AI for business · Regulation

Information Security Act — Slovenian NIS2

Transposes NIS2 into Slovenian law. Essential and important entities must register, manage cyber risks and report incidents.

Applies in phasesSLOCybersecurityOfficial Gazette RS 40/2025

What it means for AI

If you fall under ZInfV-1, AI tools belong in your risk assessment and supply-chain security — including rules on what data may go into external AI services.

What you must do

  • Self-registration of newly covered entities (deadline 19 Dec 2025).
  • Implement risk management measures within 18 months of entry into force (by 19 Dec 2026); earlier essential service operators within one year.
  • Report significant incidents to the national CSIRT.

Examples

A medium-sized food producer

Food production is a covered sector: check whether you are an important entity, register and complete the measures by December 2026.

Key dates

  1. ZInfV-1 enters into force.

  2. Deadline for self-registration of covered entities.

  3. Deadline to implement risk management measures (18 months).

Who supervises

Government Information Security Office (URSIV) and SI-CERT.

Official sources
Related regulations
← All regulations

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.