Agentic AI Security · EU AI Act · NIS2

One assessment. Two regulations. Your AI agents covered.

NIS2 is law in Germany since December 2025. Austria follows on 1 October 2026 with NISG 2026. The AI Act's transparency duties start in August 2026, high-risk obligations in December 2027. I assess your agent architecture once and map every finding to both regulations: threat model, compliance mapping, remediation roadmap. Independent. No tool to sell.

Book a free 30-min Idea Call →
Why Now

The EU gave you runway on high-risk AI. NIS2 did not.

The Digital Omnibus moved the AI Act's high-risk obligations to 2 December 2027. That is not a reprieve. Transparency duties under Article 50 apply from 2 August 2026, and GPAI enforcement starts the same month. Meanwhile NIS2 already applies in Germany, with registration deadlines passed, and Austria's NISG 2026 takes effect on 1 October 2026: registration by 31 December 2026, audits from April 2027.

Your AI agents sit in the middle of both. They hold credentials, call tools and touch the systems NIS2 calls critical. Both regulations demand risk management, incident reporting and documentation for exactly this kind of system. An assessment that covers only one of them means paying twice.

Roughly three quarters of the controls overlap. One assessment, mapped to both regulations, is the shortest path to compliant agents.
Concrete Deliverables

What you walk away with.

Not a slide deck full of paragraphs from the regulation. Five artefacts your auditors, your engineers and your board can act on.

EU AI Act and NIS2 Compliance Mapping

Every finding mapped to the concrete articles that apply to you: risk management, reporting duties, documentation, under the AI Act and NIS2 (NISG 2026 in Austria, BSIG in Germany).

Threat Model of Your Agent Architecture

Scenario-driven attack trees across agents, tools, memory and orchestration, built with the OWASP Top 10 for Agentic Applications, MITRE ATLAS and CSA MAESTRO.

Report with Remediation Roadmap

Prioritized fixes scored by effort and impact, sequenced against your regulatory deadlines: what must be done before October 2026 and what can wait until 2027.

Audit Evidence Pack and Executive Read-out

A live walkthrough for your leadership plus documentation you can hand to an auditor or a customer security questionnaire as proof of due diligence.

Optional Continuous Retainer

Re-assessment as you ship new agents, compliance monitoring as the rules evolve, and an updated threat model on record. EUR 1,500 to 3,000 per month.

Core Assessment

Agentic AI Security Assessment

€12,000 to €18,000 · 2 to 4 weeks · remote or on-site

Priced by the complexity of your agent architecture. Includes discovery, threat modeling, EU AI Act and NIS2 mapping, the written report with remediation roadmap, and the executive read-out. Optional continuous retainer from €1,500 to €3,000 per month.

Book a free Idea Call to scope it
How It Runs

From architecture to audit-ready in three stages.

A focused engagement, typically 2 to 4 weeks from kick-off to executive read-out.

Stage 1

Discovery and Classification

We map your agents, tools, data flows and orchestration, and classify each system under the AI Act risk tiers and your NIS2 entity status.

Stage 2

Threat Modeling

Scenario-driven attack trees surface the real attack paths and map them to OWASP Agentic, MITRE ATLAS and MAESTRO.

Stage 3

Mapping and Roadmap

Every finding mapped to the AI Act and NIS2, then turned into a remediation roadmap sequenced against your deadlines.

Track Record

I build multi-agent systems. And I take them apart.

The assessment comes from the builder's side, not from an audit checklist. This is work I show on stage and run in production.

Talk · AWS Community Day Istanbul 2026

Your Agent Is Your New Layer 8

Why autonomous agents behave like a new human layer in your organisation: with all the security consequences that brings.

Session · AWS Community Day Istanbul 2026

Securing Agent Identity

How agents get their own identities, scoped permissions and auditable access instead of shared API keys.

Live build · AWS Community Day Athens 2026

A multi-agent crew, built on stage

A multi-agent film crew shown live: specialised agents planning, producing and reviewing against real constraints.

Enterprise work

Multi-agent deep dives

Technical deep dives on hybrid multi-agent architecture and platform engineering for enterprise teams, plus hands-on Amazon Bedrock AgentCore workshops.

The Green Light

Up to 100% AWS funded.

As an AWS Community Hero, I navigate the funding process with you, from application to approval. Eligibility is assessed in the first 30 minutes, not added as an afterthought at the end.

PoC Funding

Up to €10,000

Covers prototype development. Deliverables engineered to meet funding requirements.

Migration Funding

Up to €400,000

For larger cloud transformation projects. Multi-phase plan structuring and end-to-end application support.

Questions Buyers Ask

Answers, in writing.

Has the EU AI Act's August 2026 high-risk deadline been delayed?

Yes. The Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and product-embedded AI to August 2028. Transparency duties under Article 50 still apply from 2 August 2026, and enforcement of the GPAI obligations starts the same month.

Does NIS2 apply to our AI agents?

If your organisation is an essential or important entity under NIS2, your AI agents are part of the ICT risk you are obliged to manage. In Germany the law is in force since December 2025. In Austria NISG 2026 takes effect on 1 October 2026, with registration due by 31 December 2026.

Is my AI agent a high-risk system under the AI Act?

It depends on what the agent does, not on the model behind it. Agents involved in hiring, credit, essential services or safety components typically land in Annex III. The assessment includes this classification, documented and defensible.

What does an AI agent security assessment cost?

EUR 12,000 to 18,000 fixed, depending on the complexity of the architecture. The continuous retainer runs EUR 1,500 to 3,000 per month. Both prices are on this page on purpose: comparable engagements are quoted at USD 35,000 and up.

We already did a penetration test. Why a threat model?

A pentest finds implementation bugs in what you built. A threat model finds design flaws in what you are about to build, including attack paths a pentest never executes: goal hijacking, memory poisoning, tool misuse across agents.

Your agent holds credentials. So it holds rights

FREE DECK

Agent Security Check

An autonomous agent holds credentials, calls tools and touches systems. This is where the findings pile up.

  • The attack paths
  • Two regulations with deadlines
  • A placement map
  • Two worksheets

37 pages. Large type, one idea per page, sources on every page. Double opt-in: you confirm by email first. Unsubscribe with one click.

Linda Mohamed
Your consultant

Linda Mohamed

AWS Community HeroIndependent ConsultantBedrock · CrewAI · LangGraphEN & DE delivery

An independent practice for organisations that want their AI agents assessed by the person who builds them. AWS Community Hero, speaker at AWS Community Days in Istanbul and Athens 2026, and builder of production multi-agent systems on Amazon Bedrock, CrewAI and LangGraph. Based in Vienna, Austria. Remote or on-site, English or German.

Book a free 30-min Idea Call →
Architecture

Where agents cross boundaries.

Findings cluster in the same places: identities, tool permissions and what reaches the model. The review follows the OWASP Top 10 for Agentic Applications[7], MITRE ATLAS[8] and MAESTRO[9].

Agent deployment on AWS: one IAM role per agent, secrets in Secrets Manager, weights encrypted at rest, logs in CloudWatch.
What a threat model looks at: every agent has its own identity and role, secrets live outside the code, model weights are encrypted, and every call leaves a log. The example is a reference project from my lecture.Source: Linda Mohamed, lecture “Von Managed zu Hybrid: KI-Architekturen”, Hochschule Burgenland, 2026
Data boundary on a managed model: application, private data and retrieval stay in your environment; only permitted context crosses to the model endpoint.
The boundary question behind most findings: which context, tools and data may cross to the model, and who decided that.Source: Linda Mohamed, lecture “Von Managed zu Hybrid: KI-Architekturen”, Hochschule Burgenland, 2026
AWS services

The AWS services behind this work.

The AWS controls that come up in almost every agent review. Each name links to the official documentation.

AWS Identity and Access Management (IAM)

Who and what may call which service. For agents: one narrow role per agent.

AWS CloudTrail

Records every API call in the account, the audit trail for what an agent actually did.

Amazon Bedrock Guardrails

Filters for topics, harmful content and personal data on the way into and out of the model.

Amazon Bedrock AgentCore

Runtime, memory, identity and tool gateway for AI agents built with any framework, such as Strands or CrewAI.

Amazon CloudWatch

Logs, metrics and alarms. For AI systems: latency, errors and cost per call.

Amazon Bedrock

Managed access to foundation models from several providers through one API. You choose the model and write the prompt; AWS runs the model.

Book directly

Book it right here.

All prices are net. Companies outside Austria pay no VAT and can book directly by card. Companies in Austria, please choose “Pay by invoice”: 20% VAT is added there.

Agentic AI Security Assessment

€12,000net

A focused engagement, typically 2 to 4 weeks from kick-off to executive read-out.

Buy now →Pay by invoice

Security Assessment Extended

€15,000net

The same assessment for a larger scope. Not sure which size fits? Book the free call first.

Buy now →Pay by invoice

Security Assessment Complex

€18,000net

For complex agent landscapes. We confirm the scope in the free call.

Buy now →Pay by invoice

Security Retainer Essential

€1,500net / month

Re-assessment as you ship new agents, compliance monitoring and an updated threat model on record.

Buy now →Pay by invoice

Security Retainer Standard

€2,250net / month

The Essential retainer with more capacity per month.

Buy now →Pay by invoice
Start Here

Begin with a 30-minute Idea Call.

Before the assessment, we have a short conversation to confirm fit. No commitment. No slides. The same opening conversation that precedes every paid engagement.

  • Confirm the scope of your agent architecture
  • Check where the EU AI Act and NIS2 apply to you
  • Decide whether the one-time assessment or the retainer fits best
  • Get the intake brief and a calendar slot
Book the Idea Call

Only a quick question? Book 15 minutes

Typically respond within one business day. Vienna, Austria · serving clients across the EU · [email protected]