AI for business · Regulation
NIS2 Directive — cybersecurity of essential and important entities
Requires companies in 18 sectors (energy, transport, health, digital infrastructure, manufacturing, food, waste, postal and more) to manage cyber risks and report incidents. In Slovenia implemented by ZInfV-1.
In forceEUCybersecurityDirective (EU) 2022/2555
What it means for AI
AI tools and AI suppliers are part of your ICT supply chain: include them in risk analysis, access control and incident response — e.g. what happens if staff paste confidential data into an external AI.
What you must do
- Risk management measures (policies, supply-chain security, access control, encryption, backups, training).
- Incident reporting: early warning within 24 h, notification within 72 h, final report within one month.
- Management bodies approve the measures and are personally accountable.
Examples
A logistics company uses an AI route planner in the cloud
The provider is an ICT supplier: assess its security, availability and access to your data.
Key dates
NIS2 enters into force.
Transposition deadline for Member States.
Official sources
Related regulations
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.