NIS2 and the AI Act: where they overlap (and where they don't)
We already covered NIS2's 10 minimum cybersecurity measures. The natural question for any entity deploying AI is: if I already comply with NIS2, do I also comply with AI Act Art. 15 on the cybersecurity of high-risk AI systems? The short answer is "largely, but not entirely."

What NIS2 already gives you
The 10 categories in NIS2 Art. 21(2) — risk analysis, incident handling, business continuity, supply-chain security, encryption, access control, MFA, among others — build exactly the kind of cybersecurity risk-management infrastructure that AI Act Art. 15 also requires for high-risk AI systems: robustness, accuracy, and cybersecurity "throughout their lifecycle." If your entity is already an essential or important entity under NIS2 and has these measures in place, you're not starting from zero for the AI Act — you're starting from a solid base.
What NIS2 doesn't cover: AI-specific threats
AI Act Art. 15 goes beyond generic cybersecurity and requires resilience against third-party attempts to alter the system's use, outputs, or performance by exploiting its specific vulnerabilities. This includes three vectors NIS2 doesn't address, because they don't exist in traditional software:
- Data poisoning — manipulating the training set to introduce hidden biases or malicious behaviors.
- Model poisoning — compromising the model's parameters or fine-tuning process directly.
- Adversarial examples — inputs deliberately crafted to fool the model in production, altering its classification or decision without being obvious to a human eye.
None of these three vectors appears in NIS2 Art. 21's 10 categories — not because NIS2 is poorly designed, but because it was written for information systems in general, before generative AI models became widespread in critical processes.
The official bridge: the July 2026 Action Plan
The European Commission explicitly acknowledged this gap in its Cybersecurity and AI Action Plan, published in July 2026. The plan directly connects NIS2 and AI Act Art. 15 obligations, and guides regulated entities — especially those already obligated under NIS2 that also deploy high-risk AI systems — on how to extend their existing risk-management framework to cover AI-specific threats, rather than building two disconnected, parallel compliance programs.
What to do in practice
For an entity already subject to NIS2 that deploys or plans to deploy high-risk AI systems, the most efficient path is to extend the risk inventory and incident-management program it already has under NIS2, explicitly adding the three AI threat vectors as additional risk categories — not building a separate program from scratch. The supply chain (Art. 21 category 4) also needs specific review: a model or training-data vendor introduces attack surface that a traditional software vendor doesn't.
From NIS2 to the AI Act, without duplicating work
NIS2 Checklist for the cybersecurity base, and the AI Act Risk Classification Checklist to know if your system is high-risk and what Art. 15 adds.