Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

The EU AI Act, for security and risk teams

A risk-tiered law that lands on anyone building or deploying AI. What it classifies, what it demands, and where it overlaps with the security programme you already run.

Updated September 2026 · 7 min read

The risk tiers

The Act is structured by risk. Prohibited uses (such as certain manipulative or social-scoring systems) are banned outright. High-risk uses — safety components, and applications in areas like employment, critical infrastructure and law enforcement — carry the full weight of obligations. Limited-risk systems mainly owe transparency, such as telling people they are interacting with a bot. Most systems are minimal-risk with few duties. The obligations phase in over staggered dates.

What high-risk actually demands

For high-risk systems, providers must run a lifecycle risk-management system, govern their training data, keep technical documentation and logs, be transparent to deployers, ensure human oversight, and meet accuracy, robustness and cybersecurity bars. Deployers carry their own duties around how the system is used, monitored and overseen.

None of that is unfamiliar to a security team — it is governance, logging, access control and monitoring, applied to a new class of asset.

Where it meets your security programme

The efficient path is to treat AI systems as assets inside your existing risk and governance process rather than standing up a parallel programme. The same ISMS disciplines — asset inventory, logging, monitoring, incident handling, supplier governance — carry most of the load.

Governing the AI you adopt is what turns the Act from a compliance headache into an extension of controls you already run.

FAQ

Questions, answered

Does it apply to us if we are outside the EU?
It can. Like GDPR, the Act reaches providers and deployers whose systems or outputs are used in the EU, so many non-EU organisations meet it through their EU customers or operations. Applicability is a question for your counsel.
Is general-purpose AI covered?
Yes. Providers of general-purpose AI models have specific transparency obligations, and the most capable models carry additional systemic-risk duties, separate from the risk tiers that apply to AI systems.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.