Ugur Tuna · Cambridge, UK

I build AI systems, and the controls that make them safe to use.

AI technology and governance lead in the UK public sector. Hands-on engineer with a background in clinical genomics data at national scale.

In brief

Now
AI and digital transformation lead in the UK public sector. I lead an organisation-wide AI and automation programme: the governance and assurance that let people use AI with confidence, workflow pilots built hands-on with technical colleagues, and the skills staff need to use AI well.
Before
At the University of Cambridge, working on the NIHR BioResource, I ran end-to-end genomic data provisioning for one of the UK’s largest national research cohorts: HLA imputation across 50,000+ samples, recall-by-genotype studies, secure data releases and GDPR subject access requests.
The thread
I have built data systems where one wrong row reaches a patient study, and I now work where AI meets public accountability. In both, I care about the same thing: evidence you can check.

Building in the open

Three connected projects, one question: how do you get real value from AI without losing control of it?

  1. Act safely

    How do you let an AI agent act without it sending the wrong thing, twice, to the wrong people?

    agent-guardrails Python · SQLite · hash-chained audit log · Claude tool use

  2. Measure quality

    Does an AI summary of the evidence say what the sources say? What did it miss, and what did checking it cost?

    evidence-synthesis-eval Python · Inspect · model-graded and deterministic scorers

  3. Assure and decide

    How can a team do proportionate AI assurance in an afternoon rather than a quarter?

    ai-assurance-kit Python · Pydantic · JSON Schema · Jinja2

All projects, including clinical genomics and applied machine learning

How I work

  • Usage is not quality.

    Adoption figures show who clicked, not whether the output was right.

  • A second model is a critic, not a verifier.

    Models share blind spots, so their agreement is not evidence.

  • Permission to build is not permission to deploy.

    Connecting data, sharing a tool and letting it act are separate decisions.

  • Fix the data before adding an agent.

    Often a better template or ordinary automation is the right answer.

  • Count all the effort.

    Checking and correction time are part of the cost of AI.

  • Show what is uncertain.

    Say what has not been verified, every time.

Track record

At the University of Cambridge (NIHR BioResource):

  • Processed 50,000+ samples across HLA imputation batches, with automated strand-conflict resolution
  • Delivered genomic cohorts of 10,000+ samples with cryptographic verification
  • Ran secure cloud transfers of hundreds of gigabytes into trusted research environments
  • Harmonised clinical data from several NHS Trust formats into the OMOP common data model
  • Led a team of 6 junior data scientists in genomic data processing and secure data handling
  • Enabled research across 10+ disease areas, including rare diseases, IBD, neurodegeneration and immunology
  • Handled GDPR subject access requests that returned clinical genomic data for patient care decisions

Writing

Short, practical essays on using AI well.

All writing

Contact

GitHub
github.com/dsugurtuna
Website
ugurtuna.com