← Back to overview

One compliance approach for NIS2 and the AI Act

Two major regulations hit Dutch SMEs the same year: the EU AI Act and the Cybersecurity Act (NIS2). Treated separately, they duplicate work. Treated as one track, they don't.

One compliance approach for NIS2 and the AI Act

Since August 2026, two regulatory tracks have been live for Dutch SMEs at once: the EU AI Act and the Dutch Cybersecurity Act (Cyberbeveiligingswet, the national implementation of NIS2). Most businesses treat them as two separate projects, run by two separate people, on two separate timelines. That's the expensive way to do it — the two laws overlap enough that one track covers most of both.

Short answer in 3 minutes: not sure whether NIS2, the AI Act or the GDPR applies to you? Take the free AI Compliance & Risk Scan — see your exposure per obligation immediately, with an honest report. No sales pitch.

Why treat them as one project?

NIS2 targets network and information security. The AI Act regulates how AI systems are built and used. Different subjects, but the same underlying question for an SME: which systems and data do we depend on, and are we handling them responsibly? Answer that once and you've done most of the groundwork for both laws — running them separately means doing that inventory, and training your team, twice.

Where the requirements actually meet

How to actually run the combined approach

Start with a single risk analysis that covers both laws at once, rather than two separate assessments. Our NIS2 checklist for SMEs is a fast way to see which parts of NIS2 need attention; pair that with an AI inventory and you'll see exactly where the two overlap in your organisation. From there, build the shared policy and shared training around what you actually found — not a generic template.

Getting the right people in the room matters as much as the framework. Policy owners, IT, and the operational managers who actually use AI tools day to day need to work from the same document, not three different interpretations of it.

Don't wait to start

The NIS2 deadline has already passed and the AI Act's transparency obligations are live now, not upcoming. The organisations behind on both are the ones that started separately, then discovered the duplication halfway through. Start with the free compliance scan to see where you stand on both, then build one plan instead of two.

Take the free AI Compliance & Risk Scan