NIS2, the EU AI Act, data protection rules and other digital regulations: Companies are not short on rules. What is often missing is the structure needed to manage them effectively.
With every new regulatory framework come additional requirements, deadlines and responsibilities. At the same time, companies are deploying more and more AI applications, often embedded in existing software for HR, customer service, marketing or document analysis. New regulatory requirements are therefore colliding with systems and processes whose use across the organization has not always been fully mapped.
In practice, many of these tasks end up with the same teams. Compliance has to assess regulatory requirements, technology teams implement the necessary measures, risk management evaluates the impact, and executive leadership needs to maintain an overall view. Many companies are only now beginning operational implementation. This is revealing that the challenge is not limited to the complexity of individual regulations. Their interaction is what is pushing existing organizational structures to their limits.
NIS2 Goes Far Beyond IT
With NIS2, the European Union aims to establish a high common level of cybersecurity. The directive applies to a defined group of companies, including organizations with annual revenue of €10 million or more or at least 50 employees. Affected sectors include energy, transportation, finance, healthcare, research and postal services, among others.
Cyber risk management, security incident reporting processes, supply chain risk considerations and greater accountability for management bodies must all be integrated into the organization. As of March, two-thirds of companies affected by NIS2 in Germany had not yet registered for the process.
Because of its complexity, NIS2 cannot simply be delegated to the IT department. Technical measures such as firewalls, backups and attack detection remain important. However, they do not address all of the organizational questions.
Companies need to know which processes are critical to business operations, which systems and external service providers those processes depend on, and who is responsible for which decisions when a security incident occurs. They also need to establish how incidents are communicated internally, assessed and reported within the required deadlines.
These interfaces are where gaps frequently emerge. IT understands the systems and technical dependencies. Risk management assesses potential business impacts. Compliance tracks regulatory obligations. If these areas operate separately and in isolation, the organization lacks a shared view of risks, measures and responsibilities.
Cybersecurity is therefore becoming less of a purely technical task and more of an enterprise-wide governance issue.
The AI Act Increases the Need for Coordination
At the same time, companies must translate the EU AI Act into their own processes. According to the European Commission, it is the first comprehensive legal framework for artificial intelligence. It follows a risk-based approach: The greater the risk an AI system poses to safety, health or fundamental rights, the more extensive the associated obligations.
In practice, implementation starts with a fundamental question: Where is artificial intelligence actually being used across the organization?
The answer is often more difficult than expected. AI is not limited to internally developed applications. It is also embedded in commercially purchased software. Procurement may know the vendor, the business unit may know the specific use case, and IT may control the technical access. Determining whether an application is subject to regulatory requirements, what risks it creates and what role the company has under the AI Act therefore requires cross-functional assessment.
When Every Regulation Gets Its Own Project
Many companies respond to new requirements by creating separate project teams. A NIS2 action plan is developed, a separate AI inventory is created for the AI Act, and additional control systems exist for data protection, information security or internal audit.
At first glance, this separation may seem manageable. As the number of regulations increases, however, it leads to duplicated work and coordination problems.
For example, regular access-right reviews may be relevant to NIS2, data protection, internal security policies and certain AI applications. If the same control is described, reviewed and documented separately for each regulatory framework, the workload increases without making the control itself more effective.
The real problem is not a lack of documentation. It is a lack of connections between the information that already exists.
From Inventory to Continuous Governance
The first step is a reliable inventory. Companies need to determine which legal entities, locations, processes, systems and service providers may fall under NIS2. For the AI Act, they also need a comprehensive inventory of AI applications already in use or planned.
The next step is to clearly assign responsibilities. For every material requirement, it should be clear who assesses it, who implements the necessary measures and who verifies their effectiveness. In practice, unclear responsibilities often mean that tasks are identified but not consistently completed.
Existing controls should then be consolidated. Areas such as access management, vendor assessments, data backups, business continuity or incident reporting do not need to be developed and documented from scratch for every regulatory framework. A single existing control can support multiple regulatory requirements, provided its design, ownership and effectiveness are clearly documented.
Only on this basis can meaningful reporting be established. Executive leadership does not need a list of every legal provision. It needs to see which material risks exist, which measures remain outstanding, where evidence is missing and where decisions are required.
This does not mean centralizing all responsibility in a single department. IT remains responsible for technical measures, business units for their processes and compliance for regulatory interpretation. What is needed, however, are shared terminology, consistent assessment criteria and clear handoffs between the teams involved. This allows individual areas to work independently without losing sight of the organization’s broader objectives.
Governance, Risk and Compliance, or GRC, provides an organizational framework for this approach. Risks, regulatory obligations, controls and responsibilities are not treated separately but systematically connected.
Compliance Becomes a Continuous Governance Task
NIS2 and the AI Act are therefore not initiatives that can simply be completed once and then checked off. Systems change, new service providers are added and business units introduce additional AI applications. At the same time, technical threats, standards and regulatory requirements continue to evolve.
Companies therefore need processes that continuously capture these changes. A new AI capability should not first come to light during an internal audit. Likewise, a change in cloud provider or a modification to a business-critical process needs to be reflected in risk and compliance assessments.
Treating NIS2 solely as an IT responsibility and the AI Act solely as a compliance issue simply shifts the complexity from one department to another.
The key is to connect regulatory requirements with existing processes, risks and controls. This can reduce duplicated work, clarify responsibilities and make audits easier to prepare for.
The bigger picture does not emerge from creating more and more lists. It emerges from a shared structure that allows new requirements to be integrated without starting from scratch every time a new regulatory framework comes along.