AMISOURCE.

Services06

AI Security & Compliance

AI that is safe to use and possible to account for — to leadership, customers and regulators.

The challenge

AI systems change the terms for security and compliance. An LLM solution can read documents the user has no permission for, be manipulated through content it retrieves, or leak sensitive data to a third-party model. Meanwhile the EU AI Act demands documented governance, NIS2 (in Sweden: the Cybersecurity Act) demands incident preparedness, and DORA reaches financial actors' AI providers.

Most AI projects we review have an impressive demo — and none of the four matters above handled.

Our approach

  1. Readiness assessment. Classification of your AI use against the Act's risk tiers, a gap analysis against obligations, and a timeline that gets you there — without unnecessary bureaucracy.
  2. Security testing. We test your LLM solutions like an adversary: prompt injection, data leakage, privilege escalation and the supply chain. The result is prioritised action, not a checklist.
  3. Governance that connects. AI governance should not be an island. We tie it into your existing ISMS, risk process and cybersecurity work — one governance model, not three.
  4. Documentation that holds. Model choices, data flows, evaluations and decisions documented so they hold up in review — by a customer, auditor or authority.

We work by the same principle as in the pharmaceutical and financial worlds where we have roots: what isn't documented didn't happen.

Frequently asked questions

The AI Act's high-risk deadlines have been deferred — can we rest now?

No — the date has moved, not gone. Transparency and literacy obligations already apply, and preparation (classification, governance, documentation) takes longer than most expect. Organisations that start now manage December 2027 calmly; those that wait will do it in a panic.

What are the most common security gaps in GenAI solutions?

Excessive permissions (the agent sees more than the user), vulnerability to prompt injection via retrieved documents and web content, sensitive data in logs and evaluation sets, and uncontrolled egress to model providers without agreements. Our tests probe exactly these patterns — before someone else does.

We have no security department. Can we still do this?

Yes. Small organisations need the same discipline but a simpler structure. We scale the scope to fit you — and leave templates and routines that are easy to maintain without a large IT organisation.

Next step

Ready to talk about where AI pays off in your business?

Book a free 30-minute intro call. We listen, ask questions and tell you honestly whether we're the right partner — or not.