New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

Services

AI Security Advisory Retainer

Senior AI security leadership on retainer, without the full-time hire. €8,000 per month, async-first, three-month minimum.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

What you actually get

What lands in your inbox each month.

AI security policy document

Initial creation, then quarterly updates as your stack evolves.

Threat model review

For any new agent or LLM feature shipped that month.

Customer questionnaire support

Answers to AI sections of incoming customer questionnaires. This alone often justifies the retainer.

Vendor AI security review

When you adopt a new model provider, evaluation framework, or AI-adjacent tool.

Monthly written report

Security posture summary, risks identified, recommended actions.

Office hours

Async availability via Slack or email for engineering questions throughout the month.

Download the service one-pager

Two pages: the €8,000 monthly scope, what lands every month, and how the engagement starts.

Download PDF

How it starts

Discovery call (30 minutes)

I learn about your stack, your team, and the AI security questions that have come up so far.

Scope and start

We agree what the first month covers — usually the policy baseline and a threat model of whatever ships next. Mutual NDA before kickoff.

Retainer runs

€8,000 a month, invoiced monthly. Three-month minimum, then month-to-month with 30-day notice on either side.

Pricing

One retainer. Three-month minimum, then month-to-month.

AI Security Advisory Retainer

Roughly 16 to 20 hours a month

8,000
€ / month
  • AI security policy ownership
  • Threat model review for every new agent or feature
  • Customer security questionnaire support
  • Vendor and model provider reviews
  • Monthly written report
  • Async office hours plus two calls a month

Three-month minimum, then month-to-month with 30-day notice on either side. Prices exclude VAT; invoiced monthly by Molnsys AB.

Common questions

Yes for ET clients. Workable for PT clients with the right cadence. The retainer is designed to run roughly 80% async, so overlap hours matter less than they would for a full-time hire.

The pool of candidates who can credibly handle agentic systems, MCP, and RAG security is small enough that a search takes six months and lands you a $300K-plus hire. The retainer gets you started in two weeks at a fraction of the cost.

The fractional engagement transitions cleanly. I help you spec the role, interview candidates, and ramp them up. You don't get stuck.

Then start with a Sprint or a Review instead. The retainer is priced for teams shipping AI changes continuously — if months go by without a new agent, feature, or customer questionnaire, a fixed-scope engagement is the better buy and I will say so on the call.

The €3,500 Sprint is the smallest way to work with me, and it is bookable without a call. Below the retainer price the advisory format itself breaks down: there is not enough continuity to own a policy or review what ships.

Mutual NDA available before kickoff. Customer security questionnaire responses, internal threat models, and policy documents are obviously confidential and stay that way.

Why this fits

Most companies building with AI need senior AI security expertise long before they can justify a full-time hire. Enterprise customers start asking AI security questions in procurement. Regulators follow. Hiring for it takes six months and lands a $300K+ candidate.

The retainer puts that expertise on your side of the table now. I work as the embedded AI security lead: async-first, focused on the work an in-house lead would be doing, at €8,000 per month.

Three months minimum, then month-to-month with 30-day notice on either side.

Why this works with someone in Sweden

Time zones. Sweden afternoon overlaps with US East Coast morning. Workable for one to two scheduled calls per week with ET clients. Pacific Time clients work with the right cadence but full PT-only schedules don’t fit well.

Async-first by design. Roughly 80% of the work is written threat models, policy documents, questionnaire responses, code review comments. Calls are the exception, not the default.

Your engineering team is probably already global. If your engineers are in Lisbon, Tel Aviv, or Bangalore, adding Gothenburg to the mix is the smallest stretch.

Sample artifacts

Sample artifacts (AI security policy excerpt, monthly report excerpt, threat model review example) available on request.

Request samples →

Not ready to talk yet?

Free checklists, guides, and a sample assessment report. No call required.

Browse free resources →

Sounds like a fit?

A short call is usually enough to figure out whether this is what you need and what it would look like.