Jump to

Share

Regulations

AI solution surrounded by four shields labeled AI Act, NIS2, DORA, and GDPR

AI Act, NIS2, DORA and GDPR which requirements affect your AI solution?

How the AI Act, Cybersecurity Act/NIS2, DORA, and GDPR differ and what questions companies should ask about risk, data, suppliers, and responsibility.

AI Act, NIS2, DORA and GDPR – which requirements affect the company's AI solution?

The AI Act, NIS2 and DORA are often mentioned together, but they regulate different things. The AI Regulation focuses on risks and liabilities in AI systems. NIS2 and the Swedish Cybersecurity Act apply to cybersecurity in affected entities. DORA sets requirements for digital operational resilience in the financial sector. GDPR applies when personal data is processed.

A platform can provide technical support for authorization, logging and data control, but this does not automatically mean that the customer complies with the regulations. The actual use, the organization's role and the division of responsibility must be assessed.

Please note: The article provides an overview and is not legal advice. Regulations and guidance change. Last fact-checked on September 16, 2026, after the EU's digital omnibus regulation on AI entered into force.

Four regulations with different purposes

AI Act

The AI Act is risk-based and distinguishes between prohibited uses, high-risk systems, transparency requirements, and systems with low or minimal risk, among other things.[1][2]

NIS2 and the Cybersecurity Act

NIS2 and the Cybersecurity Act focus on risk management, security measures, management responsibility and incident reporting in essential and other affected sectors.[5]

DORA

DORA harmonizes requirements for digital operational resilience for financial entities, including ICT risk, incidents, testing and third-party risk.[7]

GDPR

GDPR regulates the processing of personal data and requires, among other things, a legal basis, purpose limitation, data minimization and appropriate security.[9]

The same solution can be covered by multiple regulations, but for different reasons.

Supporting a requirement is not the same as a customer automatically complying with the regulation.

AI Act: risk, transparency and responsibility

The AI Regulation, Regulation (EU) 2024/1689, entered into force on August 1, 2024 and is starting to apply gradually.[2] The timeline was amended in July 2026 by the digital omnibus regulation on AI, Regulation (EU) 2026/1744, which entered into force on July 27, 2026. The amendment, among other things, postpones the requirements for high-risk systems.[3][4]

This is what the timeline looks like after the amendment:[1][3][4]

  • February 2, 2025: The prohibitions against certain AI uses and the provision on AI literacy began to apply.

  • August 2, 2025: The rules for general purpose AI models (GPAI) and for governance began to apply.

  • August 2, 2026: The regulation began to apply generally, including the transparency rules in Article 50.

  • December 2, 2026: New prohibitions start applying to AI that generates intimate images without consent or material showing child sexual abuse. On the same date, the transitional period expires for machine-readable labeling of AI-generated content in generative systems that were on the market before August 2, 2026.

  • December 2, 2027: The requirements for high-risk systems under Annex III begin to apply, for example systems for recruitment, education, critical infrastructure and access to essential services. The previous date was August 2, 2026.

  • August 2, 2028: The requirements for high-risk systems that are part of products covered by EU product legislation under Annex I begin to apply. The previous date was August 2, 2027.

The postponement provides more time, but does not remove the requirements. Risk management, documentation and data quality take time to build up, so organizations planning systems that could become high-risk should start preparing now. Always check the current timeline and the legal text.

First, the organization needs to determine whether the solution is an AI system under the regulation and what role the organization has, such as provider or deployer. The use is then assessed.

Systems in recruitment, education, critical infrastructure and access to certain essential services, among others, can be high-risk depending on function and context. Requirements can include risk management, data quality, documentation, logging, user information, human oversight, robustness and cybersecurity.

The transparency rules have applied since August 2, 2026. They may require people to be informed when they interact with certain AI systems or when certain content is generated or manipulated.

AI literacy remains an organizational matter. Following the amendment, providers and deployers must take measures to support the development of AI literacy in their staff. The previous wording was that they should ensure a sufficient level as far as possible.[3] Staff still need relevant competence for their role.

AI assistant or AI agent – what is the difference?

NIS2 and the Swedish Cybersecurity Act

NIS2 has been implemented in Sweden through the Cybersecurity Act (2025:1506) and the Cybersecurity Ordinance (2025:1507), which have applied since January 15, 2026. Businesses in 18 sectors may be covered. The exact scope depends, among other things, on the sector and the size of the entity. The NCSC's guidance describes which entities are affected and what requirements apply to, among other things, notification, risk management and incident reporting.[5]

An AI solution becomes part of the organization's information and systems landscape. Relevant questions are therefore:

  • Is the solution part of an essential or critical process?

  • What supplier and cloud dependencies exist?

  • How are identity, vulnerabilities, continuity and backup managed?

  • Can incidents be detected, assessed and reported in time?

  • Are management's responsibility and follow-up clear?

ENISA published its NIS2 technical implementation guidance in June 2025. It is primarily aimed at digital infrastructure, ICT service management and digital providers, but can also help other organizations translate requirements into concrete controls. The organization needs to adapt the controls to its own risk profile.[6]

DORA for financial entities

DORA, Regulation (EU) 2022/2554, began to apply on January 17, 2025 and applies to the financial entities covered by the regulation. The focus is on ICT risk management, incident management, testing, information sharing and third-party risk. DORA also contains an oversight framework for critical ICT third-party service providers to the financial sector, such as large cloud providers.[7][8]

For an AI solution, a financial entity needs to assess whether it supports a critical or important function, which ICT third parties are involved and how continuity and exit can be ensured. A provider of a model via API can be part of a longer chain together with a platform, cloud and logging services.

Contracts need to provide sufficient information, access, security requirements and support for incidents and termination. DORA is not an AI regulation, but AI services used in the business are covered by the organization's ICT risk management.

Secure document analysis with AI in regulated activities

GDPR applies when personal data is processed

If prompts, documents, logs or outputs contain personal data, GDPR applies. The organization needs to define the purpose and legal basis, minimize data, ensure transparency and handle data subjects' rights.

Automated decisions with legal or similarly significant effects may trigger specific rules. A data protection impact assessment (DPIA) may be required when processing is likely to result in a high risk. IMY's guidance emphasizes that data protection must be integrated throughout the entire lifecycle.[9]

The GDPR assessment is separate from the AI Regulation's risk classification. A system can be low-risk under the AI Act but still process sensitive personal data.

In November 2025, the Commission proposed amendments to the GDPR in a separate digital omnibus package, including on the definition of personal data and on the use of data for AI development. The proposal has not yet been adopted, and for the time being GDPR applies in its current form.[10]

What happens to the company's data when you use AI?

What requirements should be placed on the platform and supplier?

  • Documented data flow, regions, retention periods and sub-processors.

  • Federated identity, least privilege and separated administrator roles.

  • Logging and traceability that support auditing without unnecessary personal data.

  • Version control for model, prompt, data sources and agent tools.

  • Testing of quality, robustness, cybersecurity and correct refusals.

  • Procedures for incident handling with contact channels, timeline and customer information.

  • Plan for continuity, backup and exit.

  • Documentation of the division of responsibilities between customer, platform and model provider.

Request evidence in the form of architecture, contracts and processes. Certifications can be relevant, but they do not replace an assessment of the actual solution.

Role-based AI with Microsoft Entra ID – how access works

Local language models or cloud models – how to choose?

Read more about security in Violet AI Platform

Documentation and responsibility

Create a register of use cases with purpose, owner, data, model, users, risk assessment and decisions. Document changes and test results. For high-risk systems, more extensive documentation may be required.

Management must understand risk and responsibility. The business owns the use, IT owns the systems landscape, information owners are responsible for data and security, and legal sets requirements and follows up. The supplier is responsible for the parts specified in the contract.

AI in the executive team: 10 questions that take you from idea to business value

When is a legal assessment needed?

Involve legal expertise and data protection competence when the solution affects individuals, processes sensitive personal data, is used in a regulated sector or may be covered by the rules for high-risk AI systems.

Perform the assessment before a pilot with real data, not after development.

Checklist questions:

  • What laws and sector rules apply to the organization and the process?

  • What role do we have under the AI Act?

  • Could the system be high-risk or subject to transparency requirements, and if so, from what date do the requirements apply?

  • Is personal data processed and is a DPIA required?

  • Is the entity covered by the Cybersecurity Act or DORA?

  • What risks are associated with third parties and transfers?

  • Who makes decisions regarding approval and changes?

From idea to pilot: what is PoC, prototype and pilot?

Sources

  1. European Commission, AI Act – regulatory framework for AI (updated August 3, 2026): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

  2. Regulation (EU) 2024/1689 (AI Act), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/swe

  3. Regulation (EU) 2026/1744 (digital omnibus regulation on AI), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2026/1744/oj/swe

  4. Council of the European Union, Artificial Intelligence: Council gives final green light to simplify and streamline rules (June 29, 2026): https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/

  5. Swedish National Cybersecurity Center, This is the Cybersecurity Act: https://www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/det-har-ar-cybersakerhetslagen/

  6. ENISA, NIS2 Technical Implementation Guidance (June 2025): https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance

  7. Regulation (EU) 2022/2554 (DORA), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2022/2554/oj/swe

  8. European Commission, Digital operational resilience – DORA: https://finance.ec.europa.eu/digital-finance/cyber-resilience_en

  9. Swedish Authority for Privacy Protection (IMY), Guidance on GDPR and AI: https://www.imy.se/verksamhet/dataskydd/innovationsportalen/vagledning-om-gdpr-och-ai/

  10. European Parliament, Legislative Train Schedule – Digital Omnibus Regulation Proposal: https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package

Ready to build your
AI capability?

Secure by default. Flexible by design.

Ready to build your
AI capability?

Secure by default. Flexible by design.

Ready to build your
AI capability?

Secure by default. Flexible by design.