AI for business · Regulation

NIS2 Directive — cybersecurity of essential and important entities

Requires companies in 18 sectors (energy, transport, health, digital infrastructure, manufacturing, food, waste, postal and more) to manage cyber risks and report incidents. In Slovenia implemented by ZInfV-1.

In forceEUCybersecurityDirective (EU) 2022/2555

What it means for AI

AI tools and AI suppliers are part of your ICT supply chain: include them in risk analysis, access control and incident response — e.g. what happens if staff paste confidential data into an external AI.

What you must do

  • Risk management measures (policies, supply-chain security, access control, encryption, backups, training).
  • Incident reporting: early warning within 24 h, notification within 72 h, final report within one month.
  • Management bodies approve the measures and are personally accountable.

Examples

A logistics company uses an AI route planner in the cloud

The provider is an ICT supplier: assess its security, availability and access to your data.

Key dates

  1. NIS2 enters into force.

  2. Transposition deadline for Member States.

Official sources
← All regulations

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.