AI Act Check
Every AI system inventoried, classified and dated, with the obligations that follow.
- Duration
- 3–4 weeks
- Price
- €6,000 to €12,000
- excl. VAT, indicative
AI & Cybersecurity
Deploy AI you can defend, and defend with AI.
Legal

Services
Deploy AI you can defend, and defend with AI.
Two things are usually true at the same time. Your teams are already using generative AI, often through tools nobody approved. And the projects that have been formally proposed are stuck, because nobody can say whether they are safe or allowed.
This practice resolves both. We inventory what is actually in use, put governance in place that is light enough not to become the reason nothing ships, and build: a scoped pilot on your data, evaluated against a measured baseline, with access control and logging from the first day rather than added before go-live.
Then we attack it. Prompt injection, data exfiltration through an assistant connected to your document store, an agent holding credentials it should not — an AI red team finds these before a customer or a regulator does. And the same models go the other way: into detection, triage and the compliance evidence that used to take a person a week.
Where AI is worth the effort, and the rules that keep it defensible.
Where you actually stand on data, skills, governance and tooling, including an honest inventory of the shadow AI your teams are already using.
A portfolio of use cases ranked by value and feasibility, sequenced into a roadmap with the platform and governance work that has to happen alongside it.
Roles, approval gates, an AI register and review criteria, aligned with ISO 42001 and the AI Act so that governance and compliance are one piece of work.
Pilots, agents, copilots and the platform underneath them, built on your data and measured against a baseline.
A use case defined precisely enough to build — data, users, success measures — with its AI Act classification settled before any budget is committed.
A working pilot — retrieval-augmented search, an internal assistant or document automation — built on your data, evaluated against a measured baseline, with access control and logging from day one.
Agents that act on systems, built with the permission model and the human checkpoints defined first, because an agent with broad credentials is an access risk before it is a productivity gain.
The work that has to happen before a company-wide assistant is switched on: permission cleanup, data classification, tenant configuration, logging and user guidance.
The engineering that turns a promising pilot into a system you can operate: versioning, evaluation in the pipeline, cost control, monitoring and a rollback that works.
Models, prompts, agents and the data behind them, tested the way an attacker would.
Security review of AI systems against the OWASP Top 10 for LLM applications: prompt injection, data leakage through context, tool and agent permissions, and model supply chain.
Adversarial testing of an assistant, RAG system or agent: jailbreaks, indirect prompt injection through retrieved content, data exfiltration and abuse of connected tools.
The assurance layer: risk assessment, data protection, and audit of what is already running.
Risk assessment of an AI system across safety, bias, robustness and rights, including the fundamental rights impact assessment the AI Act requires from certain deployers.
Controls for the data an AI system touches: minimisation, pseudonymisation, retention in vector stores, tenant isolation and the contractual position with your model provider.
An independent review of a system already in production: how it performs, how it fails, what it logs, and whether its documentation would survive a regulator's question.
The same models pointed the other way: at your alert queue, your runbooks and the compliance evidence that used to take a week.
Applying AI where it genuinely helps our own field: alert triage, evidence gathering, policy drafting and supplier questionnaire handling, with a human decision at the end.
Language models put to work on your alert queue: enrichment, deduplication and a first triage, with the analyst keeping the decision.
A secured roll-out of Microsoft Security Copilot or an equivalent, scoped to the analysts who will use it and the data it may see.
Models that read your tickets, configurations and logs and draft the control evidence an auditor asks for, reviewed by a person before it leaves.
Executives, teams and everyone who pastes into an assistant, taught what applies to them.
Working sessions that leave leaders able to judge an AI proposal: what these systems do well, where they fail, and what the regulation asks of them.
What generative AI does, what it gets wrong and what the AI Act asks of the people who use it — for every employee, in their own terms.
Hands-on training on the assistants your teams actually use: what to paste, what never to, and how to check an answer before acting on it.
Every AI system inventoried, classified and dated, with the obligations that follow.
An assistant rolled out to the whole company without opening the whole file server with it.
The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.
AI Act Check takes three to four weeks and tells you what you are running, what it is classified as, and what is owed from when.