NIS2
NIS2 for AI: supply chain, incident reporting and management accountability
NIS2 (Directive (EU) 2022/2555) requires essential and important entities to manage cybersecurity risk, secure their supply chain and report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. AI agents with tool access, and AI vendors, sit inside that scope. National transposition differs, and four Member States were referred to the Court of Justice on 8 July 2026.
Who this applies to
- Essential and important entities
- Entities in the sectors listed in Annexes I and II, generally medium-size and above, under national transposition law.
- Management bodies
- Article 20 requires management bodies to approve and oversee the cybersecurity measures, and they can be held liable. They must follow training.
- Suppliers of covered entities
- AI vendors and platforms are not necessarily in scope themselves, but covered entities must manage supply-chain risk, so suppliers face customer requirements.
Status in October 2026
Source: Directive (EU) 2022/2555 for the text; secondary sources for transposition status.
- The transposition deadline was 17 October 2024.
- On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition, according to Hunton (secondary source).
- Trackers report that most Member States now have a national law in force, with counts differing by definition. National rules differ, so use the law of the Member State where you operate.
- In January 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act. Neither is adopted.
Article 21: the minimum risk-management measures
Measures must follow an all-hazards approach and include at least the following. For each, the right-hand column notes the AI angle.
| Article 21(2) | The measure | Where AI changes the picture |
|---|---|---|
| (a) | Policies on risk analysis and information system security | Add AI systems and agents to the asset and risk register. |
| (b) | Incident handling | Prompt injection, tool abuse and data exfiltration by an agent are incident scenarios. |
| (c) | Business continuity, backup, disaster recovery, crisis management | Model or vendor outage, fallback models, recovery of retrieval indexes. |
| (d) | Supply chain security | Model providers, hosting, sub-processors and open-source components. |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling | Model and agent updates, evaluation before release, dependency pinning. |
| (f) | Assess effectiveness of measures | Red-teaming and regression tests for agents. |
| (g) | Cyber hygiene and training | Staff training on safe use of AI tools; links to AI literacy under the AI Act. |
| (h) | Cryptography and encryption | Encryption of prompts, context and logs; key management. |
| (i) | HR security, access control, asset management | An identity and scoped permissions for every agent; least privilege. |
| (j) | Multi-factor or continuous authentication, secured communications | Strong authentication for people who approve agent actions. |
Article 21(3) adds that, for supply chain measures, entities consider each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development procedures.
Article 23: reporting significant incidents
| Clock | What is due |
|---|---|
| Within 24 hours of becoming aware | Early warning, indicating whether unlawful or malicious acts are suspected and whether there is cross-border impact. |
| Within 72 hours | Incident notification with an initial assessment and indicators of compromise where available, updating the early warning. |
| Within one month of the notification | Final report. An intermediate report may be requested. |
Reports go to the designated CSIRT or competent authority, and the definition of a significant incident and national reporting channels depend on national law. Entities must also inform recipients of their services where appropriate. For an agent incident, the practical challenge is reconstruction: what did the agent do, with which data, on whose authority, and when. See the blog post on NIS2 meets AI agents.
Management accountability and fines
Under Article 20 management bodies must approve the measures and oversee their implementation, and can be held liable. Under Article 34, Member States must set maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important entities, for breaches of Articles 21 or 23, whichever is higher. These are minimum ceilings, so national law may set higher ones.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| Art. 21(2)(i): access control and identity for every actor, including agents | Identity for every user, agent and workflow; permissions scoped per tool and data source. | Access and permission map per agent. | Identity, Access |
| Art. 21(2)(d) and 21(3): supply-chain security | Approved-model list in the Trust Profile; published sub-processor list; local models pinned to a revision and checksum-verified. | Approved-model register, sub-processor list, checksum records. | Policy, Security, Evidence |
| Art. 21(2)(b) and Art. 23: handle and report incidents | Live monitoring and a full action trace from data to model to agent to decision to action. | Reconstructable timeline with timestamps for the 24h and 72h reports. | Monitoring, Traceability, Auditability |
| Art. 21(2)(c): business continuity | A model gateway across 50+ LLMs so you can fail over between models. | Fallback configuration and tested switch-over records. | Policy, Security |
| Art. 21(2)(h): encryption | TLS 1.2 or later in transit (TLS 1.3 preferred); encryption at rest as described on the trust page. | Security overview; architecture description on request. | Security, Data controls |
| Art. 20: management oversight | Risk levels and thresholds that decide what needs approval, and dashboards of policy decisions. | Governance reports for the management body. | Risk, Monitoring, Evidence |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte does not determine whether you are an essential or important entity, or whether an incident is significant. That depends on national law.
- It does not file reports with your CSIRT or authority for you.
- It is not a 24/7 security operations centre. The trust page states that immutable audit logs and a 24/7 SOC are not claimed.
- It does not replace your own supply-chain assessment of Swfte or of the model providers you choose.
- Having these controls does not by itself meet your NIS2 duties. That is assessed against your national law and your whole estate.
Frequently asked questions
Does NIS2 apply to AI systems?
NIS2 applies to entities, not technologies. If you are an essential or important entity, the AI systems and agents you run are part of the network and information systems your Article 21 measures must cover, and AI vendors are part of your supply chain.
What are the NIS2 incident reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification (Article 23).
What are the NIS2 fines?
Member States must set maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher (Article 34).
Can management be held liable?
Yes. Article 20 requires management bodies to approve and oversee the measures, and they can be held liable for infringements. They must also follow cybersecurity training.
Has every Member State transposed NIS2?
No. The deadline was 17 October 2024. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026, per secondary sources. Check your national law.
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- Directive (EU) 2022/2555, NIS2 (EUR-Lex)
- Hunton: Commission refers four Member States to the CJEU over NIS2 transposition delays (Secondary.)
- Clifford Chance: EU cyber reforms proposed, including an overhauled Cybersecurity Act (Secondary; used for the January 2026 proposal.)
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.