German Companies Face Complex Challenges Complying with NIS2 and EU AI Act
German companies face organizational and operational hurdles ensuring compliance with the EU's NIS2 cybersecurity directive and the AI Act's risk-based AI regulations.
- • Two-thirds of German companies subject to NIS2 were not registered for compliance as of March 2026.
- • NIS2 requires integrating cyber risk management beyond IT departments, involving critical process and decision-maker identification.
- • The EU AI Act enforces a risk-based approach requiring businesses to assess AI use and risks.
- • Companies face inefficiencies due to separate teams for each regulation and need a unified governance, risk, and compliance framework.
Key details
German businesses are grappling with significant compliance challenges following the introduction of the EU's NIS2 directive and the AI Act. NIS2 aims to bolster cybersecurity across sectors by targeting companies with at least 50 employees or annual revenues exceeding 10 million euros. However, as of March 2026, two-thirds of German companies subject to NIS2 had yet to register for compliance, highlighting widespread unpreparedness.
The directive demands a comprehensive approach integrating cyber risk management, incident reporting, and supply chain scrutiny. Complexity arises because these responsibilities extend beyond traditional IT departments, requiring companies to pinpoint critical processes, vital systems, and decision-makers to avoid compliance gaps.
Concurrently, the EU AI Act introduces a risk-based regulatory framework for artificial intelligence use, mandating that businesses assess AI implementation areas and evaluate associated risks. Challenges intensify as companies often establish separate teams for each regulation, resulting in duplicated efforts, inefficiencies, and communication hurdles.
Experts emphasize the necessity of a unified governance, risk, and compliance (GRC) strategy that links risks, regulatory obligations, and control mechanisms with clear responsibility assignments. Such integration transforms regulatory adherence from a one-time project into continuous, systematic management. This approach is pivotal in managing the operational and organizational complexities introduced by these overlapping frameworks.
The evolving regulatory landscape represents a fundamental shift for German enterprises, requiring cross-departmental collaboration and clear governance to maintain compliance. Businesses must develop robust inventories of affected processes and harmonize their compliance efforts to meet the stringent requirements of both NIS2 and the AI Act effectively.
This article was translated and synthesized from German sources, providing English-speaking readers with local perspectives.
Source articles (2)
Source comparison
Latest news
Internal Strife Deepens in CDU Sachsen-Anhalt After Historic Election Loss
Berlin's 2026 Elections Mark a Milestone with Youth Engagement Amid Rising Political Discontent
German Court Rules Online Review Platforms Must Provide Evidence to Companies Challenging Negative Reviews
Germany Hits Historic Low in PISA 2025 with Declining Student Performance
International Students Fuel Germany's Economy and Labor Market Growth
Germany Faces Risk of Empty Gas Storages by February Amid Economic and Geopolitical Challenges
The top news stories in Germany
Delivered straight to your inbox each morning.