One assessment. Two regulations. Your AI agents covered.
NIS2 is law in Germany since December 2025. Austria follows on 1 October 2026 with NISG 2026. The AI Act's transparency duties start in August 2026, high-risk obligations in December 2027. I assess your agent architecture once and map every finding to both regulations: threat model, compliance mapping, remediation roadmap. Independent. No tool to sell.
Book a free 30-min Idea Call →The EU gave you runway on high-risk AI. NIS2 did not.
The Digital Omnibus moved the AI Act's high-risk obligations to 2 December 2027. That is not a reprieve. Transparency duties under Article 50 apply from 2 August 2026, and GPAI enforcement starts the same month. Meanwhile NIS2 already applies in Germany, with registration deadlines passed, and Austria's NISG 2026 takes effect on 1 October 2026: registration by 31 December 2026, audits from April 2027.
Your AI agents sit in the middle of both. They hold credentials, call tools and touch the systems NIS2 calls critical. Both regulations demand risk management, incident reporting and documentation for exactly this kind of system. An assessment that covers only one of them means paying twice.
What you walk away with.
Not a slide deck full of paragraphs from the regulation. Five artefacts your auditors, your engineers and your board can act on.
EU AI Act and NIS2 Compliance Mapping
Every finding mapped to the concrete articles that apply to you: risk management, reporting duties, documentation, under the AI Act and NIS2 (NISG 2026 in Austria, BSIG in Germany).
Threat Model of Your Agent Architecture
Scenario-driven attack trees across agents, tools, memory and orchestration, built with the OWASP Top 10 for Agentic Applications, MITRE ATLAS and CSA MAESTRO.
Report with Remediation Roadmap
Prioritized fixes scored by effort and impact, sequenced against your regulatory deadlines: what must be done before October 2026 and what can wait until 2027.
Audit Evidence Pack and Executive Read-out
A live walkthrough for your leadership plus documentation you can hand to an auditor or a customer security questionnaire as proof of due diligence.
Optional Continuous Retainer
Re-assessment as you ship new agents, compliance monitoring as the rules evolve, and an updated threat model on record. EUR 1,500 to 3,000 per month.
Agentic AI Security Assessment
Priced by the complexity of your agent architecture. Includes discovery, threat modeling, EU AI Act and NIS2 mapping, the written report with remediation roadmap, and the executive read-out. Optional continuous retainer from €1,500 to €3,000 per month.
Book a free Idea Call to scope itFrom architecture to audit-ready in three stages.
A focused engagement, typically 2 to 4 weeks from kick-off to executive read-out.
Discovery and Classification
We map your agents, tools, data flows and orchestration, and classify each system under the AI Act risk tiers and your NIS2 entity status.
Threat Modeling
Scenario-driven attack trees surface the real attack paths and map them to OWASP Agentic, MITRE ATLAS and MAESTRO.
Mapping and Roadmap
Every finding mapped to the AI Act and NIS2, then turned into a remediation roadmap sequenced against your deadlines.
I build multi-agent systems. And I take them apart.
The assessment comes from the builder's side, not from an audit checklist. This is work I show on stage and run in production.
Your Agent Is Your New Layer 8
Why autonomous agents behave like a new human layer in your organisation: with all the security consequences that brings.
Securing Agent Identity
How agents get their own identities, scoped permissions and auditable access instead of shared API keys.
A multi-agent crew, built on stage
A multi-agent film crew shown live: specialised agents planning, producing and reviewing against real constraints.
Multi-agent deep dives
Technical deep dives on hybrid multi-agent architecture and platform engineering for enterprise teams, plus hands-on Amazon Bedrock AgentCore workshops.
Up to 100% AWS funded.
As an AWS Community Hero, I navigate the funding process with you, from application to approval. Eligibility is assessed in the first 30 minutes, not added as an afterthought at the end.
PoC Funding
Covers prototype development. Deliverables engineered to meet funding requirements.
Migration Funding
For larger cloud transformation projects. Multi-phase plan structuring and end-to-end application support.
Answers, in writing.
Has the EU AI Act's August 2026 high-risk deadline been delayed?
Yes. The Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and product-embedded AI to August 2028. Transparency duties under Article 50 still apply from 2 August 2026, and enforcement of the GPAI obligations starts the same month.
Does NIS2 apply to our AI agents?
If your organisation is an essential or important entity under NIS2, your AI agents are part of the ICT risk you are obliged to manage. In Germany the law is in force since December 2025. In Austria NISG 2026 takes effect on 1 October 2026, with registration due by 31 December 2026.
Is my AI agent a high-risk system under the AI Act?
It depends on what the agent does, not on the model behind it. Agents involved in hiring, credit, essential services or safety components typically land in Annex III. The assessment includes this classification, documented and defensible.
What does an AI agent security assessment cost?
EUR 12,000 to 18,000 fixed, depending on the complexity of the architecture. The continuous retainer runs EUR 1,500 to 3,000 per month. Both prices are on this page on purpose: comparable engagements are quoted at USD 35,000 and up.
We already did a penetration test. Why a threat model?
A pentest finds implementation bugs in what you built. A threat model finds design flaws in what you are about to build, including attack paths a pentest never executes: goal hijacking, memory poisoning, tool misuse across agents.

FREE DECK
Agent Security Check
An autonomous agent holds credentials, calls tools and touches systems. This is where the findings pile up.
- The attack paths
- Two regulations with deadlines
- A placement map
- Two worksheets
37 pages. Large type, one idea per page, sources on every page. Double opt-in: you confirm by email first. Unsubscribe with one click.

Linda Mohamed
An independent practice for organisations that want their AI agents assessed by the person who builds them. AWS Community Hero, speaker at AWS Community Days in Istanbul and Athens 2026, and builder of production multi-agent systems on Amazon Bedrock, CrewAI and LangGraph. Based in Vienna, Austria. Remote or on-site, English or German.
Book a free 30-min Idea Call →Where agents cross boundaries.
Findings cluster in the same places: identities, tool permissions and what reaches the model. The review follows the OWASP Top 10 for Agentic Applications[7], MITRE ATLAS[8] and MAESTRO[9].


The AWS services behind this work.
The AWS controls that come up in almost every agent review. Each name links to the official documentation.
AWS Identity and Access Management (IAM)
Who and what may call which service. For agents: one narrow role per agent.
AWS CloudTrail
Records every API call in the account, the audit trail for what an agent actually did.
Amazon Bedrock Guardrails
Filters for topics, harmful content and personal data on the way into and out of the model.
Amazon Bedrock AgentCore
Runtime, memory, identity and tool gateway for AI agents built with any framework, such as Strands or CrewAI.
Amazon CloudWatch
Logs, metrics and alarms. For AI systems: latency, errors and cost per call.
Amazon Bedrock
Managed access to foundation models from several providers through one API. You choose the model and write the prompt; AWS runs the model.
Real patterns, documented in the open.
Each link opens a write-up on ai-solutions.wiki, the open engineering reference I maintain. Architecture, services and trade-offs are explained there in full.
OWASP Top 10 for LLM applications explained
The ten most common LLM risks with mitigations on AWS.
Read on ai-solutions.wiki →FinanceAI for Financial Compliance Automation
KYC/AML screening, transaction monitoring, regulatory reporting, and audit trail generation for financial services.
Read on ai-solutions.wiki →Case patternAI Compliance Monitoring for a Financial Institution
Architecture and lessons from deploying AI to monitor communications, transactions, and activities for regulatory compliance across a financial institution.
Read on ai-solutions.wiki →Where the facts come from.
Deadlines and obligations change; the linked legal texts are the reference. This page is not legal advice.
- Regulation (EU) 2024/1689, the EU AI Act (EUR-Lex)
- EU AI Act Article 50: transparency obligations
- Cloud Security Alliance research note: AI Act high-risk deadline after the Digital Omnibus, Regulation (EU) 2026/1744
- Directive (EU) 2022/2555, NIS2 (EUR-Lex)
- RIS: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025
- DLA Piper: NIS 2 Directive transposed in Germany, register with the BSI
- OWASP Top 10 for Agentic Applications for 2026
- MITRE ATLAS
- Cloud Security Alliance: MAESTRO agentic AI threat modeling framework
- ai-solutions.wiki: OWASP Top 10 for LLM applications explained
- AWS: What is Amazon Bedrock AgentCore?
Book it right here.
All prices are net. Companies outside Austria pay no VAT and can book directly by card. Companies in Austria, please choose “Pay by invoice”: 20% VAT is added there.
Agentic AI Security Assessment
A focused engagement, typically 2 to 4 weeks from kick-off to executive read-out.
Buy now →Pay by invoiceSecurity Assessment Extended
The same assessment for a larger scope. Not sure which size fits? Book the free call first.
Buy now →Pay by invoiceSecurity Assessment Complex
For complex agent landscapes. We confirm the scope in the free call.
Buy now →Pay by invoiceSecurity Retainer Essential
Re-assessment as you ship new agents, compliance monitoring and an updated threat model on record.
Buy now →Pay by invoiceSecurity Retainer Standard
The Essential retainer with more capacity per month.
Buy now →Pay by invoiceBegin with a 30-minute Idea Call.
Before the assessment, we have a short conversation to confirm fit. No commitment. No slides. The same opening conversation that precedes every paid engagement.
- Confirm the scope of your agent architecture
- Check where the EU AI Act and NIS2 apply to you
- Decide whether the one-time assessment or the retainer fits best
- Get the intake brief and a calendar slot
Only a quick question? Book 15 minutes
Typically respond within one business day. Vienna, Austria · serving clients across the EU · [email protected]