AI Compliance

NIS2 and AI: What the Directive Requires of AI Systems and AI Vendors, and NIS2 vs the AI Act

NIS2 has no article about AI, yet an AI assistant or agent run by an essential or important entity is part of its network and information systems, and the company supplying it is part of its supply chain. This guide maps Articles 20, 21 and 23 onto AI, compares NIS2 with the EU AI Act, gives the transposition picture as of October 2026 and ends with a checklist.

NIS2 does not regulate AI as a technology, but it covers AI in practice. An AI system that an essential or important entity runs is part of its network and information systems, so the Article 21 risk measures, the Article 23 reporting deadlines of 24 hours, 72 hours and one month, and management accountability all apply to it, and AI vendors are assessed as suppliers.

What NIS2 requires of essential and important entities

The NIS2 Directive, Directive (EU) 2022/2555, applies to public and private entities of the types listed in its Annexes I and II that are at least medium-sized and operate in the EU, plus some entities regardless of size. The European Commission describes it as covering 18 critical sectors, including health, energy, transport and the public sector. Annex I entities above the medium-sized ceilings are essential entities; most others in scope are important entities. Member states had to transpose it by 17 October 2024 and apply their measures from 18 October 2024.

DutyArticleWhat it asks of the entity
GovernanceArt. 20The management body approves the cybersecurity risk-management measures, oversees them and can be held liable for breaches; its members must follow training
Risk measuresArt. 21(1) and (2)Appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, covering at least ten areas
Supply chainArt. 21(2)(d) and 21(3)Security in relationships with direct suppliers and service providers, weighing each supplier’s vulnerabilities, product quality and secure development
ReportingArt. 23For significant incidents: early warning within 24 hours, notification within 72 hours, final report no later than one month after the notification
FinesArt. 34For breaches of Art. 21 or 23, maximum fines of at least EUR 10 million or 2% of worldwide turnover (essential) and EUR 7 million or 1.4% (important), whichever is higher
Personal sanctionsArt. 32(5)For essential entities, authorities can seek a temporary ban on the chief executive or legal representative exercising managerial functions

Where AI systems sit inside NIS2

The Directive names artificial intelligence only twice, in recitals 51 and 89, and both times as a tool defenders may use to detect and prevent attacks, subject to data protection law. There is no AI article. What brings AI into scope is Article 21(1): the measures cover the network and information systems an entity uses for its operations or to provide its services. An assistant answering staff questions from internal documents, an agent that updates tickets, a model server on your GPUs, a vector index and the connectors between them all qualify. The table applies each of the ten minimum areas in Article 21(2) to them.

Article 21(2) areaWhat it means for an AI system
(a) Risk analysisAdd each AI system to the risk analysis, with AI-specific threats: prompt injection, data leaking through answers, poisoned retrieval data, unsafe tool use
(b) Incident handlingDefine what an AI incident looks like (an agent acting outside its permissions, confidential data in an answer, manipulated output) and route it through the normal process
(c) Business continuityDecide what happens when an AI service or model provider is unavailable, and keep a manual or local fallback for critical workflows
(d) Supply chainAssess AI vendors and model providers as direct suppliers (next section)
(e) Acquisition and maintenancePatch inference runtimes and AI plug-ins, track model versions through change management, handle vulnerabilities in AI components
(f) EffectivenessInclude AI systems in security testing and red-team exercises, and keep the results
(g) Hygiene and trainingTrain staff on AI misuse, such as pasting credentials or acting on unchecked output
(h) CryptographyEncrypt prompts, indexes and logs in transit and at rest
(i) Access and assetsKeep an AI inventory, give agents least-privilege service accounts and control who may use which agent
(j) AuthenticationPut multi-factor authentication on AI admin consoles and on AI tools that reach sensitive data

An AI incident has to be reported only if it is significant under Article 23(3): it has caused or could cause severe operational disruption or financial loss for the entity, or considerable material or non-material damage to others. If it is, the 24-hour, 72-hour and one-month clock applies to the CSIRT or competent authority. When the incident also involves personal data, a separate GDPR notification may be due, and Article 35 of NIS2 requires the competent authority to inform the data protection authority where an infringement may entail a personal data breach. A risk assessment for each AI system is the simplest way to show that point (a) covers AI.

AI vendors as a supply-chain risk

Article 21(3) asks entities to take into account the vulnerabilities specific to each direct supplier, the overall quality of its products and cybersecurity practices, and its secure development procedures. With AI the chain is longer than usual: the application vendor, the model provider behind it, the hosting or inference provider, their sub-processors, and the open-weight model files, plug-ins and MCP servers that arrive as components.

Implementing Regulation (EU) 2024/2690 of 17 October 2024 makes this concrete for DNS, cloud computing, data-centre, managed service and other digital providers. Its supply chain section asks them to select suppliers on their cybersecurity practices, their ability to meet the entity’s specifications, the quality and resilience of what they supply, and the entity’s ability to diversify sources and limit vendor lock-in. Contracts should then specify, where appropriate, security requirements, incident notification without undue delay, a right to audit or to receive audit reports, vulnerability handling, rules for subcontracting and duties at termination. ENISA published technical implementation guidance for these measures in June 2025. Other entities are not bound by that list, but it is a sound template for an AI contract. For AI, add questions on which model providers see your data, whether it trains models, how much notice you get before a model changes, and whether the workload could move to another model or run locally.

Some AI vendors are in scope themselves, for example as cloud computing or managed service providers listed in Annex I, so ask whether yours is registered as an essential or important entity and where. The 20-question vendor questionnaire in our template covers the rest.

NIS2 vs the AI Act

NIS2, Directive (EU) 2022/2555AI Act, Regulation (EU) 2024/1689
Legal formDirective, applied through national lawRegulation, applies directly
What it protectsSecurity of the network and information systems of essential and important entitiesHealth, safety and fundamental rights affected by AI systems and general-purpose AI models
Who carries dutiesEntities in the listed sectors, by type and sizeProviders, deployers, importers and distributors of AI systems; providers of general-purpose AI models
How risk is setAll-hazards, proportionate to exposure, size, likelihood and severityFixed classes: prohibited, high-risk (Annex I and Annex III), transparency duties, minimal
Security dutyTen minimum areas of measures (Art. 21)Accuracy, robustness and cybersecurity for high-risk AI, including data and model poisoning, adversarial examples and confidentiality attacks (Art. 15)
Incident reportingSignificant incidents: 24 hours, 72 hours, final report one month after notificationSerious incidents with high-risk AI: provider reports within 15 days, 10 days after a death, 2 days for a widespread infringement or serious and irreversible disruption of critical infrastructure (Art. 73)
Supply chainSupplier security is part of the entity’s measures (Art. 21(2)(d))High-risk providers need written agreements with suppliers of tools, services and components (Art. 25(4))
PeopleManagement body approves, oversees and can be liable; training is mandatory (Art. 20)Measures to support AI literacy (Art. 4); competent, trained human oversight for high-risk deployers (Art. 26(2))
Maximum finesAt least EUR 10 million or 2% (essential), EUR 7 million or 1.4% (important)Up to EUR 35 million or 7% for prohibited practices; EUR 15 million or 3% for most other duties; EUR 7.5 million or 1% for misleading information (Art. 99)
DatesApplies since 18 October 2024 through national lawProhibitions since 2 February 2025; Art. 50 since 2 August 2026; Annex III high-risk from 2 December 2027; Annex I from 2 August 2028

Critical infrastructure is where the two meet

Annex III point 2 of the AI Act makes AI high-risk when it is intended as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. The AI Act never cites NIS2: it defines critical infrastructure through the Critical Entities Resilience Directive, (EU) 2022/2557. Recital 55 adds that components intended solely for cybersecurity purposes do not count as safety components, so an AI tool that only detects intrusions is not high-risk on that ground. These systems are also exempt from the fundamental rights impact assessment in Article 27. For energy and utility operators, our NIS2 AI brief for critical infrastructure operators covers deployment inside segmented OT networks.

One incident, two or three clocks

An AI failure at an essential entity can be a significant incident under NIS2 and a serious incident under the AI Act at the same time. Under Article 26(5) of the AI Act, a deployer that identifies a serious incident must inform the provider immediately, and the provider reports to the market surveillance authority, while the NIS2 report goes to the CSIRT or competent authority. Add the GDPR’s 72-hour breach notice when personal data is involved, and keep one incident record that feeds all three.

The Cyber Resilience Act as a bridge

The Digital Omnibus on AI, Regulation (EU) 2026/1744, added Article 42(3) to the AI Act: high-risk AI systems within the scope of the Cyber Resilience Act that meet the conditions of its Article 12(1) are deemed to comply with the AI Act’s cybersecurity requirements. The Cyber Resilience Act’s reporting obligations for manufacturers have applied since 11 September 2026, and the rest of it applies from 11 December 2027, so ask vendors of AI products which route they follow.

Banks and insurers follow DORA

Article 4 of NIS2 gives way to sector-specific EU acts with at least equivalent requirements, and the Directive names DORA, Regulation (EU) 2022/2554, as that act for financial entities. For a bank or insurer, the ICT risk and incident rules for AI come from DORA.

NIS2 transposition status in October 2026

Most member states have transposed the Directive, but not all. The Commission sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025, and on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition, asking the Court for a lump sum and daily penalties (verified October 2026). Thresholds, competent authorities, registration deadlines and penalties are set nationally and vary by member state, so check the law in each country where you operate.

On 20 January 2026 the Commission also proposed targeted amendments to NIS2, alongside a proposed new Cybersecurity Act, to increase legal clarity and simplify compliance. Until an amending directive is adopted and transposed, the 2022 text and the national laws based on it are what apply.

NIS2 AI checklist

  • Every AI system, model server, vector index and AI connector is in the asset inventory with an owner (Art. 21(2)(i))
  • AI-specific threats are in the risk analysis: prompt injection, data leakage, poisoning, unsafe tool use (a)
  • The incident process defines AI incidents and maps them to NIS2 significance, AI Act serious incidents and GDPR breaches (b, Art. 23)
  • Critical workflows have a fallback if an AI service or model provider is unavailable (c)
  • Each AI vendor and model provider is assessed as a direct supplier, with incident notice, audit and exit terms in the contract (d)
  • Model versions, inference runtimes and AI plug-ins go through patching and change management (e)
  • AI systems are included in security testing and red-team exercises (f)
  • Staff training covers AI misuse, and management body training covers AI risk (g, Art. 20(2))
  • Prompts, indexes and logs are encrypted in transit and at rest (h)
  • Agents run on least-privilege accounts with role-based access, and AI admin consoles require MFA (i, j)
  • AI system logs reach the security operations team in time for a 24-hour early warning
  • The management body has approved the measures that cover AI (Art. 20(1))
  • The national law, competent authority and CSIRT are identified for each member state you operate in

For the reporting work itself, the NIS2 compliance and reporting use case shows how evidence from GRC, SIEM and ticketing systems can be gathered for notifications, and the AI incident response agent keeps an outage timeline current and drafts updates for approval, which is the raw material for the 72-hour notification and the final report.

How VDF AI fits

VDF AI runs assistants and agents inside your own perimeter, on-premises, in a private cloud or fully air-gapped, and network egress can be disabled. For those workloads no external inference provider joins your supplier list, and segmented or OT-adjacent zones keep their boundaries. Updates for air-gapped sites arrive as signed artifacts that your team inspects and installs from an internal registry.

Role-based access control is included on every plan, tools are granted per role through the MCP gateway registry, and consequential agent actions can wait for human approval. Every prompt, retrieval, model route, tool call, response and approval is logged with the actor and time and can stream to your SIEM, which supports detection, incident timelines and post-incident review. The trust center lists the evidence security reviewers usually request. These controls support your Article 21 measures; the measures, and the accountability for them, remain yours.

Sources

Frequently asked questions

Does NIS2 apply to AI?

Yes, indirectly. NIS2 regulates entities, not technologies, and mentions artificial intelligence only in two recitals. But when an essential or important entity uses an AI assistant, agent or model server in its operations or services, that system is part of its network and information systems. The Article 21 risk-management measures, the Article 23 incident reporting duties and the management accountability in Article 20 therefore cover it, and the company supplying it is assessed as a supplier.

What is the difference between NIS2 and the EU AI Act?

NIS2 is a directive about the cybersecurity of essential and important entities in 18 sectors, applied through national law since October 2024. The AI Act is a regulation about the risks AI systems pose to health, safety and fundamental rights, applied directly and in phases. NIS2 asks an entity to secure all its systems, AI included; the AI Act sets duties by risk class for whoever provides or deploys an AI system. An entity can be subject to both for the same system.

Is an AI vendor a supplier under NIS2?

Yes, if it supplies an AI service or product that an in-scope entity relies on. Article 21(2)(d) makes supply chain security part of the entity's own measures, and Article 21(3) asks it to weigh each direct supplier's vulnerabilities, product quality and secure development practices. Some AI vendors are also in scope themselves, for example as cloud computing or managed service providers, which brings detailed supplier rules under Implementing Regulation (EU) 2024/2690.

Do AI incidents have to be reported under NIS2?

Only when they are significant. Article 23 defines a significant incident as one that has caused or could cause severe operational disruption or financial loss for the entity, or considerable damage to others. An AI incident that meets that test follows the usual clock: an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after the notification. The same event can also be an AI Act serious incident or a GDPR personal data breach.

Is AI used in critical infrastructure high-risk under the EU AI Act?

Only some of it. Annex III point 2 makes AI high-risk when it is intended as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. Recital 55 adds that components used solely for cybersecurity are not safety components. The obligations for these systems apply from 2 December 2027 under the Digital Omnibus, Regulation (EU) 2026/1744.

Has every EU country transposed NIS2?

No. Member states had until 17 October 2024. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition, asking for a lump sum and daily penalties. Most other member states have national laws in place, and the details, such as registration deadlines, authorities and penalties, vary between them, so check the law in each country where you operate.

Filed under
AI complianceAI securityEU AI Actcritical infrastructureregulated AIAI procurement
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading