Compliance

NIS2 and AI: what essential and important entities must show about their suppliers

NIS2 does not have an AI clause. It has a supply-chain security clause, and an AI supplier sits inside it like any other. Here is what that actually requires.

The short answer

NIS2, Directive (EU) 2022/2555, required EU member states to transpose it into national law by 17 October 2024, and it now governs cybersecurity risk management for a wide range of essential and important entities: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration and several other sectors. Its supply-chain security requirement means an in-scope entity has to assess the cybersecurity risk of each supplier and service provider it depends on, and an AI supplier is one such provider, not a special case with its own rules. In practice that means the same scrutiny applied to a cloud provider or a managed IT contractor: assessing the supplier's own security practices, understanding what data and access it has, and being able to account for it if an incident happens. NIS2 also carries strict incident reporting timelines, an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month, and penalties up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1.4% for important entities, whichever figure is higher in each case.

NIS2 does not mention AI. That is not a gap. Its supply-chain security requirement was written to be technology-neutral, which means an AI supplier already sits inside it, evaluated the same way as any other vendor with access to an entity's systems or data.

Who NIS2 actually covers

NIS2, Directive (EU) 2022/2555, required EU member states to transpose it into national law by 17 October 2024. It splits in-scope organisations into two tiers. Essential entities span energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, business-to-business ICT service management, public administration and space. Important entities span postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research organisations, among others. The split determines the penalty tier and how closely an entity is supervised, not whether the core obligations bind it.

Why an AI supplier is not a special case

NIS2's cybersecurity risk-management measures explicitly cover supply-chain security: an in-scope entity has to assess the risk posed by each supplier and service provider it depends on, including the security practices those suppliers themselves follow. Nothing in the directive carves AI out for separate treatment. An AI supplier is a supplier. The questions that apply to it are the same ones that apply to a cloud provider, a managed IT contractor or a payments processor:

  • What access does this supplier have to our systems or data, and is that access proportionate to what it actually needs.
  • What are the supplier's own security practices, and can the entity actually verify them rather than take them on trust.
  • If the supplier suffers an incident, how would the entity know, and how quickly.
  • Does the supplier itself depend on further suppliers the entity has no visibility into.
NIS2 was written to be technology-neutral on purpose. An AI supplier does not get a lighter question set because the underlying technology is newer.

The incident reporting clock

NIS2's timelines are tight and apply regardless of where an incident originates. A significant incident requires an early warning within 24 hours of the entity becoming aware of it, a fuller notification within 72 hours, and a final report within one month. If the incident originates at a supplier rather than in the entity's own systems, the clock does not pause to wait for the supplier to explain itself: the entity still has to notify on the same timeline, which means it needs to actually know what its AI supplier is doing with its access and data well enough to report on an incident quickly, not learn about it secondhand and scramble.

Where AI makes this harder in practice

The difficulty is not that NIS2 asks something new of AI suppliers. It is that AI systems are often harder to inspect than a conventional IT service: what data actually flows through a model, what the model does with it, and where the underlying infrastructure sits are not always answerable questions if the supplier's own systems are opaque. An AI system that runs on infrastructure the entity controls, or that produces a verifiable record of what it actually did with what data, gives the entity something concrete to point to when it has to answer NIS2's supply-chain questions honestly, rather than relying on a supplier's word.

What this means in practice

An essential or important entity bringing in an AI supplier should run the same supply-chain assessment it would run for any other vendor with meaningful access: proportionate access, verifiable security practices, a real answer to how quickly it would learn of a supplier-side incident, and a documented understanding of who else the supplier itself depends on. Penalties reach 10 million euros or 2% of global annual turnover for essential entities, and 7 million euros or 1.4% for important entities, whichever is higher in each case, for the entity that fails this, not for the supplier. That is the actual incentive to ask the questions properly before signing, not after an incident forces the question.

Questions readers ask

Who counts as an essential or important entity under NIS2?
NIS2 sets out two annexes of sectors. Essential entities include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, business-to-business ICT service management, public administration and space. Important entities include postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research organisations, among others. The distinction affects which penalty tier applies and the intensity of supervision, not whether the core obligations apply at all.
Does NIS2 have specific rules for AI suppliers?
No. NIS2's supply-chain security requirement is technology-neutral: an in-scope entity has to assess the cybersecurity risk posed by each supplier and service provider it relies on. An AI supplier is one such provider. It faces the same scrutiny as any other vendor with access to the entity's systems or data, not a separate AI-specific regime.
What are the actual incident reporting deadlines?
Three stages for a significant incident: an early warning within 24 hours of becoming aware of it, a more complete incident notification within 72 hours, and a final report within one month. These timelines apply regardless of whether the incident originated in the entity's own systems or in a supplier's, including an AI supplier's.
MICKAI®

Published by Mickai LTD. Written by Micky Irons.

Unified covers the field broadly and treats Mickai as one example within it. About the journal and the team.

Mickarle Wagstaff-Irons - Micky Irons, full name Mickarle Sean Junior Wagstaff-Irons. Founder and CEO of Mickai. Biography and related work.

Keep reading