June 14, 2026 Regulation

NIS2 and High-Risk AI: Who Is Affected and Why?

By Thorsten Litzki · Litzki Systems LLC

tl;dr

Key takeaways

  • •  For high-risk AI operators, NIS2 is an additional layer of obligations on the same infrastructure.
  • •  Affected are financial service providers, healthcare, HR software, critical infrastructure and B2B SaaS providers with EU customers.
  • •  NIS2, the EU AI Act and sector regulation meet on the same infrastructure: three regimes, one surface.
  • •  The pressure is shifting away from paper policies toward robust technical evidence.

Thesis  The decisive question is: Can you prove it?

NIS2 is the EU's central directive for network and information security. For regulated companies with high-risk AI systems under the EU AI Act, it means an additional layer of obligations on the same infrastructure your AI runs on.

What the NIS2 directive aims to achieve

The NIS2 directive pursues three clearly defined goals:

  • Higher security level for critical and important entities across the entire EU
  • Binding minimum standards for technical and organizational protective measures
  • Uniform framework for reporting obligations for security incidents, with concrete deadlines

For you, this means: your digital infrastructure must maintain a demonstrable security standard at all times, one that can be proven to supervisory authorities and auditors. The pressure is shifting away from paper policies toward robust evidence of technical states.

Relevance for companies with high-risk AI systems

If you operate high-risk AI under the EU AI Act, several regimes meet on the same surface: NIS2, sector-specific regulation (for example financial supervision or health law) and the EU AI Act itself. Particularly affected are:

  • Financial service providers with AI-driven scoring, trading or monitoring systems
  • Healthcare institutions and health-tech with AI-driven diagnostics or triage
  • HR software providers with automated decision processes
  • Critical infrastructure operators with AI in control or monitoring chains
  • B2B SaaS providers with AI functionality for EU customers

For all these organizations, the same question keeps coming up: Can you prove it? This is exactly where a technical infrastructure evidence approach comes in that jointly addresses NIS2, DORA and the EU AI Act, for example through procedures described in NIS2 and DORA.

Key terms and the regulatory framework

Important and especially important entities

NIS2 distinguishes between categories of entities with graduated supervisory depth. Whether you count as important or especially important depends on sector, company size and the criticality of the services provided. For high-risk AI operators, this raises the expectation of formalized security and evidence processes.

Important entities
  • Reactive, downstream supervision
  • Fines up to €10 million or 2% of worldwide annual turnover
  • Sectors: HR platforms, SaaS, postal & courier, chemicals
  • Self-reporting and evidence obligation upon request
Especially important entities
  • Proactive, regular authority inspections
  • Fines up to €20 million or 4% of worldwide annual turnover
  • Sectors: banks, healthcare, energy, KRITIS
  • Ongoing evidence obligation without separate request

Network and information systems

NIS2 defines network and information systems as the entire technical infrastructure on which your services run. This includes hosting, network, DNS, identity and access management, logging, monitoring and the application stack on which your AI system operates in production.

Regulatory framework and interfaces

NIS2 interlocks with:

  • EU AI Act requirements for high-risk AI
  • Sector-specific regulation such as financial or health supervision
  • National implementation standards in Germany

For compliance teams, this makes it clear: you need machine-readable, reproducible evidence of the state of your infrastructure at the time of the audit. This is exactly where CERTavia delivers cryptographically verifiable infrastructure evidence that feeds into your NIS2 and AI Act dossier as a building block. More on this at CERTavia infrastructure evidence.

Target groups and scope of application of the NIS2 directive

NIS2 targets services of high societal and economic importance. For organizations with high-risk AI, this means you fall within scope via two axes: through your sector and through the criticality of your digital services.

The central question of every NIS2 audit: Can you prove it? The pressure is shifting from paper documents toward robust technical evidence of the infrastructure's state at the time of the audit.

Which companies typically fall under NIS2

NIS2 primarily addresses entities classified as important or especially important. Whether your organization belongs depends on:

  • the sector (for example financial markets, health, energy, transport, administration)
  • the role in the value chain (operator of critical services or essential digital platforms)
  • company size and the reach of your services

For AI-driven business models, this means: as soon as your platform or service becomes system-relevant for customers or infrastructure, you move into NIS2's focus.

Sector NIS2 classification Typical high-risk AI (Annex III)
Financial markets (banks, payment providers, insurers) Especially important Scoring, trading, automated credit decisions
Health (hospitals, labs, health-tech) Especially important Diagnostic AI, triage, image analysis
Critical infrastructure (energy, water, transport) Especially important Control AI, anomaly detection, monitoring
HR platforms (large, cross-sector) Important Candidate-selection AI, workforce planning
B2B SaaS for regulated customers Important (indirect) Depends on customers' AI use on the platform

Financial services

Banks, payment providers, insurers and marketplace platforms with AI-driven high-risk systems operate in a dual regime of financial supervision and NIS2. Concretely, this means:

  • Availability, integrity and traceability of the infrastructure are examined equally
  • Scoring, trading and decision systems need a documented infrastructure state at the time of the audit
  • DORA and NIS2 overlap heavily: shared technical evidence reduces duplicate effort

Healthcare

Hospitals, labs, telemedicine and health-tech providers with diagnostic or triage-related AI are particularly exposed. The central requirements:

  • Failure or compromise creates immediate patient risk. NIS2 classifies this as especially critical
  • Structured security measures must be demonstrably proven, beyond mere documentation
  • Networks and systems must maintain the protection level at the time of the audit. Retrospective statements fall short

HR software and high-risk AI

HR platforms with automated candidate selection or workforce planning fall into the high-risk classification via the EU AI Act. What this means for NIS2:

  • NIS2 applies as soon as the platform is classified as an essential digital service, especially when used in critical sectors
  • What is examined is how your infrastructure controls identities, access, logging and deployment of the AI models
  • Missing evidence on IAM and deployment paths is the most common audit finding

Critical infrastructure

Operators of critical infrastructure use AI for monitoring, anomaly detection or control. NIS2, sector-specific special laws and the EU AI Act are closely intertwined here:

  • Proof of a stable, correctly configured stack becomes an integral part of every audit
  • Sector-specific authorities (BSI, BNetzA, BaFin) expect consistent evidence from a single evidence set
  • A machine-readable infrastructure evidence via the Sovereign Validation Protocol reduces room for interpretation

B2B SaaS providers with AI functionality

B2B SaaS providers fall within NIS2 scope when their services function as essential digital services for regulated customers. The key implications:

  • If your customers operate high-risk AI on your platform, your infrastructure effectively becomes part of the audit scope
  • NIS2 significantly tightens requirements for suppliers and ICT third-party providers
  • Contractual assurances alone fall short: technical evidence of the infrastructure's state is expected

Delimitation and classification of high-risk AI systems

Whether a system counts as high-risk is determined primarily via the EU AI Act, in particular Annex III. In practice, a three-step approach has proven effective:

  1. Mapping AI systems by business process and impact on persons
  2. Comparison against the Annex III categories using a fixed set of criteria
  3. Assignment of the relevant infrastructure scope for NIS2, including hosting, network, IAM and logging

A structured quick check, such as the EU AI Act quick test offers, provides initial clarity here. Whoever performs this classification early can consistently map NIS2, DORA and AI Act requirements onto the same infrastructure evidence and maintain a single documentation world instead of three separate ones.

This is Part 1 of 2. Part two covers concrete obligations, implementation strategies and recommended actions:

Part 2: Obligations, implementation & recommended actions →
Check now

Can you prove NIS2 compliance?

CERTavia delivers machine-readable, cryptographically verifiable infrastructure evidence as a building block of your NIS2 and AI Act documentation.