Chaminda Delpagodage
Fintech CISO and AI Adoption Lead. Ex-PayPal.

Get AI approved by security. Then get it used.

AI rollouts in regulated companies stall in two places: the security review, and the people expected to use it. I work both, with 20 years in security and production systems behind it.

I still build software, too. See the builds.

20 years
Security and production systems
Ex-PayPal
Cloud infrastructure at scale
Today
Leading AI adoption in a regulated fintech
Fractional AI advisory

Workforce AI rollout for regulated companies.

The CEO says go. Compliance says no. Employees use AI anyway.

Stalled in review

Pilots sit in security review for months. There is no policy an auditor would accept.

Shadow AI

Staff paste customer data into tools nobody approved.

Approved, then ignored

Licenses get bought. Then most people quietly stop using them.

No proof it works

Nobody can tell the board who uses it, what it saved, or why people quit.

The method
01

Govern

Count the AI already in use. Then write the policy, the approved tool list and the data rules from what people actually do.

02

Enable

Put approved tools in the hands of one or two pilot teams in operations, finance, support or compliance. Training, a champion in each team, weekly office hours.

03

Measure

Track who uses it, what it saves and why people stop. Turn that into a report the board can read.

How to start
Regulated companies, about 50 to 500 people.

Start with an AI Readiness Review.

Two weeks, fixed scope. An inventory of the AI in use, a risk review, a gap list, a draft policy and a 90-day plan. If nothing is worth doing, I will say so.

Next steps are a 90-day pilot rollout and ongoing advisory.

What I don't touch: your product AI and engineering roadmap. Those stay with your CTO.

I'm usually the person who says no. That's why I can get you to yes.

Who it's for: Fintech, payments, healthcare-adjacent and insurance companies with PCI, HIPAA or SOC 2 in scope. Usually sponsored by the CEO or COO.

Builds

I still build.

Security and AI by day. Software at 5am. Each build started as a real problem.

iPhone, free beta

Steady

An intermittent fasting coach. It learns the hour a fast gets hard for you and checks in just before it. No account. Your data stays on your phone.

Chrome extension

ReplyWisely

Finds the posts on X worth replying to, drafts replies in your voice, and shows which replies actually worked.

Founders

IkigaiNiche

Discover aligned business opportunities at the intersection of your strengths, interests, and real market demand.

View product
Fintech founders

FinSec Scorecard

A diagnostic for small fintech companies assessing PCI DSS and SOC 2 readiness of their AWS infrastructure.

View product
Founders & builders

DomainNameNow

Find a brand-ready, actually-available domain name in minutes. Built for founders and indie builders who refuse to let naming delay a launch.

View product

Killed products and free builder tools

The pattern

Start bad. Stay. Transform. Repeat.

Every real change in my life followed the same shape: uncomfortable at the start, boring in the middle, a different person at the end. Building in public at 43 is just the latest rep.

Origin

How 20 years becomes a starting line.

The story isn't about escaping a career. It's about pointing everything I built toward my own ideas.

The Setup

Two full-time commitments. One person.

Day

Fintech CISO and AI Adoption Lead.

Security, compliance and AI adoption decisions that have real consequences if they go wrong.

Build

Software at 5am.

Mornings at 5am, weekends in the margins.

"I don't want freedom from responsibility. I want a life large enough to hold both."
Chaminda Delpagodage

Two ways in.

Read the newsletter, or book a call about your rollout.