artenis.alija
ende
AI Security / Albania

AI Security Consultant in Albania

LLM red teaming and prompt injection testing for Albanian businesses, in Albanian and English.

Albania is adopting AI quickly and publicly. The government appointed an AI-generated virtual minister to oversee public procurement in 2025, banks and telecoms are rolling out assistants, and a growing number of businesses answer customers through AI on WhatsApp. Very few of those systems have been tested by anyone trying to break them.

I am based in Tirana and build AI systems for Albanian businesses, which is exactly why I test them. The specific local risk is language: model safety training is far weaker in Albanian than in English, so a jailbreak refused in English can succeed when written in Albanian or a mix of both. Testing in the language your customers actually use is not optional here.

TiranaDurrësVlorëShkodërElbasanFierKorçë
AI security testing for organisations across Albania. Delivery is remote — the map shows coverage, not office locations.

AI security testing in Albania

Data regime
Albanian data protection law, aligned with GDPR as part of EU accession. Data can be hosted in-country or in the EU.
Working hours
CET. Same working day as the entire EU, with full overlap.
Languages
Albanian for staff-facing interfaces, English for technical documentation.
Delivery
Remote testing against your staging or production endpoint, with scoping and findings sessions scheduled in the Albania working day.
Frameworks
OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, EU AI Act Article 15.
Tools
Garak, PyRIT, promptfoo, Giskard, Burp Suite and custom Python harnesses.

Authorised testing only

Every assessment runs under a written scope and authorisation from the owner of the system, agreed before any test is run.

Why AI security matters in Albania

Albanian-language attacks work better

Research has repeatedly shown that safety filters trained mostly on English are easier to bypass in lower-resource languages. Every assessment for an Albanian-facing system includes attacks written in Albanian, in Gheg and Tosk phrasing, and in mixed Albanian-English.

Data protection aligned with GDPR

Albania's updated personal data protection law follows the GDPR model as part of EU accession. A chatbot that leaks one customer's data to another is a reportable data protection problem, not only a reputational one.

Cyber security is a national priority

After the 2022 attacks on government systems, Albania strengthened its cyber security law and the role of the national cyber security authority. AI systems connected to customer data now sit inside that expectation.

WhatsApp and web chat are the attack surface

Most customer-facing AI here runs on WhatsApp or a website chat widget, open to anyone with a phone number. That makes prompt injection and data leakage a public-facing risk from the first day.

What gets tested

The six attack classes behind most serious findings. The full list, and the tooling used for each, is on the main AI security page.

Direct prompt injection and jailbreaks

Role-play, instruction override, payload splitting, encoding tricks (Base64, leetspeak, invisible Unicode) and multi-turn escalation, to see whether the model can be argued out of its instructions and guardrails.

Indirect prompt injection

Instructions planted in the content your system reads rather than in the chat box: an uploaded PDF, an inbound email, a web page an agent browses, a product review, a CRM note. This is the attack most production systems are least prepared for.

System prompt and configuration leakage

Extracting the hidden instructions, internal URLs, API structure, business rules and occasionally the credentials that developers put in a system prompt on the assumption nobody would see it.

Data exfiltration through output

Markdown images, auto-unfurled links and tool calls that quietly send conversation data or retrieved documents to an attacker-controlled server once a malicious instruction lands.

Excessive agency and tool abuse

Agents persuaded to send emails, issue refunds, change records or call internal APIs outside their intended purpose. Tested against the real tool permissions, including MCP servers and poisoned tool descriptions.

RAG and vector store weaknesses

Cross-tenant document leakage, retrieval that ignores the user's access rights, poisoned documents that steer answers, and embeddings that reveal more than the source permissions allow.

How the assessment runs

1. Scope and threat model

Map what the AI system can read, what it can do, who talks to it and what would hurt most if it went wrong. Written authorisation and rules of engagement are agreed before any testing.

2. Automated scanning

Garak, PyRIT and promptfoo run thousands of known attack patterns against the live or staging endpoint to establish a baseline quickly and cheaply.

3. Manual adversarial testing

The part that finds the serious issues: multi-turn manipulation, indirect injection through your real document and email flows, and chained attacks that scanners cannot plan.

4. Agent and integration testing

Every tool, API and permission the model can reach is tested for abuse, including privilege boundaries between users and tenants.

5. Report and fixes

Each finding comes with a reproduction, a severity, the OWASP LLM and MITRE ATLAS mapping, and a concrete fix — architecture first, filters second.

6. Retest and regression suite

Fixes are retested, and the successful attacks become a promptfoo suite in your pipeline so they cannot quietly come back with the next model upgrade.

Areas served

AI security testing is available across Albania, including Tirana, Durrës, Vlorë, Shkodër, Elbasan, Fier, Korçë, Berat, Sarandë. There is no local office — testing is delivered online, which is how AI endpoints are attacked in practice anyway.

AI risk in Albania's key sectors

Where AI is being deployed fastest here, and the risk tested first in each sector.

AI security for regulated financial AI

Assistants over accounts, claims and policies are tested for data leakage, manipulation into actions and unsafe advice, with results documented for DORA, the AI Act and your regulator.

AI security for patient-facing assistants

A booking or patient-support assistant connected to records can be manipulated into revealing another patient's appointments or history. Health data is special-category data under GDPR, so assistants are tested for leakage and for unsafe medical advice before patients use them.

AI security for guest-facing assistants

Booking and concierge bots are public and connected to reservations. They are tested for price manipulation, leakage of other guests' details and unauthorised booking changes.

AI security for shopping and support assistants

AI support agents can be talked into refunds, discount codes and policy exceptions, and product-page content can carry indirect prompt injection. Both abuse paths are tested against the tools the assistant can actually call.

AI security for lead and viewing bots

Property assistants hold lead data, owner details and pricing rules. Prompt injection that exposes other clients or commits to prices is tested before the bot goes public.

Frequently asked questions

Do you test AI systems in Albanian?

Yes, and it is one of the main reasons to test locally. Safety behaviour in Albanian is weaker than in English on most models, so the Albanian-language attacks are often the ones that succeed.

Can you come on site in Tirana?

Yes. Testing itself is done remotely against your staging or production endpoint, but scoping sessions and the findings walkthrough can be held in person in Tirana or elsewhere in Albania.

We only use ChatGPT through an API. Do we still need testing?

Yes. The provider secures the model; you are responsible for what it can read and do inside your application. That wiring is where almost all of the serious findings are.

Related pages

AI security in other markets

Get in touch

Tell me what needs automating

Describe the process that is costing you time and roughly how much. I reply to every enquiry personally, usually within one working day.

Response
Usually within one working day, Mon–Fri CET
Delivery
Remote across Europe, the Nordics and the Gulf
Or email inquiries@artenisalija.com