Helping organisations navigate safety, security and regulatory risk
I advise businesses on digital regulation, safety and security, helping them navigate UK and European regulatory frameworks, particularly where products, platforms and AI systems face novel challenges. I split my time between London and Brussels.
My practice focuses on platform regulation, online safety, and AI safety. I advise on the Online Safety Act, the Digital Services Act, the EU AI Act, and related digital regulatory regimes. I also advise on cybersecurity, including NIS2 and the Cyber Resilience Act, and support with multi-jurisdictional incident response.
My work often involves situations where there is no clear rulebook: when clients are preparing to launch a product and need to understand the risks before it ships, or when something has gone wrong and the clock is running, whether it is scrutiny from the European Commission, Ofcom, the ICO or another public enforcement body, or private enforcement.
I wrote some of the earliest systemic risk assessments for VLOPs, advised GPAI model providers on implementation of the EU AI Act, and defended statistical techniques that regulators doubted.
Alongside my legal practice, I am CISM certified, and a member of the Chartered Institute of Information Security and the Royal Statistical Society. I also have an MSc in neuroscience, for which I spent too many hours in RStudio, VS Code and SPSS.