NIS2 is not an AI-specific law. But AI agents fall into its operational reality.

As soon as agent systems affect real processes, ownership, logging, incident paths, and supplier transparency start to matter.

2026-09-169 min read
Network of glass nodes inside a shield ring, one node pulsing

Short answer: what does NIS2 mean for AI agents in mid-market companies?

Germany: NIS2 implementation has applied since 6 December 2025. Section 33(1) BSIG requires registration within three months of first or renewed qualification as a covered entity or commencement of covered registry services. For critical facilities, subsection 2 refers to the KRITIS umbrella act. Applicability and special rules require separate assessment.

AI agents help with evidence and reporting deadlines, but must themselves be part of the risk analysis.

Weekly AI live calls are now embedded across the site.

Every Saturday at 11:00 Europe/Berlin, the format gives a compact mix of market filtering, practical cases, questions, and clear next steps.

Saturday, September 19, 2026 at 11:00 · Europe/Berlin1x per weekLive Q&A

Next session: Saturday, September 19, 2026 at 11:00 · Europe/Berlin. The series then continues on a weekly rhythm.

What this means in practice

For affected companies, the decisive question is not whether a system is marketed as AI. The real question is whether it becomes part of a critical ICT and process environment.

That makes documentation, ownership, security measures, and response capability highly relevant.

Four operational NIS2 questions for agent systems

These points should be answered before rollout.

Who owns the system?

There should be a named business owner and a named technical owner.

What is logged?

Relevant agent actions, data access, and approvals must remain traceable.

What is the incident path?

Errors, outages, or wrong decisions must not disappear into a blind spot.

Which vendors are involved?

The supply chain, subprocessors, and critical dependencies need to be visible.

Starting point

Begin with one concrete use case and test governance and evidence there first.

  • Describe the use case
  • Document involved systems
  • Define risk and approval thresholds
  • Set up logging and escalation

NIS2: scope and deadlines in Germany

Germany: NIS2 implementation has applied since 6 December 2025. Section 33(1) BSIG requires registration within three months of first or renewed qualification as a covered entity or commencement of covered registry services. For critical facilities, subsection 2 refers to the KRITIS umbrella act. Applicability and special rules require separate assessment.

Under section 28(2)(3) BSIG, the relevant entity type must have either at least 50 employees or annual turnover AND annual balance sheet totals each exceeding €10 million. This is not a complete applicability test: other entity types, thresholds, linked companies and exemptions may matter. Using AI alone does not create a NIS2 obligation.

Where section 32 BSIG applies, notification is required without undue delay after awareness of a significant incident: an early warning within 24 hours and an incident notification within 72 hours. The final report is due within one month of that incident notification. If the incident continues, a progress report is required instead, followed by a final report after handling is complete.

What NIS2 concretely requires from agent systems

For covered entities, sections 30 and 38 BSIG specify key requirements. These points do not replace a full applicability or controls assessment.

Risk management

Agents with access to CRM, ERP or e-mail belong in the risk analysis: access control, encryption, incident handling and business continuity must cover them.

Management responsibilities

Section 38 BSIG requires implementation and oversight of risk measures and regular training. Liability to the entity depends on culpably caused harm and applicable company-law rules; an incident does not automatically create personal liability.

Supply chain

Model providers, hosting and sub-processors of every agent must be documented and checked for security commitments.

Evidence

Section 30 BSIG requires documented, appropriate, proportionate and effective measures. Logs can support evidence but cannot replace risk analysis, security controls or rehearsed response procedures. They do not guarantee a successful audit.

Frequently asked questions on NIS2 and AI agents

Does my company fall under NIS2?

Under section 28(2)(3) BSIG, the relevant entity type must have either at least 50 employees or annual turnover AND annual balance sheet totals each exceeding €10 million. This is not a complete applicability test: other entity types, thresholds, linked companies and exemptions may matter. Using AI alone does not create a NIS2 obligation.

Is an AI agent an ICT system under NIS2?

At a covered entity, assess agent systems according to their role in the IT systems, components and processes used to provide services. System access alone does not replace assessment of statutory scope and exemptions.

What is the fastest first step?

Check registration status, name a business and a technical owner per agent system, and set up logging plus an escalation path. That is exactly what the NIS2 checklist covers.

Official sources for German NIS2 implementation

Checked on 16 September 2026. Entity type, special rules and the specific facts determine applicability. A reported grace period is not a statutory deadline extension.

Start potential analysis

If you want to prioritize a real process, a few clear inputs are enough for a strong first assessment.

WhatsApp Kai