Illuminate Risk Making AI risk visible. Book a discovery call
AI agent governance & AI security advisory

Adopt AI without inheriting its security risks.

Most organizations already have AI agents doing real work — and no map of what those agents can reach, what they can change, or who is accountable when one of them gets it wrong. We make that risk visible, then help you govern it.

Vendor-neutral. Assessment-first. No platform to sell you.

How we work

  • Vendor-neutral by design

    We do not resell a platform. The governance framework we write works with the agents and tooling you already run.

  • Assessment before commitment

    We start by finding out what is actually deployed. Clarity first, spend second — and you keep the findings either way.

  • AI-native delivery

    We run AI agents in our own operations, so the advice comes from hands-on practice rather than second-hand theory.

  • Built for the mid-market

    Scoped and priced for organizations without a dedicated AI governance function — not just the Fortune 100.

Services

Four ways we help — start with the one that matches your problem

Every engagement is fixed-fee and assessment-first. You get findings you can act on whether or not you hire us again.

Flagship engagement

AI Agent Governance Assessment

A structured engagement that answers three questions: what AI agents are running in your environment, what they can reach, and how you govern them.

Who it's for
Organizations that have deployed AI agents — or are about to — and have not mapped the access and accountability around them.
What you get
Agent inventory, access and permission map, risk register, a governance framework proposal, and a phased roadmap.
Engagement
Typically 2–3 weeks, fixed fee.
Discuss your situation

AI Security Posture Assessment

A broader look at exposure from LLM-based systems: what data is leaving through which models, prompt-injection exposure, AI supply-chain risk, and identity implications.

Who it's for
Organizations with wider AI adoption beyond agents — assistants rolled out company-wide, custom retrieval systems, AI-augmented internal tools.
What you get
A posture report with exposure areas ranked by risk, plus a prioritized remediation roadmap.
Engagement
Typically 2–3 weeks, scoped to your footprint.
Discuss your situation

Agent-Aware Detection & SIEM Gap Assessment

Where your current detection coverage stops and agentic activity begins — the behaviours your existing rules were never written to see.

Who it's for
Security operations teams that have introduced agents into an environment already monitored by a SIEM.
What you get
Detection coverage map, gap analysis, agent-specific detection use cases, and recommendations for extending coverage.
Engagement
Typically 1–2 weeks.
Discuss your situation

Agent & LLM Cost Audit

A fixed-fee audit of what your AI agents actually cost to run, and which calls are burning the budget. Model-selection waste is usually the finding — a small share of activity often accounts for most of the spend.

Who it's for
Engineering and platform teams running LLM agents in production without a clear view of unit economics.
What you get
A cost report covering spend by session, model and task type, with the specific changes that reduce it, plus a readout call.
Engagement
Fixed-fee engagement with a defined deliverable.
Discuss your situation

Not sure which applies? The discovery call exists to work that out — and if we're not the right fit, we'll say so and point you somewhere useful.

Why now

The governance gap is already open

AI agents arrived through the side door. A team enabled an assistant, a developer wired an agent into a repo, a business unit bought a tool with an API key nobody inventoried. The capability showed up faster than the controls did.

That leaves most organizations with agents that have real access and no governance: no inventory of what exists, no map of what each one can touch, no monitoring of what it actually does, and no plan for the day one of them is manipulated into doing something nobody intended.

You cannot govern what you cannot see. That is the whole reason this practice exists — and why the first deliverable of every engagement is a map, not a recommendation.

  • 94% of security leaders name AI as the most significant driver of change in cybersecurity this year. World Economic Forum, Global Cybersecurity Outlook 2026
  • 87% identify AI-related vulnerabilities as the fastest-growing cyber risk — up sharply year over year. World Economic Forum, Global Cybersecurity Outlook 2026
  • “Months, not years” is how the Five Eyes intelligence alliance describes the timeline for frontier AI to transform offensive cyber capability. Five Eyes joint statement, June 2026
About

A small, AI-native security practice

Illuminate Risk LLC pairs experienced cybersecurity judgement with an AI-augmented delivery model — a focused practice that uses the same class of agentic tooling it advises on, so the guidance comes from operating the technology rather than reading about it.

The work is deliberately narrow. We take on agent governance, AI security posture, detection coverage, and AI cost — engagements where a defined scope and a fixed fee produce a defensible answer. We do not sell a platform, and we are not trying to become your managed security provider.

Direct: hello@illuminaterisk.com

David Peach, founder

Engagement model
Fixed fee, assessment-first. You know the cost and the scope before anything starts.
Delivery
Senior judgement plus an AI-augmented delivery engine — the capacity of a larger practice without the overhead.
Coverage
Vendor-neutral and mid-market focused. We work with the agents and tooling you already run.
First step
A 25-minute discovery call. No proposal until we both know it is a fit.

Start with a conversation, not a proposal

Twenty-five minutes to describe what you have deployed and what is worrying you. You will leave with a clearer picture of the gap, whether or not we work together.