As of August 2nd 2026, The EU AI Act transparency duties apply: users must be told when they are interacting with an AI system, and AI-generated content and deepfakes must be appropriately labelled. Penalties for non-compliance reach up to 35 million euro or 7 percent of global annual turnover. Additional duties for high-risk systems start on 2 December 2027.
Our assestment connects compliance and technical testing: we find out which of your systems the Act covers and what you are responsible for, and we secure the systems you build or run, both in the cloud or on your own hardware.
Enforced in Poland since 11 August 2026 via the national AI Systems Act, the supervisory authority KRiBSI can inspect organisations, impose fines and process complaints. With this market surveillance authority in place, AI Act regulations are expected to be fully enforced by Polish companies.
We map the AI systems you already use, are building, or plan to roll out. For each one we determine your role under the AI Act(provider or deployer), and and its risk tier: prohibited, high-risk,, limited-risk with transparency duties, or minimal. get a register that shows what is in scope and what each system requires of you.
For in-scope systems we check for applicable requirements (under articles 9 to 15):, risk management, data governance, technical documentation, logging, transparency, human oversight and accuracy, robustness and cybersecurity. You get a prioritised list of gaps and a roadmap to close them before the deadlines.
We test models and LLM-based applications using own methodology, built on the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications 2026. Typical scenarios include prompt injection and goal hijacking, RAG poisoning, abuse of tools and MCP, identity and privilege misuses, and phantom actions, where the system confirms an operation it never actually performed.
We prepare and adapt the documentation the Act expects: policies, risk analyses, technical documentation and instructions for use. We also help you build AI governance, including the AI literacy measures that Article 4 expects of providers and deployers to ensure.. We may also line this up with an ISO/IEC 42001 management system so it fits the way you already work.
We help you deploy AI in the cloud (e.g. Azure AI Foundry, AWS Bedrock) and on-premises, including choosing the right hardware for local models. We review the architecture and configuration around the model, from access and isolation to secrets and data flows, ensuring that sensitive or personal data does not leak. For teams building their own AI, we set up a secure development lifecycle (S-SDLC) from day one.
The work does not stop at go-live. We help you set up logging and post-market monitoring, verify your AI vendors meet their own AI Act obligations, and reassess as your systems and the rules evolve.
Q:
Most likely, at least partially. The Act applies directly across the EU and covers both providers and deployers, including companies outside the EU whose systems are used in it. If you build, resell, fine-tune or simply use AI in your processes, some obligations apply to you. The first step is to find out which part.
Q:
They run on separate tracks. Your obligations come from the EU Regulation and apply regardless of the Polish law. The Polish Act covers supervision: it sets up KRiBSI as the market surveillance authority, creates regulatory sandboxes, and opens a complaints route. In short: the Regulation sets rules and the national Act decides enforces them.
Q:
TheHigh-risk systems are defined in the Annex III of the Regulation, covering areas such as employment, credit scoring, critical infrastructure, biometrics and access to essential services, plus certain safety components. Their core duties (articles 9 to 15) apply from 2 December 2027 and 2 August 2028. Transparency duties for lighter-risk systems such as chatbots and AI-generated content marking already apply. It pays to classify early, because fixing a high-risk system takes time.
Q:
Closely. The Act requires high-risk systems ti achieve a reasonable level of accuracy, robustness and cybersecurity, and to resist attempts to alter their. You cannot demonstrate that convincingly without comprehensive tests. Our red teaming gives you the evidence and reproducible findings, with severity and proof of concept, that both hardens the system and supports your technical documentation.
Q:
For testing we use our own methodology aligned with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications 2026. For compliance we start from the AI Act itself and map controls onto recognised frameworks such as ISO/IEC 42001 for AI management and ISO/IEC 23894 for AI risk, so the work fits your existing governance instead of duplicating it.
Q:
Yes. Before the planned deployment we can model the threats and map the attack surface, review the architecture and the cloud or on-premises setup, and set up a secure development lifecycle so the model and the software around it are secure from the first line of code. Doing this early makes the later AI Act work far easier to prove.
Q:
Securitum has been providing penetration testing since 2009 and runs hundreds of security tests every year for leading European banks and technology companies. In AI Act projects, that means your compliance is backed by people who test systems against real attacks every day, not only by people who write policies.