# Innovaiden

> Innovaiden is a management consulting firm and agentic AI platform company whose forward-deployed engineers deliver engagements directly. Expert advisory in cybersecurity, M&A due diligence, cyber risk quantification, AI governance, and EU regulatory compliance (NIS2, DORA, EU AI Act) across the US and EU. Its platform, Innovaiden Create, puts specialist AI agents behind business functions with human approval gates on every consequential action.

Founded by Dritan Saliovski. We work with businesses from small teams to enterprise, including private equity firms, law firms, insurers, and regulated enterprises, to operationalize cybersecurity and AI governance as controls — not policy PDFs.

## Innovaiden Create (platform)

- AI agents in production behind business functions: intake, quoting, scheduling, reporting, screening, migrations
- Human-in-the-loop approval gates on every consequential action; end-to-end audit trail
- Evidence grading (Verified / Observed / Estimated / Hypothesis) with source and date on every data point
- Built and operated by forward-deployed engineers; first production release usually in weeks
- More than 50 applications in production; early access: https://create.innovaiden.com/coming-soon

## Services

- Cybersecurity consulting and assessments
- M&A and PE cybersecurity due diligence
- Cyber risk quantification (FAIR methodology)
- AI advisory and governance frameworks
- NIS2, DORA, and EU AI Act compliance
- Technology due diligence

## Core pages

- [Home](https://www.innovaiden.com/): Practitioner-led cybersecurity consulting, AI advisory, and M&A technology due diligence across the US and EU.
- [Services](https://www.innovaiden.com/services): Cybersecurity assessments, AI advisory, M&A due diligence, and regulatory compliance services.
- [Platform](https://www.innovaiden.com/platform): Innovaiden Create: the agentic AI platform where specialist agents run the small functions of a business inside applications Innovaiden builds and operates, with human approval gates on every consequential action. More than 50 applications in production. Early access at https://create.innovaiden.com/coming-soon.
- [Solutions](https://www.innovaiden.com/solutions): Solutions for private equity, law firms, insurers, technology companies, and regulated enterprises.
- [Methodology](https://www.innovaiden.com/methodology): The Innovaiden engagement method: anchor on your strategic objective, deal thesis, or investment mandate; mine external signal; connect findings across every workstream involved; translate the result for the audience that has to decide.
- [About](https://www.innovaiden.com/company/about): About Innovaiden — practitioner-led consulting firm and agentic AI delivery platform.
- [Careers](https://www.innovaiden.com/company/careers): Open roles at Innovaiden.
- [Insights](https://www.innovaiden.com/insights): Practitioner insights on cyber risk, AI governance, M&A due diligence, and EU regulatory compliance.
- [Newsletter](https://www.innovaiden.com/newsletter): Innovaiden newsletter — practitioner analysis on AI, cyber, and regulatory developments.
- [Subscribe](https://www.innovaiden.com/newsletter/subscribe): Subscribe to the Innovaiden newsletter.
- [Contact](https://www.innovaiden.com/contact): Contact Innovaiden — work with our advisory and delivery teams.
- [Request Demo](https://www.innovaiden.com/contact/demo): Request a platform demo.
- [Schedule Call](https://www.innovaiden.com/contact/schedule): Schedule a consultation call.
- [Privacy Policy](https://www.innovaiden.com/privacy-policy): Privacy policy.
- [City Commute Privacy Policy](https://www.innovaiden.com/privacy-policy-citycommute): City Commute Privacy Policy
- [City Commute — Terms of Use](https://www.innovaiden.com/citycommute-terms): City Commute — Terms of Use
- [Roots — Family Tree Privacy Policy](https://www.innovaiden.com/privacy-policy-roots): Roots — Family Tree Privacy Policy
- [Roots — Terms of Use & EULA](https://www.innovaiden.com/roots-terms): Roots — Terms of Use & EULA
- [Treat Map — iOS App Privacy Policy](https://www.innovaiden.com/privacy-policy-treatmap): Treat Map — iOS App Privacy Policy
- [Treat Map — Terms of Use & Community Guidelines](https://www.innovaiden.com/treatmap-terms): Treat Map — Terms of Use & Community Guidelines
- [CartPal — Family Shopping Assistant Privacy Policy](https://www.innovaiden.com/privacy-policy-cartpal): CartPal — Family Shopping Assistant Privacy Policy
- [Support | Innovaiden](https://www.innovaiden.com/app/mobile/support): Support | Innovaiden
- [Treat Map | Your neighborhood's trick-or-treat map](https://www.innovaiden.com/app/mobile/treatmap): Treat Map | Your neighborhood's trick-or-treat map
- [Roots | Your family's story, kept in the family](https://www.innovaiden.com/app/mobile/roots): Roots | Your family's story, kept in the family
- [City Commute | Stockholm transit, live](https://www.innovaiden.com/app/mobile/citycommute): City Commute | Stockholm transit, live
- [Cookie Policy](https://www.innovaiden.com/cookie-policy): Cookie policy.
- [Terms of Use](https://www.innovaiden.com/terms-of-use): Terms of use.
- [Security](https://www.innovaiden.com/security): Innovaiden security and compliance posture.
- [AI Workshop Dallas](https://www.innovaiden.com/workshop): Hands-on AI workshop — next edition in Dallas, end of September 2026.

## Insights

### Cyber Risk

- [MCP Server Security: The Protocol Connecting AI Agents to Your Infrastructure](https://www.innovaiden.com/insights/mcp-server-security-ai-agent-protocol): The Model Context Protocol connects AI agents to external tools. Real 2026 CVEs show the attack surface is already being exploited.
- [What Risk Committees Need to Know About AI Coding Tools](https://www.innovaiden.com/insights/ai-coding-tools-risk-committee-briefing): AI coding tools are adopted team by team, below committee line of sight. Three questions separate oversight from assurance.
- [From AI Principles to Proof of Control](https://www.innovaiden.com/insights/ai-principles-proof-of-control): Boards approved AI principles. The next 18 months are about proving those principles operate as controls. The gap is where regulatory risk sits.
- [When Your Coding Copilot Installs Malware: Securing AI in the SDLC](https://www.innovaiden.com/insights/ai-coding-tools-sdlc-security): RoguePilot, CamoLeak, and Comment-and-Control attacks prove AI coding tools are a live attack surface. A practical control set for development teams.
- [Three Questions Boards Should Ask About AI Agents](https://www.innovaiden.com/insights/board-questions-ai-agents): Most boards hear the AI productivity pitch but not the identity, permission, and accountability model underneath. Three questions surface the gap.
- [Three Convergence Points Reshaping Enterprise Security Intelligence](https://www.innovaiden.com/insights/ai-cybersecurity-regulation-convergence): AI agents, data governance, and regulatory enforcement are converging into a single challenge. Treating them separately creates blind spots.
- [You Cannot Secure AI Agents with Human-Era Identity Models](https://www.innovaiden.com/insights/ai-agent-identity-iam-security): Machine identities will outnumber human identities in most enterprises this year. 78% have no formal policies for AI identity lifecycle management.
- [The New Baseline: Why AI Changed What 'Secure Enough' Means](https://www.innovaiden.com/insights/security-baseline-ai-threat-landscape): AI-assisted attack tools find vulnerabilities faster than organizations can patch. Framework compliance alone no longer defines adequate security.
- [Project Glasswing and the New Baseline for Cybersecurity Assessment](https://www.innovaiden.com/insights/project-glasswing-cybersecurity-assessment-baseline): Project Glasswing resets the baseline for cybersecurity assessment. When AI finds 27-year-old flaws, traditional assessment methodologies need to catch up.
- [Claude Code Source Leak: When Your AI Vendor Becomes the Vulnerability](https://www.innovaiden.com/insights/claude-code-source-leak-ai-vendor-risk): Anthropic shipped Claude Code's complete source in a routine npm update. With tens of thousands of forks and exposed feature flags, AI vendor risk needs rethinking.
- [McKinsey Lilli Breach: Old Vulnerability, New AI Risk](https://www.innovaiden.com/insights/mckinsey-lilli-breach-enterprise-ai-security): A 1998-era SQL injection reportedly exposed McKinsey's AI platform Lilli. The vulnerability class is old. The consequences for enterprise AI are not.
- [AI-Powered Cyber Attacks in 2026: What Boards and CFOs Need to Act On](https://www.innovaiden.com/insights/ai-cyber-threats-2026-board-briefing): AI-powered attacks and deepfake fraud are the defining threats of 2026. A plain-language briefing for boards and CFOs, with the 12 controls that change the risk profile.
- [Cyber Insurance Underwriting: The Technical Assessment Gap](https://www.innovaiden.com/insights/cybersecurity-insurance-assessment-guide-underwriters): In our engagement experience, document-only reviews miss most material cyber risks. Technical validation is what closes the gap for underwriters.

### AI & Data

- [Data Questions to Ask Before Funding Your Next AI Initiative](https://www.innovaiden.com/insights/data-questions-before-funding-ai): Investment committees approve AI projects with a value case that ignores data risk. A short checklist prevents the post-mortem finding.
- [AI Governance as an Operating System, Not a Policy PDF](https://www.innovaiden.com/insights/ai-governance-runtime-controls): Most organizations have AI principles. Few have controls that execute at runtime. The gap between policy and enforcement is where incidents happen.
- [What Shadow AI Means for Your Risk Register](https://www.innovaiden.com/insights/shadow-ai-risk-register-governance): If your risk register treats AI as one line item under technology risk, it is out of date. Shadow AI touches four risk categories at once.
- [Before You Secure AI, Fix Your Data Map](https://www.innovaiden.com/insights/data-discovery-before-ai-deployment): Only 35% of organizations have full visibility into unstructured data. Without data discovery and classification, AI security controls have no foundation.
- [Shadow AI Is Already Inside Your Organization. Here Is How To Find It.](https://www.innovaiden.com/insights/shadow-ai-discovery-10-day-sprint): 78% of employees who use AI at work bring their own AI tools. Only 36% of organizations have governance policies. A 10-day sprint closes the gap.
- [Claude Mythos Preview: Anthropic Built Its Most Powerful Model and Chose Not to Release It](https://www.innovaiden.com/insights/claude-mythos-preview-withheld-frontier-model): Anthropic built Claude Mythos Preview and chose not to release it. The first frontier model withheld for cyber risk reshapes AI governance playbooks.
- [The End of Single-Vendor AI Stacks: Why Enterprises Need a Model Portfolio](https://www.innovaiden.com/insights/multi-model-ai-strategy-enterprise-portfolio): Single-vendor AI stacks create concentration risk enterprises don't yet see. A portfolio approach across cloud, open-source, and edge models is overdue.
- [Trust Shockwaves in AI Platforms: Why Vendor Risk Now Includes Political Exposure](https://www.innovaiden.com/insights/ai-vendor-trust-political-risk-due-diligence): AI platform loyalty can fracture overnight. The ChatGPT-Claude shift shows why vendor evaluation must now include political and reputational risk.
- [AI Data Governance: The Same Problem Enterprises Already Solved](https://www.innovaiden.com/insights/ai-data-governance-enterprise-guide): Enterprise AI data concerns mirror cloud migration fears of 2010-2016. The governance discipline is identical, only the processing engine changed.

### M&A Due Diligence

- [Your AI Story Is an Examinable Representation, and the Exam Year Ends 30 September](https://www.innovaiden.com/insights/sec-ai-washing-exam-priorities-private-equity): Nothing new landed this summer. The SEC has been examining the accuracy of AI representations all year, and the fiscal year closes on 30 September. That is the point.
- [CRA Exposure in M&A: A Proportionate Diligence Lens, Not a Conformity Audit](https://www.innovaiden.com/insights/cyber-resilience-act-ma-due-diligence-deal-teams): You do not need a full Cyber Resilience Act audit to diligence a product target. You need a few questions that read the room, a hypothesis formed from the tech and cyber work you are already doing, and the discipline to carry it into the SPA and the W&I tower.
- [Three Questions Investment Committees Should Ask About AI Risk](https://www.innovaiden.com/insights/investment-committee-questions-ai-risk): Investment committees see more AI-intensive deals every quarter, but the process was not built for the pattern. Three IC-level questions surface AI risk before the vote.
- [Sponsor Liability for Portfolio Cyber Failures: A Practitioner's Defense Playbook After Bain/PowerSchool](https://www.innovaiden.com/insights/pe-sponsor-cyber-liability-bain-powerschool): A US court let negligence claims against Bain Capital proceed for a portfolio company's breach. The cost of weak cyber diligence is no longer just a write-down, it's the sponsor named in the suit. The exposure attached to how the bid was conditioned.
- [AI Boom, Security Bust: How Deal Teams Should Diligence AI-Heavy Targets](https://www.innovaiden.com/insights/ai-diligence-pe-deal-teams): Deal teams are seeing more AI-intensive targets. The diligence process was not designed for agent sprawl, training data provenance, or vendor lock-in.
- [Cybersecurity Due Diligence for M&A: A Practitioner's Framework](https://www.innovaiden.com/insights/ultimate-guide-cybersecurity-due-diligence-ma): A three-tier framework for M&A cybersecurity due diligence - from 24-hour screening to post-close monitoring - with Expected Annual Loss quantification.
- [GenAI in Tech & Cyber Due Diligence: 10 Practical Uses That Don't Require You to Sacrifice Data Control](https://www.innovaiden.com/insights/genai-tech-cyber-due-diligence-ma): Practical GenAI applications for tech and cyber due diligence in M&A, with the governance controls that keep deal-confidential data protected.
- [How Cybersecurity Due Diligence Protects M&A Deal Value](https://www.innovaiden.com/insights/cybersecurity-due-diligence-protects-deal-value): In our middle-market engagements, material cybersecurity findings have typically driven 8-25% valuation adjustments. Here's how diligence informs deal structure and protects buyer ROI.
- [Five Technology Risks That Determine M&A Deal Outcomes](https://www.innovaiden.com/insights/top-technology-risks-ma-due-diligence): In our middle-market engagements, cybersecurity vulnerabilities, technical debt, privacy gaps, IP ambiguity, and integration complexity have reduced IRR by 8-12 points in affected transactions.
- [Digital Due Diligence in 24-72 Hours: The M&A Speed Advantage](https://www.innovaiden.com/insights/speed-matters-digital-due-diligence-ma): In our middle-market engagements, roughly 72% of quality deals have involved multiple bidders. External-only digital due diligence delivers comprehensive technology intelligence in 24-72 hours.
- [Cybersecurity Due Diligence in M&A: What PE Firms Miss Before Close](https://www.innovaiden.com/insights/cybersecurity-due-diligence-pe-firms): Most PE deal teams assess cybersecurity through questionnaires and limited-access reviews. Here's what that approach systematically misses, and why it matters at close.

### AI & Cybersecurity

- [The Models Broke Containment to Cheat a Test, and Breached a Real Company on the Way](https://www.innovaiden.com/insights/openai-models-broke-containment-hugging-face-breach): OpenAI's cyber-evaluation models escaped their sandbox through a zero-day, reached Hugging Face production, and stole the answer key to their own benchmark. The objective was in scope. Nothing else was.
- [Prompt Injection Now Cuts Both Ways: Two Weeks That Turned the AI You Deployed Into an Attack Surface](https://www.innovaiden.com/insights/prompt-injection-both-directions-ai-security-perimeter): Researchers tricked six AI browsers into leaking credentials; North Korea shipped malware that gaslights the AI doing the triage. Prompt injection now cuts both ways.
- [Regenerative Containment: The One Control That Turns the Exposure Window Into a Constant You Set](https://www.innovaiden.com/insights/regenerative-containment-keystone-blast-radius): If you cannot win every race, the goal shifts to surviving a loss. Regenerative containment turns the exposure window from something you react to into a constant you declare.
- [Washington Is Building the Patch-Absorption Layer the Velocity Gap Exposed](https://www.innovaiden.com/insights/executive-order-frontier-ai-cybersecurity-clearinghouse): The June 2 executive order builds a Treasury-run clearinghouse to coordinate vulnerability scanning and patch distribution: the absorption layer the Velocity Gap exposed.
- [The Vulnerability Lifecycle Is Collapsing on One Side. The Metric Executives Need Is the Velocity Gap.](https://www.innovaiden.com/insights/vulnerability-lifecycle-velocity-gap-executive-doctrine): Mythos-class AI went from withheld to publicly available in nine weeks. Discovery now runs at machine speed; remediation does not. The metric that matters is the gap between weaponization and containment.
- [AI Development Tooling: The Supply Chain Attack Your Security Team Is Not Watching](https://www.innovaiden.com/insights/ai-development-tooling-supply-chain-attacks): AI coding tools create bidirectional supply chain risk. The axios trojan and Claude Code leak hit the same day. Most security teams are not watching.
- [Agentic Attackers Are Here: What Mythos and Recent AI-Enabled Operations Mean for Your Threat Model](https://www.innovaiden.com/insights/agentic-attackers-ai-enabled-cyber-threats): AI models that exploit vulnerabilities autonomously are here. Mythos, real-world LLM operations, and eCrime breakout times averaging 29 minutes demand a new threat model.
- [Your Next Security Incident May Start in an AI Assistant, Not an Inbox](https://www.innovaiden.com/insights/ai-assistant-attack-surface-browser-risk): Browser AI assistants create high-value attack surfaces. The Chrome Gemini hijack shows why enterprises must rethink endpoint security for embedded AI.
- [Deploying AI Agents: A Security-First Implementation Framework](https://www.innovaiden.com/insights/ai-agent-deployment-security-framework): Only 29% of organizations are prepared to secure AI agent deployments. A six-domain framework for deploying agents with controls mapped to ISO 27001 and DORA.
- [AI Agents vs. Chatbots: What the Distinction Means for Your Security Posture](https://www.innovaiden.com/insights/ai-agents-vs-chatbots-security-posture): Most organizations treat AI agents and chatbots as the same security category. They are fundamentally different - and chatbot controls are not enough.
- [AI Agents in the Enterprise: Security Risks Boards Aren't Seeing Yet](https://www.innovaiden.com/insights/ai-agent-security-risks-enterprise): AI agent adoption is outpacing security infrastructure. Only 14.4% of organizations have full security approval for their entire agent fleet. A present risk boards are missing.

### Professional Services

- [Project Acorn and the Consulting Partnership Reset](https://www.innovaiden.com/insights/project-acorn-consulting-partnership-reset): McKinsey's Project Acorn shifts partner pay from cash toward equity: the clearest signal yet from MBB of a consulting partnership reset buyers must price in.
- [Why Consulting Firms Can't Align People, Services, and AI](https://www.innovaiden.com/insights/consulting-misalignment-people-services-ai): Large consulting firms have misaligned people, services, and technology. AI is making this fragmentation worse before it makes it better.
- [Consulting Firms Selling AI Transformation Can't Deliver It](https://www.innovaiden.com/insights/transformation-paradox-consulting-firms-ai): Every consulting firm has an AI strategy and AI partnerships. None has transformed its own delivery model - which is exactly what they sell to clients.
- [AI-Native Agencies vs. SaaS: The Future of Advisory](https://www.innovaiden.com/insights/ai-native-agencies-future-of-advisory): 88% of organizations use AI but only 28% see measurable transformation. The gap is not a technology problem - it's why AI-native agencies outperform SaaS.
- [The Consulting Pyramid Is Broken: What Replaces It](https://www.innovaiden.com/insights/professional-services-pyramid-broken): AI has automated junior analyst work faster than firms can redeploy. The consulting pyramid is under structural pressure - here's what replaces it.

### AI in Practice

- [From Copilots to Colleagues: What Computer-Use Agents Mean for Enterprise Operations](https://www.innovaiden.com/insights/copilots-to-colleagues-computer-use-agents): Computer-use agents that operate your desktop autonomously are here. The governance gap between copilots and autonomous colleagues is the next risk.
- [Seven Ways Business Leaders Are Using AI Agents Today](https://www.innovaiden.com/insights/seven-ai-agent-use-cases-business-leaders): AI agents are not a future capability. They are an operational tool that professionals and deal teams are using now to compress hours of skilled labor.
- [Getting Started with AI Agents: A Setup Guide for Business Professionals](https://www.innovaiden.com/insights/getting-started-ai-agents-setup-guide): You do not need a technical background to use an AI agent. A paid subscription, a desktop app, and twenty minutes. A step-by-step setup guide.
- [AI Agents for Business Leaders: What They Are and Why They Matter](https://www.innovaiden.com/insights/ai-agents-business-leaders-guide): The shift from AI that talks to AI that does is underway. A plain-language guide to what AI agents are, where the market stands, and why it matters.

### Regulatory Compliance

- [Brussels Stopped Treating AI Governance and Cyber Compliance as Two Programs](https://www.innovaiden.com/insights/eu-cybersecurity-ai-action-plan-nis2-enforcement): On 7 July the Commission published its Cybersecurity and AI Action Plan. On 8 July it asked the Court to fine four member states over NIS2. Read together, they set the direction.
- [The EU AI Act's August 2 High-Risk Deadline Just Moved. Here Is What Actually Comes Due.](https://www.innovaiden.com/insights/eu-ai-act-august-deadline-moved-digital-omnibus): The Digital Omnibus (final Council approval June 29) defers the AI Act's high-risk obligations to 2027 and 2028. But August 2 is not cancelled: transparency rules still land.
- [The Cyber Resilience Act's First Obligation Gate Is 90 Days Away. Most Smaller Product Companies Still Cannot Prove They Are Ready.](https://www.innovaiden.com/insights/cyber-resilience-act-readiness-smaller-product-companies): The CRA has been binding law since December 2024, but its obligations arrive in phases. This week the conformity-assessment machinery switched on. The first reporting deadline is 11 September 2026. For most smaller product companies the gap is not capability. It is evidence.
- [The EU's Single Entry Point Solves the Regulator's Problem. The Operator Still Needs a Crosswalk.](https://www.innovaiden.com/insights/eu-digital-omnibus-single-entry-point-crosswalk): The proposed Digital Omnibus Regulation would consolidate incident reporting into one ENISA-run portal. The proposal is still in negotiation, and the five underlying regimes do not go away. The work moves upstream, into the controls crosswalk.
- [The EU's High-Risk AI Filter: Inside the May 2026 Draft Guidelines](https://www.innovaiden.com/insights/eu-ai-act-draft-guidelines-high-risk-classification): On 19 May 2026 the European Commission published draft guidelines clarifying when an AI system is high-risk under Article 6. The exceptions are narrower than the market assumed.
- [Five Frameworks, One Vendor: How NIS2, DORA, CRA, the Revised CSA, and the EU AI Act Create Cross-Framework Exposure](https://www.innovaiden.com/insights/four-frameworks-one-vendor-eu-regulatory-exposure): NIS2, DORA, CRA, the revised CSA, and the EU AI Act each evaluate different dimensions of the same vendor. Running them as separate programs hides cross-framework exposure.
- [Sweden's Cybersecurity Act (2025:1506): NIS2 Is Now Law](https://www.innovaiden.com/insights/sweden-cybersecurity-act-2025-nis2): Sweden's Cybersecurity Act (SFS 2025:1506) entered into force on 15 January 2026, shifting cybersecurity obligations to entity-wide scope with explicit management accountability requirements and fines up to €10M.

## Optional

- [Full insights content (llms-full.txt)](https://www.innovaiden.com/llms-full.txt): Concatenated markdown of every published insight for deep-context retrieval.
- [Sitemap](https://www.innovaiden.com/sitemap.xml): Machine-readable index of all indexed URLs.
- [Per-insight markdown](https://www.innovaiden.com/insights/{slug}.md): Each insight is available as raw markdown by appending .md to its URL.

## Contact

- Website: https://www.innovaiden.com
- Insights hub: https://www.innovaiden.com/insights
- Contact: https://www.innovaiden.com/contact
- About: https://www.innovaiden.com/company/about
- Email: contact@innovaiden.com
