A stack-ranked program of ten practical controls for safely adopting third-party SaaS AI, Claude, Gemini, Bedrock, MCP servers, OSS LLMs, RAG, and agentic workflows across tech and non-tech functions — calibrated to the 02 Aug 2026 EU AI Act enforcement date.
HelloFresh is moving AI from pilots into the operating fabric of the company: code copilots in engineering, RAG-grounded knowledge bots for CX and Ops, agentic flows touching planning, fulfilment, and supplier comms. Every one of those use cases adds new attack surface that the existing AppSec, IAM, and DLP stack does not natively cover.
The risk concentration is not the model itself. It is the data flowing into prompts, the actions agents are authorised to take, and the identity, supply-chain, and trust assumptions baked into MCP tools and third-party SaaS connectors. The recent in-house Bedrock prompt-logging incident, the public CVE-2025-6514 affecting mcp-remote across 437k+ installs, and the live tool-poisoning research against MCPTox-tested clients all point to the same gap: AI traffic and agent identity are governance blind spots.
Ten controls, ranked by prerequisite ordering and risk-reduction-per-FTE-week. Tier 1 (#1–#3) is foundational and non-negotiable before scaling. Tier 2 (#4–#6) builds the technical chokepoints. Tier 3 (#7–#10) is data-architecture, supply-chain assurance, detection, and validation.
| # | Control | Risk | Effort | Residual | Owner | Primary mapping |
|---|
| Control | EU AI Act | ISO 42001 | ISO 27001 | NIST AI RMF | OWASP LLM10 | OWASP MCP10 | NIS2 | GDPR | PCI DSS |
|---|