This website uses cookies

To provide the highest level of service we use cookies on this site.
Your continued use of the site means that you agree to their use in accordance with our terms and conditions.

AI Act compliance

and AI security assessment

As of August 2nd 2026, The EU AI Act transparency duties apply: users must be told when they are interacting with an AI system, and AI-generated content and deepfakes must be appropriately labelled. Penalties for non-compliance reach up to 35 million euro or 7 percent of global annual turnover. Additional duties for high-risk systems start on 2 December 2027.

Our assestment connects compliance and technical testing: we find out which of your systems the Act covers and what you are responsible for, and we secure the systems you build or run, both in the cloud or on your own hardware.

Enforced in Poland since 11 August 2026 via the national AI Systems Act, the supervisory authority KRiBSI can inspect organisations, impose fines and process complaints. With this market surveillance authority in place, AI Act regulations are expected to be fully enforced by Polish companies.

Key dates that shape scope



Key focus areas

01

Inventory and risk classification

We map the AI systems you already use, are building, or plan to roll out. For each one we determine your role under the AI Act(provider or deployer), and and its risk tier: prohibited, high-risk,, limited-risk with transparency duties, or minimal. get a register that shows what is in scope and what each system requires of you.

02

Gap analysis and conformity

For in-scope systems we check for applicable requirements (under articles 9 to 15):, risk management, data governance, technical documentation, logging, transparency, human oversight and accuracy, robustness and cybersecurity. You get a prioritised list of gaps and a roadmap to close them before the deadlines.

03

AI security testing and red teaming

We test models and LLM-based applications using own methodology, built on the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications 2026. Typical scenarios include prompt injection and goal hijacking, RAG poisoning, abuse of tools and MCP, identity and privilege misuses, and phantom actions, where the system confirms an operation it never actually performed.

04

Documentation and governance

We prepare and adapt the documentation the Act expects: policies, risk analyses, technical documentation and instructions for use. We also help you build AI governance, including the AI literacy measures that Article 4 expects of providers and deployers to ensure.. We may also line this up with an ISO/IEC 42001 management system so it fits the way you already work.

05

Secure deployment and implementation

We help you deploy AI in the cloud (e.g. Azure AI Foundry, AWS Bedrock) and on-premises, including choosing the right hardware for local models. We review the architecture and configuration around the model, from access and isolation to secrets and data flows, ensuring that sensitive or personal data does not leak. For teams building their own AI, we set up a secure development lifecycle (S-SDLC) from day one.

06

Monitoring, vendors and post-market

The work does not stop at go-live. We help you set up logging and post-market monitoring, verify your AI vendors meet their own AI Act obligations, and reassess as your systems and the rules evolve.

FAQ

Q:

Does the AI Act apply to my company?

Most likely, at least partially. The Act applies directly across the EU and covers both providers and deployers, including companies outside the EU whose systems are used in it. If you build, resell, fine-tune or simply use AI in your processes, some obligations apply to you. The first step is to find out which part.

Q:

How do the Polish AI Systems Act and KRiBSI fit in?

Q:

Which systems count as high-risk, and when are the deadlines?

Q:

How does security testing tie into compliance?

Q:

What standards do you work from?

Q:

We are building our own AI. Can you help from the start?

Q:

Why Securitum?

Any questions?

Happy to get a call or email
and help!