Jose Lopez with his dog

Jose Lopez

Head of AI · Secure AI systems at scale

I build AI systems that survive contact with production. I care about the part after the demo.

About

I live on the Spanish coast and work from there. The commute is excellent.

I have been building software for more than 25 years. Over that time, I have worked on many different kinds of systems, including combat systems for one of the Spanish Navy’s most advanced frigates, distributed graph engines, production ML systems, and AI agents. I now lead AI at bunny.net.

I would rather ship a boring system that stays up than a clever one that needs me awake.

What I do

I work on the part of AI that comes after the demo: the gateways, guardrails, agents and platform work needed to make it useful, secure and reliable.

I have built systems at very different kinds of scale: high-volume AI traffic, enterprise threat modeling, hundreds of millions of daily inferences, and graphs with billions of nodes.

Being Head of AI has never meant only building the technology. I help CEOs, CTOs, VPs of Engineering and boards decide where AI is useful, where it is dangerous and what the company should do next. I have also handled the technical side of acquisition due diligence, looking past the deck to see whether the product, architecture and team are actually what they claim to be.

Experience

These were not demos. Everything below shipped, often at a scale where mistakes got expensive.

Head of AI · bunny.net

I set the product AI direction and built an AI Gateway and LLM Firewall for high-volume production traffic across bunny.net’s global network. It detects prompt injection, redacts PII, and checks standard and streaming requests, BYOK setups, and model traffic generated by Codex and Claude Code.

Head of AI · IriusRisk

I built the AI team and platform from scratch and started orchestrating agents in production. We shipped Jeff for guided threat modeling, Bex for risk triage in Jira, and a secure-by-design simulator in which a team of agents attacks real system models and writes the security reports.

I also helped set the company’s AI strategy: how AI would change cyber attacks, what new products it enabled, and where to place our bets.

Head of AI · DTEK.ai

I helped define what computer vision and generative AI could actually do for retail. I handled technical acquisition due diligence, looking at the product, architecture and team behind the pitch. I also built a multimodal retail assistant using vision-language models to automate checkout and in-store flows.

Principal ML Engineer · Mimecast

Three systems, all at uncomfortable scale: an event platform on Spark and Cassandra processing petabytes of data; a content-safety model detecting nudity and violence; and a brand detector recognising more than 300 brands in email images. The two vision systems ran more than 250 million inferences per day.

Lead ML / Big Data Architect · Zed Worldwide

I built a distributed graph engine that processed billions of graph nodes with Spark and MapReduce. I also built Social Baton, a marketing ML system that coordinated global campaigns which reached Twitter’s trending topics several times.

CEO · ELIMCO Sistemas

I led more than 150 people across defence and critical-infrastructure programmes and delivered the AEGIS combat-system integration with Lockheed Martin for Spain’s F-105 frigate.

Founder & CEO · MightyGate

I founded a mobile software company, shipped more than 12 apps, reached 850,000 downloads, and sold it.

Software Architecture & Project Management · Novasoft, Optimi, ICDOS

Ten years building software for government, telecom and industrial systems, from Java/J2EE applications to mobile-network optimisation research using genetic algorithms.

Open-source projects

Threat-modeling toolkit GitHub · open project

Threat modeling for Claude Code that speaks STRIDE and PASTA, maps compliance and checks the security work actually happened.

Workspace for agents GitHub · open project

A harness for teams of AI agents, with isolated workspaces, scheduled loops, memory and receipts. I use it every day for development and for my own agents.

Claude ThreatModel GitHub · open project

Threat modeling that runs while you code, with zero extra workflow.

Secure Agent Tutorial GitHub · open project

A hands-on guide to building agents you can trust with something real.

Writing

I publish on Disrupted AI, my Substack on secure, auditable enterprise AI and threat modeling for agents. These are three of its most-read posts.

Media appearances