NIS2 and EU AI Act for security teams — what's required and how sovereign AI helps

Two European regulations now converge on cybersecurity teams deploying AI: NIS2 governs security operations; the EU AI Act governs the AI system itself. If you deploy AI for cybersecurity in the EU, both apply — and sovereign architecture addresses key requirements of each.

NIS2 — what security teams need to know

The Network and Information Security Directive 2 (NIS2) replaced the original NIS Directive in January 2023, with member-state transposition deadlines from October 2024. It dramatically expands scope, obligations and penalties for organisations operating in the EU.

  • Expanded scope: NIS2 covers "essential" entities (energy, transport, health, digital infrastructure) and "important" entities (manufacturing, food, chemicals, digital services). The scope is far broader than NIS1.
  • Incident reporting: 24-hour early warning, 72-hour incident notification, one-month final report. The timelines are strict and the reporting must include root cause and impact assessment.
  • Supply chain security: entities must assess and manage risks from their ICT suppliers and service providers. This includes AI vendors processing security data.
  • Board-level accountability: management bodies can be held personally liable for non-compliance. Cybersecurity is no longer delegable to the IT department alone.
  • Penalties: up to 2% of global annual revenue for essential entities, up to 1.4% for important entities. Administrative fines, not just corrective orders.

EU AI Act — what it means for AI in cybersecurity

The EU AI Act is the world's first comprehensive AI regulation. It takes a risk-based approach: the higher the risk the AI system poses, the stricter the obligations.

  • Risk-based classification: AI systems are classified as unacceptable risk (banned), high risk (strict obligations), limited risk (transparency requirements), or minimal risk (no specific obligations).
  • High-risk AI in critical infrastructure: AI used in critical infrastructure — which includes cybersecurity for essential entities — falls into the high-risk category, triggering full conformity obligations.
  • Transparency and documentation: high-risk AI systems require technical documentation, logging, human oversight mechanisms, and transparency about the system's capabilities and limitations.
  • Phased enforcement: prohibited practices from February 2025; high-risk obligations from August 2026; full enforcement by August 2027.

The intersection: when both apply at once

If you are an essential or important entity under NIS2 and you deploy AI for your cybersecurity operations, both regulations apply simultaneously:

  • NIS2 governs your security operations — incident reporting, supply chain risk, evidence retention, board accountability.
  • The EU AI Act governs the AI system you use for those operations — transparency, human oversight, accuracy, robustness, cybersecurity of the AI system itself.

The practical consequence: your AI cybersecurity vendor is now a supply chain risk under NIS2 and the AI system is a high-risk system under the AI Act. Both frameworks demand auditability, transparency and evidence. Choosing an AI vendor for cybersecurity is no longer a procurement decision alone — it is a compliance decision.

How sovereign architecture addresses both frameworks

A sovereign AI platform — one that runs on your infrastructure with zero data export — addresses key requirements of both NIS2 and the EU AI Act by architecture rather than by contractual promise:

  • Data residency (NIS2 supply chain): if your security data never leaves your infrastructure, the AI vendor is not a data processor and the supply chain risk is architecturally eliminated — not managed, eliminated.
  • Auditability (AI Act transparency): a non-repudiable audit trail — from human intent through model reasoning to action taken — provides the transparency and logging the AI Act requires for high-risk systems.
  • Governance runtime (AI Act high-risk): policy enforcement on every action, PII redaction, prompt-injection blocking, human oversight mechanisms — the technical controls the AI Act demands, enforced at runtime rather than documented in a policy PDF.
  • Identity (NIS2 evidence chain): every action bound to an accountable actor — non-repudiable, from human intent to automated action. When NIS2 requires incident evidence within 24 hours, the trail already exists.

How Monarch maps to NIS2 and the EU AI Act

Monarch is built at the intersection of these frameworks — not retrofitted to meet them:

  • 126 controls across 6 frameworks including NIS2, with CWE-mapped evidence and remediation guidance.
  • GDPR alignment by architecture — air-gapped deployment eliminates cross-border transfer; cloud deployments offer EU-region data residency.
  • Governance runtime for AI Act compliance — policy enforcement under 2ms on every action, PII redaction across 8 entity types, prompt-injection blocking across 20+ patterns, full audit logging. Applies identically to sovereign local models — no ungoverned path.
  • Full audit trail from human intent through model reasoning to action taken — non-repudiable, bound to verifiable identity, retained locally.

Built in Europe, tuned in Singapore. PDPA, GDPR, NIS2 and EU AI Act aligned.

Frequently asked questions

Does NIS2 apply to cybersecurity AI?

Yes. If you are an essential or important entity under NIS2 and you deploy AI for cybersecurity, the AI system is part of your security operations and falls within NIS2's scope for incident reporting, supply chain security and risk management.

When does the EU AI Act take effect?

The EU AI Act entered into force in August 2024 with phased enforcement. Prohibited AI practices applied from February 2025. High-risk AI system obligations — the category most relevant to cybersecurity — apply from August 2026. Full enforcement across all categories by August 2027.

How does sovereign deployment help with NIS2?

NIS2 requires supply chain security and incident evidence chains. Sovereign deployment eliminates the supply chain risk of sending security data to a third-party cloud. Air-gapped deployment goes further — zero data export means there is no cross-border transfer to assess, no third-party processor to audit, and a complete local evidence chain for incident reporting.

Does Monarch meet EU AI Act requirements?

Monarch's governance runtime — policy enforcement on every action, PII redaction, prompt-injection blocking, full audit logging, non-repudiable identity — provides the technical controls the AI Act requires for high-risk AI systems: transparency, human oversight, accuracy and cybersecurity. The specific compliance determination depends on the deployment context and the customer's risk classification.

NIS2 and EU AI Act — sovereign architecture addresses both.

Request a briefing