Assay Cyber Est. 2025 · VA
Blog hello@assaycyber.com
Notes & analysis · Updated periodically

Field notes from the regulatory wall.

Working notes on AI governance, the EU AI Act, ISO 42001 and 27001, and the operational reality of running a security program when the rules are still being drafted. Citation-disciplined. Plainly written. No takes for the sake of takes.

2026 · 04 · 20 EU AI Act

Most SaaS companies are not high-risk under the EU AI Act. Read the regulation before you sign the compliance contract.

Most mid-market SaaS companies offering AI features carry only transparency obligations, not the full high-risk regime. A walkthrough of the Annex III classifications and the Article 6(3) exception your compliance consultant probably won't mention.

Vanguard Cyber Solutions LLC · d/b/a Assay Cyber
Home Privacy Security © 2026