NIS2

NIS2 for AI: supply chain, incident reporting and management accountability

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to manage cybersecurity risk, secure their supply chain and report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. AI agents with tool access, and AI vendors, sit inside that scope. National transposition differs, and four Member States were referred to the Court of Justice on 8 July 2026.

sources

Who this applies to

Essential and important entities
Entities in the sectors listed in Annexes I and II, generally medium-size and above, under national transposition law.
Management bodies
Article 20 requires management bodies to approve and oversee the cybersecurity measures, and they can be held liable. They must follow training.
Suppliers of covered entities
AI vendors and platforms are not necessarily in scope themselves, but covered entities must manage supply-chain risk, so suppliers face customer requirements.

Status in October 2026

Source: Directive (EU) 2022/2555 for the text; secondary sources for transposition status.

  • The transposition deadline was 17 October 2024.
  • On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition, according to Hunton (secondary source).
  • Trackers report that most Member States now have a national law in force, with counts differing by definition. National rules differ, so use the law of the Member State where you operate.
  • In January 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act. Neither is adopted.

Article 21: the minimum risk-management measures

Measures must follow an all-hazards approach and include at least the following. For each, the right-hand column notes the AI angle.

Article 21(2)The measureWhere AI changes the picture
(a)Policies on risk analysis and information system securityAdd AI systems and agents to the asset and risk register.
(b)Incident handlingPrompt injection, tool abuse and data exfiltration by an agent are incident scenarios.
(c)Business continuity, backup, disaster recovery, crisis managementModel or vendor outage, fallback models, recovery of retrieval indexes.
(d)Supply chain securityModel providers, hosting, sub-processors and open-source components.
(e)Security in acquisition, development and maintenance, including vulnerability handlingModel and agent updates, evaluation before release, dependency pinning.
(f)Assess effectiveness of measuresRed-teaming and regression tests for agents.
(g)Cyber hygiene and trainingStaff training on safe use of AI tools; links to AI literacy under the AI Act.
(h)Cryptography and encryptionEncryption of prompts, context and logs; key management.
(i)HR security, access control, asset managementAn identity and scoped permissions for every agent; least privilege.
(j)Multi-factor or continuous authentication, secured communicationsStrong authentication for people who approve agent actions.

Article 21(3) adds that, for supply chain measures, entities consider each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development procedures.

Article 23: reporting significant incidents

ClockWhat is due
Within 24 hours of becoming awareEarly warning, indicating whether unlawful or malicious acts are suspected and whether there is cross-border impact.
Within 72 hoursIncident notification with an initial assessment and indicators of compromise where available, updating the early warning.
Within one month of the notificationFinal report. An intermediate report may be requested.

Reports go to the designated CSIRT or competent authority, and the definition of a significant incident and national reporting channels depend on national law. Entities must also inform recipients of their services where appropriate. For an agent incident, the practical challenge is reconstruction: what did the agent do, with which data, on whose authority, and when. See the blog post on NIS2 meets AI agents.

Management accountability and fines

Under Article 20 management bodies must approve the measures and oversee their implementation, and can be held liable. Under Article 34, Member States must set maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important entities, for breaches of Articles 21 or 23, whichever is higher. These are minimum ceilings, so national law may set higher ones.

How the platform supports it

Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.

RequirementPlatform controlEvidence artifactFabric facets
Art. 21(2)(i): access control and identity for every actor, including agentsIdentity for every user, agent and workflow; permissions scoped per tool and data source.Access and permission map per agent.Identity, Access
Art. 21(2)(d) and 21(3): supply-chain securityApproved-model list in the Trust Profile; published sub-processor list; local models pinned to a revision and checksum-verified.Approved-model register, sub-processor list, checksum records.Policy, Security, Evidence
Art. 21(2)(b) and Art. 23: handle and report incidentsLive monitoring and a full action trace from data to model to agent to decision to action.Reconstructable timeline with timestamps for the 24h and 72h reports.Monitoring, Traceability, Auditability
Art. 21(2)(c): business continuityA model gateway across 50+ LLMs so you can fail over between models.Fallback configuration and tested switch-over records.Policy, Security
Art. 21(2)(h): encryptionTLS 1.2 or later in transit (TLS 1.3 preferred); encryption at rest as described on the trust page.Security overview; architecture description on request.Security, Data controls
Art. 20: management oversightRisk levels and thresholds that decide what needs approval, and dashboards of policy decisions.Governance reports for the management body.Risk, Monitoring, Evidence

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

What this does not cover

  • Swfte does not determine whether you are an essential or important entity, or whether an incident is significant. That depends on national law.
  • It does not file reports with your CSIRT or authority for you.
  • It is not a 24/7 security operations centre. The trust page states that immutable audit logs and a 24/7 SOC are not claimed.
  • It does not replace your own supply-chain assessment of Swfte or of the model providers you choose.
  • Having these controls does not by itself meet your NIS2 duties. That is assessed against your national law and your whole estate.

Frequently asked questions

Does NIS2 apply to AI systems?

NIS2 applies to entities, not technologies. If you are an essential or important entity, the AI systems and agents you run are part of the network and information systems your Article 21 measures must cover, and AI vendors are part of your supply chain.

What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification (Article 23).

What are the NIS2 fines?

Member States must set maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher (Article 34).

Can management be held liable?

Yes. Article 20 requires management bodies to approve and oversee the measures, and they can be held liable for infringements. They must also follow cybersecurity training.

Has every Member State transposed NIS2?

No. The deadline was 17 October 2024. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026, per secondary sources. Check your national law.

Sources

Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build EU-first AI with the evidence already running

Start with one entry point. Add governance, in-region options and evidence as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.