German Companies Face Complex Challenges Complying with NIS2 and EU AI Act
German companies face organizational and operational hurdles ensuring compliance with the EU's NIS2 cybersecurity directive and the AI Act's risk-based AI regulations.
- • Two-thirds of German companies subject to NIS2 were not registered for compliance as of March 2026.
- • NIS2 requires integrating cyber risk management beyond IT departments, involving critical process and decision-maker identification.
- • The EU AI Act enforces a risk-based approach requiring businesses to assess AI use and risks.
- • Companies face inefficiencies due to separate teams for each regulation and need a unified governance, risk, and compliance framework.
Key details
German businesses are grappling with significant compliance challenges following the introduction of the EU's NIS2 directive and the AI Act. NIS2 aims to bolster cybersecurity across sectors by targeting companies with at least 50 employees or annual revenues exceeding 10 million euros. However, as of March 2026, two-thirds of German companies subject to NIS2 had yet to register for compliance, highlighting widespread unpreparedness.
The directive demands a comprehensive approach integrating cyber risk management, incident reporting, and supply chain scrutiny. Complexity arises because these responsibilities extend beyond traditional IT departments, requiring companies to pinpoint critical processes, vital systems, and decision-makers to avoid compliance gaps.
Concurrently, the EU AI Act introduces a risk-based regulatory framework for artificial intelligence use, mandating that businesses assess AI implementation areas and evaluate associated risks. Challenges intensify as companies often establish separate teams for each regulation, resulting in duplicated efforts, inefficiencies, and communication hurdles.
Experts emphasize the necessity of a unified governance, risk, and compliance (GRC) strategy that links risks, regulatory obligations, and control mechanisms with clear responsibility assignments. Such integration transforms regulatory adherence from a one-time project into continuous, systematic management. This approach is pivotal in managing the operational and organizational complexities introduced by these overlapping frameworks.
The evolving regulatory landscape represents a fundamental shift for German enterprises, requiring cross-departmental collaboration and clear governance to maintain compliance. Businesses must develop robust inventories of affected processes and harmonize their compliance efforts to meet the stringent requirements of both NIS2 and the AI Act effectively.
This article was translated and synthesized from German sources, providing English-speaking readers with local perspectives.
Source articles (2)
Source comparison
Latest news
Bundesliga and Key International Football Matches Highlight September 4, 2026 Schedule
CDU Warns Against Coalition with AfD Following Sachsen-Anhalt Election Surge
Germany Leads EU Talks on Deportation Centers Outside the Union
Volkswagen Secures 2030 Restructuring Deal Amid Factory Uncertainties and Internal Struggles
Hamburg Housing Company's Solar Panel Rejection Sparks Climate Debate Amid Rising Corporate Climate Investments
AfD Leads in Sachsen-Anhalt Election Amidst Voter Concerns and Coalition Uncertainties
The top news stories in Germany
Delivered straight to your inbox each morning.