Czech Institutefor AI and Data

We train companies in safe AI use and AI Act obligations. We only teach what we verify through our own security audits.

MANIFEST01 / 03

Every claim about AI is backed by a test. Every risk by a concrete analysis.

Knowledge for free. We publish guides and checklists without a paywall or registration.

No sponsor, no conflict. We do not accept money from companies we evaluate.

What CIAD does

We train your team.
From basics to expert.

Built on real audit findings, not slides from the internet.

  1. Foundation

    Safe AI use in non-technical teamsPractical habits for safe AI use in marketing, HR, operations and finance.

  2. Leadership

    AI and cybersecurity for leadershipA strategic framework for risks and their management by organisational leadership.

  3. Compliance

    Data governance and the AI Act in practiceGDPR and the AI Act as an operational framework, including ready-to-use internal AI rules.

  4. Technical

    Secure LLM deployment in internal processesA threat model and security standard for deploying LLMs in internal processes.

  5. Expert

    AI red team, simulated attackA structured attack against a production deployment, with remediation measures and outcome verification.

  6. Annual prevention programme

    Quarterly audit + continuityA quarterly audit, monthly briefing and continuity of prevention for regulated organisations.

What stays with the team.

We turn the programme into rules and habits that the organisation uses after the final workshop.

  1. Rules for every role

    Non-technical teams practise safe prompting and handling sensitive data. Leadership addresses accountability and decision-making. Technical roles receive a process for threat modelling, testing and secure LLM deployment.

  2. Evidence for the AI Act

    The output includes internal rules for AI use, attendance records and recommendations based on role and context of use. The organisation can then document how it ensures staff AI literacy under Article 4.

  3. Practice after training

    Follow-up coaching verifies what the team actually uses, where the rules fall short and what needs to change. The annual programme adds a quarterly audit and repeat training after changes to tools, people or processes.

EU REGULATION 2024/1689

The AI Act is in force. Obligations are phasing in.

It applies to every company that uses AI. The obligations target employers, not just developers.

  1. Prohibitions and AI literacy

    Unacceptable-risk practices are banned and organisations must ensure AI literacy of staff working with AI (Article 4).

  2. General-purpose AI

    Obligations for providers of general-purpose AI models and the penalty framework take effect.

  3. AI transparency

    Transparency rules, including labelling requirements for selected AI content, and other generally applicable parts of the regulation take effect.

  4. High-risk systems

    Following the political agreement on the AI Omnibus, obligations apply to stand-alone high-risk systems including biometrics, education and employment.

  5. Regulated products

    Obligations apply to high-risk AI embedded in regulated products such as robotics and industrial machinery.

How you will work with us.

Assessment

We map how the team actually uses AI and where risks arise. Scope and pricing follow an initial consultation.

Tailored programme

We build the training around real examples from your operations. From Foundation to Expert, in person and online.

Verification and coaching

After training, we measure what has taken hold. Follow-up coaching and internal AI rules that the team actually uses.

A security audit that has your back.

Websites, AI systems and data. Every finding includes evidence, severity and a remediation plan. Our training is built on these audits.

REQUEST AN AUDIT

Web & apps

Every vulnerability on the surface is a way in. OWASP Top 10, security headers and CSP, TLS configuration and the third-party supply chain.

AI & LLM systems

Prompt injection and jailbreak testing, RAG system security, risks in agentic loops, deepfakes and identity protection.

Databases & data

Injection vectors, authentication and access control, encryption at rest and in transit, and exposure of access credentials.

What we actually find.

E-commerce

A door nobody knew about

We found a WordPress plugin nobody had updated in two years. It provided access to customer orders, names, addresses and email addresses, without a single password.

Internal system

Accounting within anyone’s reach

The company’s internal system was accessible from the internet to anyone who knew the address. No restriction, no second factor. An open door to sensitive data for an attacker.

Email domain

An invoice nobody sent

The domain had no email protection configured. Anyone could send an invoice in the company’s name with a changed account number, and the recipient would not spot the forgery.

Independent institute. Proof over promotion.

Built on an auditable methodology. Every finding has evidence and a deadline, every fix is verified. No finding is closed blindly.

We do not accept money from companies we evaluate. We use the same methodology in our own audits that we teach. The institute is led by founder and director Zbyšek Chudoba.

6parallel AI auditors
×3multi-stage verification
0ties to vendors
FAQ

Frequently asked
questions about our work.

Who is subject to the AI literacy obligation under the AI Act?

Every organisation that uses AI. Article 4 has applied since February 2025 to both providers and deployers, and training must reflect staff roles and the context in which AI is used.

How does company AI training work?

We begin with an assessment and prepare a tailored programme from Foundation to Expert, in person and online. Follow-up coaching comes next. Scope and pricing follow an initial consultation.

Will the training also prepare us for an inspection?

Yes. The output includes training attendance records, internal AI rules and role-based recommendations. The organisation can then document how it meets the AI literacy obligation under Article 4 of the AI Act.

What does a CIAD security audit include?

Six phases: OSINT reconnaissance, the web layer (OWASP Top 10, TLS), databases, AI systems, an audit report with CVSS classification and a remediation plan, and a verification re-audit. The deliverable is a PDF report and a closure protocol.

What is AI security and why does it matter for companies?

Protection against prompt injection, hallucinations in RAG systems, model drift and deepfake threats. It reduces operational and reputational risk from AI deployment and provides verifiable evidence of security to customers and regulators.

What is the EU AI Act and how does it affect Czech organisations?

The EU legal framework for regulating AI. Czech companies most often act as deployers: they must classify systems by risk level, implement AI risk-management processes and maintain documentation. CIAD performs audit gap analyses of readiness.

How is CIAD different from security and consulting firms?

An independent audit institute that does not accept funding from vendors it audits. We present results as verifiable findings with CVSS classification, not generic recommendations. Our role is independent verification.

What training programmes does CIAD offer companies?

Six levels: safe AI use for non-technical teams, AI and cybersecurity for leadership, the AI Act in practice, secure LLM deployment, AI red team (simulated attack), and an annual prevention programme with quarterly audits.

How is CIAD funded?

From the founder’s own resources and revenue from commercial audits and training. It does not accept funding from AI technology vendors or entities it evaluates. Details: Conflicts of interest and funding (Czech).

What does the first step look like for a municipality or smaller organisation?

CIAD Snapshot is an entry audit with no system access, delivered within five days, with a score from 0 to 100 and a remediation plan. Scope and pricing follow an initial consultation. It can be followed by training or an annual prevention programme with quarterly verification.
CONTACT

Book training for your team.

Tell us what you need to cover, whether that is training for your team or an audit. We reply within two working days with a proposed next step. The first consultation is non binding and we price the work only once the scope is clear.

Office
Příčná 1892/4
110 00 Prague 1

WEEKLY NEWSLETTER

Non binding inquiry

A rough number is fine. Leave blank for an audit request.

What are you interested in