Heldr insights

Rules change. You stay ahead.

Clear explanations and concrete actions on AI compliance, cybersecurity and governance. Written for SMBs.

Compliance radar6 min read

49% of surveyed employees use private AI for work. What is your business exposed to?

Almost half of employees in the Alert Online 2026 survey use private AI accounts for work. For SMBs, that is not an IT detail. It directly affects privacy, AI literacy and information security.

Read article

All insights

07
Compliance radar8 min read

The EU AI Act deadlines moved to 2027 and 2028. This is what changes

Rules for high-risk AI in areas such as employment now apply from 2 December 2027. For AI embedded in regulated products, the date is 2 August 2028. Other duties already apply.

Read article
Myth checked7 min read

No, using ChatGPT is not automatically prohibited under the AI Act

The tool is rarely the full risk story. Purpose, data, access and the decision it influences determine what you must control.

Read article
Figure explained9 min read

Most SMBs are not NIS2-ready. What does that mean in practice?

NIS2 is not a checklist for IT alone. Management, suppliers and incident response all need visible ownership.

Read article
5-minute check7 min read

Three signs your AI tool may count as high-risk

If AI influences access to work, finance or essential services, you need to investigate its classification before scaling it.

Read article
Behind the scenes8 min read

How the Heldr team builds an AI Compliance Scan in six weeks

From discovery to a prioritised action plan: this is how scattered AI use becomes one controlled picture.

Read article
Supply chain check8 min read

Your supplier's cyber gap can become your NIS2 problem

Critical suppliers need more than a contract. Know their access, dependencies and incident commitments.

Read article