NIS2 and the EU AI Act: what actually applies since 2025
Few topics generate this much activity on this little clarity. So here is where things stand, without the drama — and without the deadlines that have long since moved.
NIS2 applies, with no transition period
The German NIS2 implementation act has been in force since 6 December 2025, with no transition period. It covers companies in 18 sectors from 50 employees upwards. The registration deadline with the BSI passed in July 2026; a substantial share of affected companies had not registered by then.
Whether you fall under it depends on your sector, not only on headcount. That is the first question worth answering before anyone talks about measures.
Under the AI Act, two obligations already bite
This is where most of the confusion sits, because the best-known deadline was postponed. In order:
AI literacy under Article 4 has applied since February 2025 — to every company using AI. No sector restriction, no minimum size. If you put an AI tool in your people’s hands, you have to make sure they can judge it.
Transparency obligations under Article 50 have applied since 2 August 2026. Where AI interacts with people or generates content, that has to be recognisable.
Obligations for high-risk systems, by contrast, were pushed to December 2027 by the Digital Omnibus of May 2026. That is the piece often passed along as “it has all been postponed” — it concerns only this one part.
What follows in practice
The uncomfortable part is rarely the technology. It is that nobody can say which AI tools are actually being used inside the company. Shadow IT is not a fringe security problem, it is the normal state: people already use whatever makes their work easier — just privately, unmonitored and, when it matters, with company data.
Three things you can settle without a large programme:
- Take inventory. Which AI tools are in use, who pays for them, what data goes into them? That is a question of days, not months.
- Provide one sanctioned path. As long as there is no approved tool, the private one stays in use. A secure, company-wide option solves more compliance problems than any policy document.
- Training and documentation. Both are required under Article 4 anyway — and both decide whether an automation gets accepted in day-to-day work.
I am not a lawyer and I do not give legal advice. What I do: set up automation and AI rollouts so they do not undercut these requirements — with documented data flows, clear access rules and training as a fixed part of the work, not an extra on the invoice.
Does this apply to you?
In 30 minutes we look together at how things actually stand at your company – free and with no obligation.