.
- Technology leadership — the PM’s role in the age of AI, applied ethics and digital transformation done with judgement.
Every article is signed with visible authorship, a publication date and a last-reviewed date. If you spot an error or want to add professional perspective, write to me and we’ll include it.