How the EU AI Act Changes Cybersecurity Obligations in 2026
Back to Expert Analysis
18 August 2026EU AI ActCybersecurityDORANIS2AI Governance

How the EU AI Act Changes Cybersecurity Obligations in 2026

The EU AI Act isn't just an AI regulation — it directly intersects with NIS2, DORA, and your existing cyber frameworks. Here's what changes.

The EU AI Act Is Not Just an AI Regulation

When most compliance teams hear "EU AI Act," they think of it as a separate workstream — something for the data science team to handle. That's a mistake. The EU AI Act (Regulation 2024/1689) directly intersects with NIS2, DORA, and your existing cybersecurity frameworks in ways that create new obligations for security teams.

Here's what changed in 2026 and what your organisation needs to do about it.

The 2026 Milestones That Matter

The EU AI Act has a phased implementation timeline. The milestones that became active in 2026 are significant:

  • February 2025 — Prohibited AI practices banned (social scoring, real-time biometric surveillance in public spaces, manipulation systems)
  • August 2025 — General-purpose AI (GPAI) model rules apply, including transparency and copyright obligations
  • August 2026 — High-risk AI system obligations fully apply

August 2026 is the critical date for most organisations. If you deploy or use AI systems classified as high-risk under Annex III of the Act, you are now subject to the full compliance regime.

High-Risk AI Systems: What's in Scope

Annex III lists the categories of high-risk AI systems. For organisations in sectors covered by NIS2 and CER, the relevant categories include:

  • Critical infrastructure management — AI used to manage or operate critical infrastructure (energy grids, water systems, transport networks)
  • Public administration — AI used in decisions affecting access to public services or benefits
  • Law enforcement — AI used for risk assessment, polygraphs, crime analytics
  • Border control — AI used for risk assessment of persons
  • Administration of justice — AI used to assist judicial authorities

If your organisation operates in any of these sectors and uses AI systems for operational decisions, you are likely in scope.

The Cybersecurity Intersection

This is where it gets complex. The EU AI Act imposes specific cybersecurity requirements on high-risk AI systems that overlap directly with NIS2:

Robustness and cybersecurity (Article 15): High-risk AI systems must be designed to be resilient against attempts by unauthorised third parties to alter their use, outputs, or performance. This is effectively a cybersecurity requirement for AI systems — and it sits on top of your existing NIS2 obligations.

Risk management system (Article 9): Providers of high-risk AI systems must establish a risk management system that is continuous and iterative throughout the system's lifecycle. This mirrors the risk management requirements under NIS2 but applies specifically to AI.

Incident reporting: The AI Act introduces its own incident reporting obligations for serious incidents involving high-risk AI systems. These must be reported to market surveillance authorities — creating a third reporting stream alongside NIS2 and CER.

DORA and AI: The Financial Sector Dimension

For organisations in the financial sector subject to DORA (Digital Operational Resilience Act), the AI Act adds another layer. DORA requires financial entities to manage ICT risks, including risks from third-party ICT providers. If those third-party providers use AI systems, the AI Act's obligations for providers flow through to your DORA third-party risk management obligations.

In practice, this means your DORA ICT third-party risk assessments now need to include an AI Act compliance check for any provider using high-risk AI systems in the services they deliver to you.

What Your Organisation Should Do Now

  1. 1.Conduct an AI inventory — identify all AI systems your organisation deploys or uses, and classify them against the EU AI Act's risk categories
  2. 2.Map the intersections — for each high-risk AI system, identify which other frameworks apply (NIS2, DORA, CER) and where the obligations overlap
  3. 3.Update your risk management framework — extend your existing NIS2/DORA risk management processes to cover AI-specific risks
  4. 4.Review third-party contracts — ensure your ICT and AI provider contracts include EU AI Act compliance representations
  5. 5.Establish AI incident reporting procedures — add AI Act incident reporting to your existing incident response playbooks

The organisations that get ahead of this are those that treat the EU AI Act as an extension of their existing cyber compliance programme, not a separate initiative.