Trust, security and operational resilience for AIAsset managers & funds

From AI risk to resilience: getting ready for DORA and the EU AI Act.

The most advanced AI models can dangerously identify and exploit software vulnerabilities, and regulators are responding. DORA already applies, and the EU AI Act is phasing in: transparency and staff training since August 2026, high-risk obligations from December 2027. We help you build a single framework that satisfies both, implement it, and run it with you.

Version française →
01 — Why now

The risk is accelerating, and regulators know it.

April–June 2026

AI becomes a serious cybersecurity risk

Anthropic’s Mythos model uncovered thousands of critical vulnerabilities. The European Central Bank summoned risk officers from euro-area banks, and Belgium’s FSMA warned that the cost of attacking any regulated entity has fallen sharply.

2025–2027

DORA today, the AI Act tomorrow

DORA already treats AI as part of a firm’s ICT estate and register of information. The AI Act adds inventory, classification, human oversight and accountability obligations on top.

02 — What we do

Four pillars, one team, strategic partners.

We advise, we implement, we can operate, and we transfer the skills to your own teams.

I

Business & regulatory advisory

Strategy, governance, compliance
→AI inventory and shadow-AI detection
→Mapping and classifying your AI use cases, and the gaps to close
→DORA and ICT-risk assessment
→AI governance, policies and staff awareness
→Third-party governance and register of information
II

Technology advisory

Architecture, security, testing
→AI architecture and data-flow mapping
→Securing models, agents and document stores
→Agent identities, access and permissions
→AI vulnerability audits and adversarial testing
→External attack surface and code security
III

Managed services

Operate, monitor, attest
→AI governance as a service
→Resilience testing and continuous cybersecurity risk monitoring
→Accelerated vulnerability triage and remediation, patch deployment
→DORA and regulatory evidence files
→Third-party and model oversight
IV

AI solutions

Build, integrate, measure
→Secure copilots, agents and RAG for cyber and compliance
→AI-assisted vulnerability monitoring and qualification
→AI-assisted access and permissions reviews
→Controlled production rollout: integration, oversight and continuity
→Value measurement and shared gains
03 — Compliance

The framework we deliver aligns with the AI Act and DORA.

EU AI ActDORAFSMA 2026/15GDPRNIST AI RMFISO/IEC 42001
Govern
  • AI inventory and risk classification
  • Governance, operating model and roles
  • AI policy and human oversight
  • Risk and controls framework
Secure
  • Architecture and data flows
  • Agent identities, access and permissions
  • Model, RAG and agent security
  • Attack surface and patching
Attest
  • Third-party and concentration risk
  • Register of information
  • Resilience, recovery and testing
  • Evidence, audit and reporting
04 — What we cover

AI-specific risks we cover.

Prompt injectionExcessive agencyData and model leakageShadow AIThird-party AI dependencyAI-accelerated exploitation

Our method

Discover›Assess›Design›Implement›Validate›Operate

Ready to build your AI resilience framework?

Let’s talk about your DORA roadmap, the EU AI Act, and what needs to ship first.