Skip to content
GlabIT
GlabIT

LLM application security · EU AI Act readiness

AI security

AI security testing in Romania for LLM applications, data and model pipelines, including OWASP GenAI LLM Top 10 review and EU AI Act readiness.

In one sentence

Security testing and review for the AI systems you deploy — LLM applications, agents, retrieval pipelines and the data behind them — against the OWASP Gen AI Security Project's GenAI LLM Top 10 (2026 edition at the time of writing; the engagement records the edition used), plus practical readiness work for the EU AI Act.

Who it is for

  • Product teams shipping chat assistants, copilots or agents on top of a foundation model
  • Companies connecting an LLM to internal documents, customer data or business tools (RAG, function calling)
  • Organisations that need an AI usage policy their staff will actually follow
  • Compliance owners asking what the EU AI Act means for a specific system

Two angles

Securing the AI systems you deploy. LLM application penetration testing — prompt injection (direct and via your documents), sensitive-data leakage, insecure output handling, excessive agency of tools, supply-chain and plugin risks — following the OWASP GenAI LLM Top 10 and, where systems take actions, the OWASP Gen AI Security Project’s agentic-security guidance. Architecture review of prompts, retrieval, memory, tool calling and logging. A usage policy for the AI tools your staff already use.

EU AI Act readiness. A practical, indicative read of where a given system may fall under the Act’s risk tiers, which obligations would apply, on what dates, and what evidence you would need. As of August 2026: the Article 50 transparency obligations (provider disclosure for direct human interaction, machine-readable marking of synthetic output, deployer disclosure of deepfakes and public-interest text with the editorial-control exception, and the emotion-recognition/biometric-categorisation duties) apply from 2 August 2026; after the AI Omnibus (in force 27 July 2026) the high-risk obligations apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Awareness and preparation, not legal advice and not a guaranteed classification — your counsel signs off, we make it concrete.

What we test, concretely

  • Prompt injection: direct, indirect (documents, web pages, emails your system reads), and multi-step through agents
  • Data leakage: system prompts, other users’ data, secrets in context or logs
  • Insecure output handling: model output rendered as HTML, executed as code, or passed to tools without validation
  • Excessive agency: what tools the model can call, with whose permissions, and what happens when it is tricked
  • Guardrail evasion and jailbreaks against your specific configuration
  • The surrounding web application and API, to the OWASP Web Security Testing Guide (WSTG v4.2)

What we deliberately do not claim

We do not certify AI systems as safe or compliant, we do not guarantee a legal risk classification under the AI Act, we do not benchmark model bias or robustness as a core service, and we do not sell an “AI security platform”. This is engineering and testing work, done by the same people who test your web applications.

Sources: OWASP Gen AI Security Project — OWASP GenAI LLM Top 10 (2026 edition, published August 2026) and the project’s agentic-security guidance; OWASP Web Security Testing Guide; European Commission — AI Omnibus (in force 27 July 2026) and Article 50 transparency guidelines. Last reviewed August 2026.

Deliverables

What you receive

  • LLM application test report

    Findings against the OWASP GenAI LLM Top 10 (the current edition recorded in the engagement — 2026 at the time of writing) with working examples — prompt injections that leak data or trigger actions, unsafe outputs, weak guardrails — each with a fix.

  • Architecture and pipeline review

    How prompts, context, tools, memory and data flow through the system; where trust boundaries are missing; what to log and monitor.

  • AI usage policy

    A short policy for staff use of AI tools — allowed, restricted, prohibited — with data-handling rules, mapped to your existing security policy.

  • EU AI Act readiness note

    For a given system — an indicative view of where it may sit under the AI Act's risk tiers, the obligations and dates that would follow, and a gap list. Indicative, not a legal classification; written for compliance and engineering together.

  • Retest

    Verification of fixes for critical and high findings.

  • Debrief workshop

    A walkthrough with your engineering and compliance teams together — the findings, which guardrails to fix first, what to log and monitor, and how the AI Act note fits your roadmap.

Engagement model

How it runs

Model
Fixed-price per application or system; policy and readiness work priced as short workshops.
Typical timeline
Set by scope in the proposal — per application for testing; policy and readiness work is delivered as short workshops.
  1. 01

    Understand the system

    Model, hosting, prompts, tools, data sources, users, and what a bad outcome would look like for you.

  2. 02

    Test

    Manual adversarial testing — direct and indirect prompt injection, jailbreak attempts, tool abuse — supported by curated test cases; review of the code paths that handle model output and tool calls.

  3. 03

    Review and advise

    Architecture, logging, guardrails, data handling; the readiness note where the AI Act applies.

  4. 04

    Retest and hand over

    Fix verification, policy sign-off, and the monitoring you should add.

FAQ

Questions a sceptical CISO asks

We use a hosted model (OpenAI, Anthropic, Azure OpenAI). Is there anything left to test?

Yes — most risk sits in your application, not the model. Prompt injection through your data sources, over-privileged tools the model can call, sensitive data in prompts and logs, and how you handle the model's output are all yours to secure.

What framework do you test against?

The OWASP Gen AI Security Project's GenAI LLM Top 10 — the current edition recorded in the engagement (2026 at the time of writing) — is the primary checklist, alongside the OWASP Web Security Testing Guide (WSTG v4.2) for the surrounding web application and API. Where agents call tools, we test authorisation and blast radius for each tool.

Can you make our AI system "safe"?

No one can, and we will not claim it. We can make specific attacks fail, reduce the blast radius when one succeeds, and put logging in place so you know when it happens.

What does the EU AI Act mean for us?

It depends on what the system does, and the timelines moved in 2026. Article 50 transparency duties apply from 2 August 2026 and are several distinct obligations rather than one label — providers must design systems intended to interact directly with people so that those people are informed (unless obvious from the context), providers must mark synthetic audio, image, video and text output in a machine-readable way subject to the Act's exceptions, deployers must disclose deepfakes and AI-generated text published on matters of public interest (with an exception where there is human editorial control), and there are separate duties for emotion-recognition and biometric-categorisation systems. Following the AI Omnibus (in force 27 July 2026), the high-risk rules apply from 2 December 2027 for Annex III systems (for example employment, credit, education) and from 2 August 2028 for AI embedded in regulated products (Annex I). The readiness note gives you an indicative view for your case and the dates that follow from it; the legal classification itself is for your counsel to confirm.

Do you also review our own models or training data?

We review data pipelines and access controls around models. Deep model-level evaluation (bias, robustness benchmarks) is a specialist activity we scope case by case, and refer on if it is outside what we do well.

Test the AI feature before your customers do

Send us a description of the system — model, data sources, tools — and we come back with a scoped, fixed-price test.