Topic cluster

NIS2 & AI: Article 21, supply chain, and board accountability

4 notes · last update July 13, 2026
Quick answer

NIS2 (in Poland: the amended Cybersecurity Act, in force from 3 April 2026) imposes Article 21 obligations on essential and important entities, including supply-chain security. AI vendor choice and where data is processed fall directly under these requirements, and management is personally accountable for negligence.

This cluster maps NIS2 onto concrete AI decisions, not generalities. We show how Article 21(2) translates into technical controls and the artifacts you must show an auditor; why a public cloud LLM is a problem under Article 21(1)(d) (supply chain, sub-processors, processing location); and what personal board accountability means after the Cybersecurity Act amendment. This is the one bridge siloed competitors don't build: lawyers write about obligations without architecture, vendors about deployments without the law. We connect the two, always linking “how to meet this on-prem”. Deadlines shift (self-identification, the Digital Omnibus package), we date and update our content. Start with the Article 21 mapping cheat sheet, then measure readiness with the checklist.

// notes in this topic

A technical note: one NIS2 article, one scenario. Does a ChatGPT Enterprise or Claude contract meet Article 21(1)(d)? Three areas where a standard public-cloud LLM relationship starts to drift from supply-chain compliance.

Frequently asked questions
Does NIS2 ban public cloud for AI?

It doesn't ban it, but it requires supply-chain risk management, you must document data location, sub-processors, and contractual clauses. For the most sensitive data, on-prem is often the simplest answer.

Who is responsible for compliance?

After the amendment, responsibility sits with management, the board must knowingly approve and oversee decisions (including the AI vendor).

Where do I start?

With an Article 21 map → controls → artifacts (we have a ready checklist) and a register of the AI systems in use (shadow AI).

Want to apply this to your case: architecture, compliance, and cost?

→ Book 30 min