Logo van Compass RM. Het meest betrouwbare data integratie en migratie platform
< Back to blogs
Managing AI agent NIS2 obligations

Managing AI agent NIS2 obligations: the honest overview for 2026

Managing AI agent NIS2 obligations starts with a realization most companies haven't reached yet: an agent that independently produces a decision based on company data already counts today as an information system under the Dutch Cybersecurity law. Not only once the EU AI Act tightens further in 2027. Already, now. That means logging across that system's entire lifecycle, a designated owner, and oversight a human can actually exercise. Exactly the three things missing from most self-built agents.

Episode 1 of this series described the hype around autonomous agents and touched briefly on NIS2 and the EU AI Act, with a promise to come back to it later. Episode 4 showed who pays the bill when an agent gets it wrong. This episode is that promise kept: a full explanation of what the law, today, already requires from a Dutch company running AI agents.

What does managing AI agent NIS2 obligations mean in practice?

NIS2 is European cybersecurity legislation, transposed into Dutch law as the Cyberbeveiligingswet. It targets "information systems": anything that processes data and does something with it inside an organization the law applies to. An AI agent that drafts a purchase recommendation, approves an invoice, or answers a customer question based on CRM data processes data and produces a decision from it. That makes it, legally speaking, just an information system like any other.

Compliance analysts at IAM vendor Corma draw that line explicitly: "an agent that processes data and produces decision-making output is, functionally, an information system under NIS2, whatever marketing calls it". Managing AI agent NIS2 obligations doesn't mean waiting for a separate "AI law" specifically about agents. The obligation already exists, tucked inside legislation that's been around for a while and is now being applied to software that didn't exist five years ago.

The AI agent hype rolls on, the industry admits the risk itself

The series so far has described the same pattern each time: everyone builds agents, shows off what they can do autonomously, and assumes the rest will sort itself out. That pattern continues unabated. This summer Google made Demis Hassabis chair of DeepMind and chief scientist of Alphabet, fully focused on what Hassabis himself calls "a pivotal moment in human history" (blog.google). xAI launched Grok Bot, agents with their own cloud computer that log into company tools themselves and only "surface" once something needs approval, exactly as described in episode 1.

What's new since that first episode: the builders themselves sound more cautious. In late July, an internal OpenAI test model escaped a sandboxed environment and reached Hugging Face's production systems. Sam Altman called it, in an extensive profile, "like a sci-fi story," and drew a hard line: "Getting AI safety right is more important than any company's momentum" (TIME, August 26, 2026). Chief scientist Jakub Pachocki put it this way: "For AI, you should expect the unexpected." That same month, more than 1,300 current and former employees of frontier AI companies signed a petition asking for mechanisms to slow model development when risks arise, and Senator Bernie Sanders publicly called on the major AI companies to pause.

That's not a reason to panic. It is a signal that even the parties arguing hardest for speed are now admitting something is missing between "it works" and "it's under control." That missing layer is exactly where legislation like NIS2 comes in.

What the EU AI Act does and doesn't require for AI agent NIS2 obligations

To be clear: the EU AI Act and NIS2 are two separate laws that overlap. A Dutch analysis by ActCheck sums it up concisely: "NIS2 and the EU AI Act overlap on cybersecurity, monitoring, and incident reporting" (ActCheck, May 7, 2026). An AI agent can therefore fall under both at once: as an AI system under the AI Act, and as an information system under NIS2.

The AI Act itself was delayed this year. The Digital Omnibus on AI, adopted by the European Parliament on June 16, 2026 and by the Council on June 29, 2026, pushed the heaviest obligations for high-risk systems (Annex III) to December 2, 2027, and for AI embedded in existing product legislation (Annex I) to August 2, 2028. What does already apply since August 2, 2026: transparency rules under Article 50, with an extension to December 2, 2026 for systems already on the market. Gibson Dunn sums it up for companies: "2 August 2026 remains a live compliance date," the later dates are "real headroom," not a reason to postpone compliance work.

Checking in again in early September, nothing about that timeline has changed since the previous episode. No new fine, no revised deadline, no tightened guideline. That calm AI Act timeline is exactly why companies think they still have time. That's true for the AI Act. It isn't true for NIS2, which runs independently of the AI Act.

Why an AI agent is already an information system

This is the part previous episodes deliberately kept short. Corma's analysis makes the connection most explicit: "Article 12 requires automatic logging of events over a system's lifetime. Article 14 requires that high-risk systems be designed so humans can effectively oversee them. Both are engineering and access-control requirements". For an AI agent, Article 12 means every action the agent performs must be recorded: what data it retrieved, what decision it made, when. Article 14 means there must be a human who can see that and intervene, not only after something has already been carried out.

There's a third provision at least as relevant, one that's stayed underexposed until now: Article 21(2), which mandates asset management and access policy. Corma draws the conclusion bluntly: "an undocumented agent holding production credentials is an asset management failure under that article, whatever else it is." That hits exactly the pattern that's come up repeatedly in this series: agents set up somewhere in a department, holding real credentials on real systems, without anyone registering them centrally.

That same research names a risk that now has a fixed term attached to it: the "orphaned AI agent." An agent whose responsible owner left the company long ago, or was never recorded in the first place, while its credentials remain active. The agent keeps running with valid access, and nobody can explain anymore why it has that access. Under NIS2, that's not just a security risk. It's a demonstrable compliance gap, exactly the kind of finding an audit gets stuck on.

Managing AI agent NIS2 obligations through the Cybersecurity law

On August 15, 2026, the Cybersecurity law, together with the Critical Entities Resilience Act, took definitive effect, replacing the old Network and Information Systems Security Act (NCSC). For a Dutch company, managing AI agent NIS2 obligations is no longer a future European concern, but a law that took effect three weeks ago.

The threshold sits at 50 or more employees, or €10 million or more in revenue, spread across eighteen designated sectors. Take a wholesaler with 60 employees and €12 million in revenue, purely as an example: that already falls within the Cbw threshold for regular operations. If that wholesaler deploys an AI agent that generates its own purchasing advice based on inventory data, that agent falls under the same obligations as any other information system in the company.

Oversight in the Netherlands is also fragmented. For the AI Act, the Netherlands chose multiple regulators instead of one central authority: the Rijksinspectie Digitale Infrastructuur (RDI) takes on a central role, while the Autoriteit Persoonsgegevens (the Dutch data protection authority) stays relevant whenever an agent touches automated decision-making. The RDI also drafted a bill outlining its own oversight duties under the AI Act, partly overlapping with its role under the Cbw for certain sectors. For a company that falls under both the AI Act and NIS2, this means concretely: two laws, two (partly) different regulators, and one AI agent that has to satisfy both.

How to actually get your AI agent NIS2 obligations in order

We're not against agents. Build as many as you want, in every department that benefits. This isn't about holding them back. It's about four steps most companies currently skip.

1. Assign an owner before the agent goes live

Don't figure out afterward who was responsible. Record in advance who manages the agent, and what happens to that responsibility once that person changes roles or leaves. That's exactly what prevents the orphaned-agent risk described above.

2. Build in logging from day one

Article 12 doesn't ask you to bolt on logging after something goes wrong. Every action, every data source, every moment the agent made a decision needs to be traceable from the very first day the agent runs.

3. Make sure a human can overrule it

Article 14 isn't about an employee who was informed once that an agent exists. It's about a human who can see what the agent is doing at any moment and intervene before an action becomes irreversible.

4. Validate before the agent acts, not after

This is where we've been for years, long before the word "agent" showed up on every slide. We already validate what moves between systems. For an AI agent, it's the same approach, applied to a new kind of requester: check first whether the data and the access rights are correct, only then pass it through. Build as many agents as you want. We handle the oversight and safety underneath.

The AI Act gives companies until 2027 to get used to the heaviest rules. NIS2 doesn't. How many of the AI agents running somewhere in your organization today could you actually account for to a regulator who shows up tomorrow?

Frequently Asked Questions

It's about what the agent does, not how advanced it is. A chatbot that only returns a standard answer is less risky than an agent that processes data itself and makes a decision from it. The moment a system does the latter, it counts as an information system, regardless of what it's called internally.

Yes, indirectly. NIS2 requires companies that fall under it to also manage risk at their suppliers (Article 21). If you supply systems or services to such a company, you can still be asked how your AI agent handles their data, even if you stay under the threshold yourself. The question shifts from "does this apply to me" to "can I show my customer this can be trusted."

Yes. Whether the agent was built by a Dutch party or runs inside an American or other foreign SaaS tool makes no difference under the law. You're the entity that falls under the Cbw and lets the agent operate within your processes, so you need to be able to show that logging and oversight are arranged, even if the underlying technology isn't yours.

Start with a simple question to every department: which AI agent or automated tool have you switched on yourselves in the past twelve months, and who can still change its credentials? Often it turns out nobody's sure, and that's exactly the signal. Treat any agent nobody can immediately name an owner for as orphaned until proven otherwise.

The Cybersecurity law gives the regulator the power to impose corrective measures and fines, and as we described in episode 4, directors can also be held personally liable in cases of demonstrable failure. An AI agent that doesn't comply is therefore a compliance violation with a fine and a name attached to it, on top of the ordinary security risk.

Partly, but they're two separate tracks. GDPR governs the protection of personal data, NIS2 governs the security of the information system itself. An AI agent that processes customer data can fall under both: GDPR determines whether you're allowed to use that data and for what purpose, NIS2 determines whether the system around it is demonstrably secured and logged. Neither one replaces the other.

Yes. This is exactly what we already do: validate what moves between systems, record who has access to what, and make that traceable. For AI agents, it's the same approach, applied to a new kind of requester. Not a future plan, we set this up as a project, tailored to your systems and your agents.

Logo Compass RM het meest betrouwbare data integratie en migratie platform
Smart middleware for integrations, migrations and complex landscapes

Download de gratis checklist

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek of integraties jouw bedrijf kunnen helpen in de checklist.

Download gratis SCADA checklist

"*" indicates required fields

SCADA data integratie checklist

Download de gratis checklist

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek of integraties jouw bedrijf kunnen helpen in de checklist.

Download gratis ERP checklist

"*" indicates required fields

ERP data integratie checklist

Download de gratis checklist

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek of integraties jouw bedrijf kunnen helpen in de checklist.

Download gratis Finance checklist

"*" indicates required fields

Finance data integratie checklist

Download de gratis checklist

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek of integraties jouw bedrijf kunnen helpen in de checklist.

Download gratis asset management checklist

"*" indicates required fields

Assetmanagement data integratie checklist

Download de gratis checklist

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek of integraties jouw bedrijf kunnen helpen in de checklist.

Download gratis data integratie checklist

"*" indicates required fields

Gratis data integratie checklist

Download the free brochure

Manually transferring data is the biggest cause of costly errors that impact your customers and your profits.
The solution? Smart data integrations. 
👉🏻 Find out in the brochure..

The brochure for all your data integration en migration challenges from Compass RM

Download de gratis brochure

Het handmatig overzetten van data is de grootste oorzaak van kostbare fouten die je klanten en je winst beïnvloeden. 𝗗𝗲 𝗼𝗽𝗹𝗼𝘀𝘀𝗶𝗻𝗴? Slimme data integraties.
 👉🏻 Ontdek het in de brochure.

"*" indicates required fields

De brochure voor data integratie en migratie uitdagingen van Compass RM