Notes from AWS Practice.
Deep-dives from ongoing AWS projects — no vendor slides, no hype cycles. What works, what it costs, what I wouldn't do again.
Two Systems, One Sales Motion: An AWS Partner Agent on Amazon AgentCore Harness
Part 1 of the series "Building a Partner Sales Agent on Amazon Bedrock AgentCore", built around one real project: a conversational agent that connects HubSpot CRM and AWS Partner Central for an AWS Partner's sales team.
AWS Certification: How to Get 30 Extra Minutes on Your Exam (DaZ +30)
AWS doesn't offer its certification exams in German, so native German speakers have to test in English. With \"DaZ +30\" you can request a one-time 30-minute extension to make up for that. Here's how to set it up.
AWS European Sovereign Cloud: What Six Months and One Live Test Actually Show
A reality check from a live account: what the sovereign AWS cloud can do today, where it hits its limits, and what that means for CIOs and CISOs in the DACH market.
Shadow Code: The Security Risks German Companies Are Buying Unnoticed in 2026
We knew shadow IT. Now comes shadow code: production code that AI agents write past IT, security, and compliance. 79 percent of organisations have no overview of the agents running in their environment. Four risks that get bought along unnoticed, and an audit in three steps.
From Pilot to Production: Why Most AI Projects Get Stuck, and What the Exceptions Do Differently
Around 95 percent of enterprise GenAI pilots show no measurable impact. Why the step from pilot to production is the hardest one of all — and what the few exceptions do differently. From my own experience building a product with AI agents over five months.
Set the AWS Security Agent Loose on Our Production Site. Here is What 10 Hours Got Us.
A field report from one of AWS’ newest AI-driven security services - from setup to findings to verdict.
When Agents Pay: AWS AgentCore Payments and the Next Identity Problem
AWS launched Amazon Bedrock AgentCore Payments with Coinbase and Stripe. This is not just a feature update. It is the moment agents move from planners to actors with financial impact. What that means for architects and CISOs.
Shadow Agents: The New Blind Spot for CISOs
67 percent of security leaders do not know which AI models and agents are running in their organisation. That is the core finding of the Pentera 2026 Report. And while Gartner projects that 40 percent of all enterprise apps will have AI agents built in by end of 2026, both curves are moving in the wrong direction.
Brownfield Cloud: Why Remediation Matters More Than Innovation
Greenfield cloud projects are the exception in 2026. The rest of us live in brownfield. And very few have a strategy for it. Three patterns I see repeatedly in AWS assessments - and why the next major discipline in cloud work is not innovation, but remediation.
What a Cloud Security Architect Actually Does All Day
When people hear Cloud Security Architect, most imagine someone who writes firewall rules all day. In practice, the majority of the work is something entirely different. An honest description of the job, for everyone who looks at it from the outside.
Agentic AI Governance Gap: Why 79 Percent Deploy But Only 21 Percent Are Ready
79 percent of organisations are deploying or testing Agentic AI. Only 21 percent have a mature governance model for it. That is not a surprise - it is the consequence of governance always lagging behind technology. Three core questions every CISO team needs to answer now.
BSI C5:2026: What Cloud Users Need to Know Now
The BSI has published C5:2026. 168 criteria instead of 121, new mandatory areas, machine-readable for the first time. Anyone who considered C5:2025-readiness sufficient is starting over. Here is what changes and what organisations need to do now.
Your AI-Generated Tests Are Lying to You
393 test files, all green. Then a colleague sat down with me. What he showed was systematic: AI-generated tests fail in predictable patterns. The seven anti-patterns I documented in my codebase - and how a Kiro Skill fixes them.
Kiro vs. Vibe Coding: Why Spec-Driven Development Is the Key to Sustainable Enterprise Code
Vibe coding may work for prototypes. For enterprise code with security requirements, it is an architectural dead end. How AWS Kiro charts a radically different path with spec-driven development - and what 175,000 lines of code in 19 days says about that path.