Compliance with regulatory frameworks such as NIS2, DORA, and the upcoming AI Act is becoming a strategic imperative for organizations that cannot be ignored. These regulations introduce stricter requirements for cyber risk management, the resilience of digital services, and the secure use of artificial intelligence, thereby significantly impacting the operations of entities in both the public and private sectors.
The NIS2 Directive expands the scope of entities subject to its requirements to include multiple sectors (public administration, energy, healthcare, transportation, and IT services) and introduces new obligations in the areas of:
The NIS2 Directive enters into force in all EU Member States and must be transposed into national legislation (in Slovakia through an amendment to Act No. 69/2018 Coll.).
DORA sets out obligations for financial market entities in the following areas:
DORA will take effect in January 2025 and is legally binding without the need for transposition.
The AI Act defines risk categories for AI systems (prohibited, high-risk, restricted, low-risk) and establishes obligations, particularly for high-risk AI:
For developers and users of AI technologies, this means the need to implement new compliance processes, conduct conformity assessments, and monitor the development and operation of algorithms.