AI Information Security Consulting

Establishing auditable, legally compliant frameworks for the safe use of artificial intelligence.

AI Act and GDPR compliance, with NIS2, ISO 27001 and ISO 42001 system development available on request.

Why does information security matter in the age of AI?

AI tools process a significant share of an organisation's knowledge assets and data, often through external, third party models. This creates new exposure: data leaks, unauthorised access, and uncontrolled use of AI tools by staff on their own initiative, known as shadow AI.

This is precisely why the regulatory landscape has expanded. GDPR has governed the handling of personal data since 2018, and this applies fully to AI systems as well. The AI Act introduced obligations specifically tailored to artificial intelligence, whilst NIS2 tightened cybersecurity fundamentals at the legislative level. ISO 27001 has long provided a well established information security management framework, now complemented by a dedicated standard, ISO 42001, specifically for AI management systems.

In the Hungarian market, many organisations have yet to address this area in a considered way, despite AI already being used on a daily basis, whilst certain obligations, such as the NIS2 cybersecurity audit, are already relevant for affected organisations right now.

What happens after you get in touch with us?

1. Free consultation (45 to 60 minutes) - assessing regulatory exposure and where the organisation currently stands on AI related information security

2. Rapid diagnosis - mapping the most pressing compliance gaps and drafting an initial AI system inventory and risk classification

3. Senior management presentation - setting out recommended intervention priorities, a roadmap and an action plan

4. Joint work – according to the agreed scope and requirements:

  • Developing an AI system inventory and risk classification
  • Establishing GDPR and AI data handling compliance
  • NIS2 and ISO compliance preparation
  • Documentation and audit preparation
  • Setting up ongoing monitoring

What are the benefits of AI information security consulting?

Avoidable penalties

Under NIS2, fines can reach 10 million euros, whilst for high risk AI Act systems, penalties can reach 15 million euros or 3 percent of annual turnover.

Auditable operations

Demonstrable, documented frameworks rather than security based on gut feeling, ready to be shown during a regulatory inspection or a client due diligence review.

Market trust and competitive advantage

Verifiable compliance for clients, partners and supplier audits, where AI specific risk management is an increasingly common requirement.

Readiness for the future

Regulation is changing quickly, and a well designed framework adapts flexibly to new requirements.

Avoidable penalties

Under NIS2, fines can reach 10 million euros, whilst for high risk AI Act systems, penalties can reach 15 million euros or 3 percent of annual turnover.

Auditable operations

Demonstrable, documented frameworks rather than security based on gut feeling, ready to be shown during a regulatory inspection or a client due diligence review.

Market trust and competitive advantage

Verifiable compliance for clients, partners and supplier audits, where AI specific risk management is an increasingly common requirement.

Readiness for the future

Regulation is changing quickly, and a well designed framework adapts flexibly to new requirements.

What can we help with?

Let's discuss where your organisation currently stands.

How does this relate to legislation and standards?

GDPR

The EU's data protection regulation has governed the handling of personal data since 2018, and this applies fully to AI systems too: to training data, to inputs given to AI, and to the outputs it generates. The AI Act does not replace GDPR but builds on it, GDPR rules continue to apply unchanged to AI systems. Our experts act as Data Protection Officers (DPO) for several organisations, so we bring practical, day to day experience in this area.

AI Act

The EU level, risk based AI regulation. In Hungary, Act LXXV of 2025 provides for its national implementation. The prohibited practices and AI literacy requirements are already in force, as are the transparency obligations for general purpose AI models. Obligations for high risk systems were postponed in summer 2026, with the entry into force set for December 2027 for standalone systems and August 2028 for systems embedded in products. This allows time to prepare, but it is worth carrying out the risk classification now.

NIS2

Transposed into Hungarian law by Act LXIX of 2024, with the Supervisory Authority for Regulated Activities as the supervisory body. Organisations previously brought within scope were required to complete their first mandatory cybersecurity audit by 30 June 2026. Fines can reach 10 million euros, together with personal liability for management. It is not AI specific in itself, but the introduction of AI systems creates a new attack surface for affected organisations.

ISO 27001

The general information security management system standard, which we ourselves rely on in our information security consulting. It provides the solid foundation, risk management, controlled processes and documented procedures, on which the AI specific layer, ISO 42001 and the related AI risk management, can be built.

ISO 42001

The first international standard specifically for artificial intelligence management systems. Its structure is similar to ISO 27001, so if an organisation already has a working ISO 27001 system in place, it can be built on effectively. It provides an auditable framework, verifiable by external parties, that validates the day to day operation of governance.

Our Lead Experts

Information Security Maturity Assessment

If you are not sure where your organisation's information security maturity currently stands, a free assessment can quickly give you a picture of the main gaps and the most pressing tasks.

Let's start with a conversation

In a free initial consultation we discuss where your organisation currently stands on AI information security and where the risks may lie. If required, we then prepare a fixed price quote for the rapid diagnosis, with a short turnaround time.

Our case studies are available here.

Contact us!

H-1118 Budapest, Kelenhegyi str. 29/b.

Frequently asked questions:

You do not need to address everything at once. GDPR compliance is already required now if you process personal data using AI. Which of the AI Act, NIS2 or ISO standards are relevant depends on the size of your organisation and the type of AI systems you use. The free consultation is exactly where this gets clarified.

GDPR governs the handling of personal data, and this continues to apply unchanged to AI systems. The AI Act does not replace it, but adds an extra layer on top, with obligations relating to the risk classification and operation of AI systems.

ISO 27001 provides a solid foundation, covering risk management, controlled processes and documented procedures, but it does not cover AI specific issues such as model trustworthiness or output validation. ISO 42001 builds on this existing foundation, adding the governance layer needed specifically for AI systems.

Our general information security consulting (IT security assessment, policy, business continuity and disaster recovery planning) covers the security of the organisation's entire IT operation. This AI specific service builds on that foundation, focusing specifically on the risks and legal obligations arising from the introduction of AI systems. If you do not yet have a foundational system in place, that is the place to start.

 

Some obligations, such as the prohibition on prohibited practices and ensuring staff AI literacy, are already in effect. The obligations for high-risk systems were postponed in summer 2026, to December 2027 for standalone systems and to August 2028 for systems embedded in products. It's worth carrying out the risk classification now, as it determines exactly what you need to prepare for.

Under NIS2, fines can reach 10 million euros, together with personal liability for management. For high risk AI Act systems, this can reach as much as 15 million euros or 3 percent of annual turnover. Beyond that, without documented, auditable operations, it is difficult to demonstrate compliance during a regulatory inspection or a client due diligence review.

The scope of NIS2 and the AI Act is not limited to large enterprises alone, in certain sectors and risk categories smaller organisations can be affected too. GDPR applies regardless of organisation size, as soon as you process personal data. We clarify this precisely for your situation during the free consultation.

 

This is the most common starting point, and it is what we call shadow AI. It is precisely where the biggest invisible risk arises, because there is no visibility into what data is going out, or into which tools. This is not an exception to the service, it is typically the first step, the system inventory exists precisely to map this out.

 

Yes, these obligations typically apply to the Hungarian legal entity and its local operations, regardless of whether AI related development decisions may fall under the authority of the foreign headquarters. Compliance responsibility cannot automatically be transferred to the parent company.

 

AI strategy sets the direction, governance establishes the day to day decision making and accountability framework, and this service makes operations auditable and legally compliant. The three build on one another, but can also be taken up separately.