2026-06-22
Building a research career in public
The short version: I spent seven years across research and industry, four of them doing research and three shipping machine learning in production. Now I'm moving into AI safety full-time. I'm early in the field, and instead of waiting until I have the credentials to look the part, I'm going to build in public and share the research, the reading, and the open questions as I go.
Where I'm coming from
I did a PhD, led research projects, and published a stack of papers, all in information systems rather than machine learning. Then I spent three years as a hands-on ML engineer and engineering lead, taking models from a notebook all the way to production: fine-tuning, multimodal pipelines, inference optimization, MLOps. That's the work that decides whether a model actually holds up for real users at scale.
Somewhere in those three years the question that mattered to me changed. It stopped being can we ship this and became what happens when systems like this are everywhere, and the safety properties we tested in the lab don't survive contact with the real world. That question is why I'm making this move.
The bet
What I'm betting on is straightforward: safety has to survive deployment, and deployment is the part I know. I spent years keeping machine-learning systems running in production, and I've seen which safety properties hold up once a model leaves the lab and which ones fall apart. There's research training underneath that too: a PhD, plus a year of deliberate upskilling through ARENA, the AI Alignment Research Fellowship, and BlueDot.
The idea I keep coming back to is this. A safety property you can only demonstrate in the lab isn't yet a property of the deployed system. Measuring that gap, and building the tooling to measure it, is the work I most want to do.
What I'm working on
Two threads, one underlying concern.
Open-weight and post-deployment safety. Safety is a property of a deployment, not of a checkpoint. A lab can sign off on the weights it releases; it cannot sign off on the fine-tune, the quantization, or the agent scaffold someone wraps around those weights a week later. Once weights are open, a safety property either survives everything the world does to it, or it doesn't hold at all. I want to build the measurement tooling for that gap.
Compositional misalignment. Alignment is tested on single models; the world deploys compositions: multi-agent orchestrations, tool chains, memory-augmented agents. Alignment does not compose linearly. My HCII 2026 paper documents this empirically for multi-agent LLM systems, and it's the thread I most want to pull on next.
In practice, right now that means: an inoculation-against-model-poisoning project with Safe AI Germany, a mechanistic investigation into why inverse scaling happens, and a steady diet of paper notes and replications.
Why in public
Two reasons.
First, accountability. Writing something down for other people to read forces a level of rigor that private notes never do. Second, the field rewards it. The people I respect in AI safety mostly earned their standing by working in the open: reproducible notebooks, honest write-ups, thinking out loud. That's the norm I want to follow.
So this site is a workshop. Some of what I publish will be wrong, and I'd rather find that out fast. If you're working on any of this, or hiring for it, or funding it, I'd genuinely like to hear from you.
Thoughts or pushback? Email me.