How Do Banks Make AI Deployments Reversible and Auditable?
Decision ledger, policy-at-intent, stress-exit, human gate design and progressive delivery: the mechanisms that give a bank evidence and a way back.
Read guideENGAGE · TEAM

Rohit is Bugni Labs' Principal for AI Native Infrastructure and Operations, the substrate systems actually run on. He operates as both architect and hands-on engineer: designing GCP-native infrastructure that is event-driven, DevSecOps-hardened, and observable from first commit, and building it with the CI/CD, infrastructure-as-code, and SRE discipline production demands, now extending that same rigour into agentic AI automation built with Python and the Anthropic SDK. 16+ years of engineering, including multi-year delivery at a UK Tier-1 banking group across Cloud CoE, PSD2 and Open Banking Lab, and commercial-onboarding platforms, plus SRE leadership in global platform operations at scale.
How regulated systems get shipped and kept running. The recurring threads are GitOps change control, re-engineering CI/CD, observability treated as a compliance instrument rather than a dashboard, and what DORA and SPACE really measure. Several pieces cover putting AI inside a regulated delivery pipeline without loosening control.
9 pieces · 1 Perspective · 5 Field Notes · 3 Guides
Decision ledger, policy-at-intent, stress-exit, human gate design and progressive delivery: the mechanisms that give a bank evidence and a way back.
Read guideHow to govern infrastructure as code when AI agents generate and apply changes: intent gates, version-controlled policy and continuous audit evidence.
Read guideA mid-market UK wealth manager wanted an assistant to triage its shared operations inbox, not a model it had to trust with judgement calls. The build that stuck
Read field noteAI code review became useful only after we made it policy-aware, evidence-led, and subordinate to human ownership.
Read field noteObservability as a compliance tool: how SRE in regulated financial services satisfies DORA, supports audit, and shortens incident reconstruction. Plus FAQ.
Read guideDeveloper productivity has become a polite name for the metric a CIO is allowed to ask about. DORA and SPACE are useful, but only after the harder conversation has been had: whether the work the team is measuring is the right work, and whether the velocity it is chasing buys back the audit cost it generates.
Read perspectiveGitOps can satisfy regulated change control when every environment change is reviewed, replayable, policy-checked, and reversible.
Read field noteDiscover how a major UK bank's screening platform leveraged AI governance in financial services to reduce commercial customer onboarding from 10 days to under 12 hours, with vendor-agnostic architecture and zero unplanned incidents.
Read field noteRe-engineering CI/CD for a regulated UK bank's 25+ microservice platform: parallel deploys, immutable artefacts, Helm, GitOps, fix-forward branching.
Read field note