artenis.alija
ende
AI Security / the Netherlands

AI Security Consultant in the Netherlands

Prompt injection and AI agent testing for a market that regulates algorithms seriously.

The Netherlands has taken algorithm supervision more seriously than most, with the data protection authority coordinating oversight of algorithms and AI and a public register for government algorithms. Dutch companies deploying AI are therefore more likely to be asked how they know their system is safe.

I provide the evidence: structured red team testing of chatbots, RAG systems and agents, with findings mapped to the OWASP LLM Top 10 and MITRE ATLAS and fixes that hold up to a second look.

AmsterdamRotterdamDen HaagUtrechtEindhoven
AI security testing for organisations across the Netherlands. Delivery is remote — the map shows coverage, not office locations.

AI security testing in the Netherlands

Data regime
GDPR, implemented nationally as the AVG. EU data residency is straightforward and generally expected.
Working hours
CET. Identical working day.
Languages
English is standard for technical and business work; Dutch for customer-facing content.
Delivery
Remote testing against your staging or production endpoint, with scoping and findings sessions scheduled in the the Netherlands working day.
Frameworks
OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, EU AI Act Article 15.
Tools
Garak, PyRIT, promptfoo, Giskard, Burp Suite and custom Python harnesses.

Authorised testing only

Every assessment runs under a written scope and authorisation from the owner of the system, agreed before any test is run.

Why AI security matters in the Netherlands

The EU AI Act

The AI Act applies in stages: prohibited practices from February 2025, general-purpose model obligations from August 2025, and high-risk system obligations from August 2026 onward, with some high-risk deadlines subject to the Commission's proposed postponement. Article 15 requires high-risk systems to be robust against attacks such as data poisoning, adversarial inputs and model evasion.

Coordinated algorithm supervision

The Autoriteit Persoonsgegevens coordinates supervision of algorithms and AI and publishes regular risk reports. Documented testing is the practical way to show an AI system is under control.

Cyber security legislation

The Dutch implementation of NIS2 brings many more organisations under formal cyber security duties, and AI systems wired into operations fall inside that scope.

English-first, Dutch-facing

Many Dutch businesses run internal tools in English and customer-facing assistants in Dutch. Both languages are attacked, because refusal behaviour differs between them.

What gets tested

The six attack classes behind most serious findings. The full list, and the tooling used for each, is on the main AI security page.

Direct prompt injection and jailbreaks

Role-play, instruction override, payload splitting, encoding tricks (Base64, leetspeak, invisible Unicode) and multi-turn escalation, to see whether the model can be argued out of its instructions and guardrails.

Indirect prompt injection

Instructions planted in the content your system reads rather than in the chat box: an uploaded PDF, an inbound email, a web page an agent browses, a product review, a CRM note. This is the attack most production systems are least prepared for.

System prompt and configuration leakage

Extracting the hidden instructions, internal URLs, API structure, business rules and occasionally the credentials that developers put in a system prompt on the assumption nobody would see it.

Data exfiltration through output

Markdown images, auto-unfurled links and tool calls that quietly send conversation data or retrieved documents to an attacker-controlled server once a malicious instruction lands.

Excessive agency and tool abuse

Agents persuaded to send emails, issue refunds, change records or call internal APIs outside their intended purpose. Tested against the real tool permissions, including MCP servers and poisoned tool descriptions.

RAG and vector store weaknesses

Cross-tenant document leakage, retrieval that ignores the user's access rights, poisoned documents that steer answers, and embeddings that reveal more than the source permissions allow.

How the assessment runs

1. Scope and threat model

Map what the AI system can read, what it can do, who talks to it and what would hurt most if it went wrong. Written authorisation and rules of engagement are agreed before any testing.

2. Automated scanning

Garak, PyRIT and promptfoo run thousands of known attack patterns against the live or staging endpoint to establish a baseline quickly and cheaply.

3. Manual adversarial testing

The part that finds the serious issues: multi-turn manipulation, indirect injection through your real document and email flows, and chained attacks that scanners cannot plan.

4. Agent and integration testing

Every tool, API and permission the model can reach is tested for abuse, including privilege boundaries between users and tenants.

5. Report and fixes

Each finding comes with a reproduction, a severity, the OWASP LLM and MITRE ATLAS mapping, and a concrete fix — architecture first, filters second.

6. Retest and regression suite

Fixes are retested, and the successful attacks become a promptfoo suite in your pipeline so they cannot quietly come back with the next model upgrade.

Areas served

AI security testing is available across the Netherlands, including Amsterdam, Rotterdam, Den Haag, Utrecht, Eindhoven, Groningen, Tilburg. There is no local office — testing is delivered online, which is how AI endpoints are attacked in practice anyway.

AI risk in the Netherlands's key sectors

Where AI is being deployed fastest here, and the risk tested first in each sector.

AI security for operational assistants

Assistants over shipment, customer and pricing data must not leak one customer's data to another or be steered into changing records. Documents and emails the system reads are tested as injection vectors.

AI security for regulated financial AI

Assistants over accounts, claims and policies are tested for data leakage, manipulation into actions and unsafe advice, with results documented for DORA, the AI Act and your regulator.

AI security for shopping and support assistants

AI support agents can be talked into refunds, discount codes and policy exceptions, and product-page content can carry indirect prompt injection. Both abuse paths are tested against the tools the assistant can actually call.

AI security for confidential knowledge systems

RAG assistants over client files and matters must respect confidentiality between clients and between teams. Retrieval access control and exfiltration through rendered output are the priority tests.

AI security for client-facing AI

Agencies run AI across many client accounts. Cross-client data leakage, prompt injection through scraped content and over-permissioned API keys are the risks tested first.

Frequently asked questions

Do you test Dutch-language assistants?

Yes. Dutch-language attacks are included for any system that serves Dutch customers, alongside English.

How long does an assessment take?

A single chatbot or RAG assistant is typically a few days of testing plus reporting. Agents with many tools take longer, and the scope is fixed before work starts.

Related pages

AI security in other markets

Get in touch

Tell me what needs automating

Describe the process that is costing you time and roughly how much. I reply to every enquiry personally, usually within one working day.

Response
Usually within one working day, Mon–Fri CET
Delivery
Remote across Europe, the Nordics and the Gulf
Or email inquiries@artenisalija.com