Can you help us understand whether the EU AI Act, EU Cyber Resilience Act or NIS-2 apply to us?
Yes. Most founders do not know these apply to them until an investor or customer raises it. If you have EU customers or EU users, the EU AI Act and Cyber Resilience Act can apply regardless of Brexit, with fines up to €35M or 7% of global turnover for the EU AI Act. NIS-2 mainly affects essential and important-sector operators and their suppliers, so it is less common at early stage but worth checking if you sell into those supply chains. Commercial Readiness includes a plain-English regulatory map specific to your product and market.
Do you test the AI models themselves, or just how we use them?
We review how AI and agents are integrated into your product, permissions, data flows, prompts, third-party AI services, and where things could go wrong, rather than testing the underlying model itself, which is usually the responsibility of the model provider.
We're not using AI yet. Is this still relevant?
Yes. The Focused Review works just as well for a standard SaaS product, covering architecture, data flows and access model. AI-specific review is only included where it's relevant to what you're building.
How is this different from a penetration test?
A penetration test tries to break what you've built. This review happens earlier, at the architecture and design level, so you fix structural issues before they become expensive, and arrive at a penetration test with fewer, cheaper findings.
