For years, many organizations have treated cybersecurity and technology regulation as separate issues: protecting systems on one hand, complying with regulations on the other. That approach no longer works. By 2026, the conversation has shifted.. NIS2 and the AI Act They compel us to view security, data governance, oversight, and accountability as part of a single management agenda. And this particularly affects industry, large organizations, and entities operating in critical sectors or already incorporating artificial intelligence into processes, products, and decisions.
At DOK Summit, this intersection of cybersecurity, compliance, and competitiveness fits perfectly with one of the event’s priority tracks: the one aimed at decision-makers and institutions that need to respond to regulation, resilience, and technological sovereignty from a practical perspective..
NIS2: Cybersecurity is no longer just a technical issue
The The NIS2 Directive establishes a common European framework to raise the level of cybersecurity in the Union. Its logic is not limited to calling for “more protection”: it requires states to strengthen their capabilities, create response authorities and structures, and imposes risk management measures and incident reporting obligations on many entities. The directive was to be transposed by October 17, 2024, and its rules have applied since October 18, 2024.
What’s relevant for an organization is that NIS2 expands the scope This framework differs from the previous one. It generally covers medium and large entities in the sectors listed in its annexes, and distinguishes between essential and important entities. Highly critical sectors include energy, transport, banking, financial infrastructure, health, water, digital infrastructure, public administration, and space; it also includes other areas such as postal services, waste management, chemicals, food, manufacturing of certain critical products, and specific digital providers.
That means that Many organizations that previously viewed cybersecurity as an operational function now have to treat it as a matter of corporate governance.. NIS2 does not stop at the technical layer: it requires the adoption of risk management measures, consideration of the supply chain, vulnerability management, cyber hygiene or service continuity, and strengthens supervision and the sanctioning regime.
AI Act: Artificial intelligence enters a real regulatory phase
Something similar is happening with AI. The European Artificial Intelligence Regulation entered into force on 1 August 2024 and establishes a harmonised EU-wide framework based on risk level. Its approach distinguishes between prohibited uses, systems subject to transparency obligations, high-risk systems, and specific obligations for certain general-purpose models..
Here’s a key date to keep in mind: the regulation generally applies from August 2, 2026, but some parts have been in effect since before then. The prohibitions, definitions, and obligations regarding AI literacy have applied since February 2, 2025, and other provisions, including those related to governance, sanctions, and obligations for providers of general-purpose AI models, came into effect on August 2, 2025.
For organizations, the message is very clear: It’s no longer enough to simply “test AI tools.” We need to know what type of system is being used, what it’s used for, what risks it entails, and what obligations it triggers.. If AI is involved in sensitive areas—for example, employment, essential services, personnel evaluations, infrastructure, or decisions with significant impact—the conversation is no longer just about technology. It is also about law, organization, and reputation.
The most common blind spot: thinking that this only affects Legal or IT
One of the most frequent mistakes is compartmentalizing this conversation: NIS2 for cybersecurity, the AI Act for legal matters, and business on another front. But European regulation is pushing in precisely the opposite direction.. Both NIS2 and the AI Act require something similar: control, traceability, accountability, and oversight. These standards are not designed solely for specialists, but rather to compel organizations to mature their approach to technology governance..
For a management committee or an industrial organization, this translates into very specific questions. Do we know which critical systems depend on third parties? Do we have clear criteria for incident notification, response, and escalation? Have we identified which AI uses might fall into sensitive categories? Is there genuine human oversight? Can we demonstrate how certain technological decisions are made?
In the Basque Country, this is already a strategic conversation
In the Basque context, this conversation fits perfectly with the DOK Summit’s thesis: Competitiveness is no longer solely about efficiency, but about the ability to generate value from technology, data, and people, while maintaining security, compliance, and autonomy.. The event is defined as a space where industry, market, public sector and talent connect to address digital transformation from a practical and applied perspective.
That’s why talking about NIS2, AI Act and cybersecurity It’s not about inserting a legal note into the middle of the program. It’s about addressing a core part of the problem. The organizations that will compete best in the coming years will not only be those that adopt technology first, but those that know how to do so with greater discernment, resilience, and responsiveness.
What’s really at stake
In the end, NIS2 and the AI Act are not just new European regulations. They are a clear indication of where the market is headed. Security can no longer be treated as a marginal cost. And AI can no longer be deployed as a black box without clear accountability..
For many organizations, the immediate challenge won’t be “complying with everything” at once. It will be about starting to ask the right questions, prioritizing, and connecting management, technology, operations, and compliance in a single conversation.
And the sooner that conversation starts, the better.
Come and participate in DOK to get up-to-date and specialized information.
NIS2 and the AI Act make security and technology governance a matter of management.
The first requires strengthening risk management and incident reporting in critical sectors and relevant entities; the second introduces a European risk-based framework for the use and deployment of AI systems, with obligations that have already begun to be activated in phases.