Blog · AI, cybersecurity and IT projects
An AI Project Manager’s blog: technology, regulation and IT projects
This AI Project Manager’s blog brings together reflections and practical cases on IT project management, cybersecurity, artificial intelligence and systems architecture, from the intersection of technology, regulation and business.
You’ll find analysis of regulations such as NIS2, DORA and the EU AI Act, real use cases applied to banking and regulated sectors, and reflections on how artificial intelligence is transforming project management and systems administration.
AI Project Manager blog categories
Latest posts from the AI Project Manager blog
-

Guardrails for generative AI: safety barriers in production
Guardrails for generative AI: what they are, input, output and action types, defence against prompt injection, common mistakes and how to validate…
-

Conformity assessment for high-risk AI systems
Conformity assessment for high-risk AI systems: what it is, the requirements assessed, internal vs notified-body routes and how to prepare from the…
-

Zero Trust in banking: practical architecture for regulated environments
How to apply a Zero Trust architecture in banking step by step and why the never trust, always verify model fits with…
-

Context engineering: the successor to prompt engineering in AI projects
What context engineering is, why it surpasses prompt engineering and how to design the context a model receives to gain reliability and…
-

ISO 22301 and business continuity: from the plan to the real drill
What ISO 22301 is, how to move from the business continuity plan to the real drill and how it relates to DORA…
-

Certifications for AI Project Managers in 2026: which ones are worth it
A guide to the certifications that genuinely help an AI Project Manager in 2026, what they cover and how to combine them…
-

Non-human identities: governing AI agents’ access
What non-human identities are, why AI agents drive up their number and how to govern their access to reduce security risk.
-

GPAI obligations under the EU AI Act: what changes in August 2026
A review of the EU AI Act obligations that come into force in August 2026, who they affect and what to do…
-

72-hour incident notification: GDPR, NIS2 and DORA compared
A comparison of the incident notification deadlines in GDPR, NIS2 and DORA and how to set up a single response process that…
-

KPIs and ROI of GenAI projects: how to measure what really matters
How to measure the ROI of GenAI projects with realistic KPIs, which hidden costs to consider and why time saving is not…
-

Prompt injection in the enterprise: risks and defences in GenAI projects
What prompt injection is, how it affects generative AI applications in the enterprise and what layered defences to apply to mitigate the…
-

ISO 42001: how to implement an AI management system in the enterprise
What ISO 42001 is, how to implement an AI management system step by step and how it relates to the EU AI…
Where to start reading this blog
If you’re here for the first time, these are the starting points to understand how I work as an AI Project Manager and how I see the intersection of technology and regulation.
- About me — who I am, my background and how I work.
- AI Forge — artificial intelligence applied to real work.
- Cybersecurity — NIS2, DORA, ENS and a strategic approach.
- IT project management — programme management in regulated environments.
- Systems management — infrastructure, cloud and technical architecture.
Sources and regulatory references
To go deeper into the regulations mentioned in this blog, consult the official sources: DORA Regulation (EU) 2022/2554, NIS2 Directive and the EU AI Act.
If you’d like to discuss any of these topics, head to the contact page.