NIS2 and AI flows

Regulation · NIS2

AI routes belong in the wider security and supply-chain picture

This guide connects NIS2 to a bounded set of AI-flow facts, policies and decisions. DUBSAR is designed to organise that evidence; it does not provide certification or legal advice.

In 30 seconds

How NIS2 relates to connected AI flows.

Question addressed
Which facts and decisions could support work on NIS2?
Next decision
Confirm the applicable scope with qualified people, then assemble the evidence for one defined system.
Declared limit
The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.

Current DUBSAR status

Evidence support, not automatic compliance

The applicable scope and obligations must be established by qualified people. DUBSAR supports a defined evidence perimeter and does not issue a legal or certification verdict.

NIS2 and AI flows

Start with the scope that actually applies

NIS2 is not an AI-specific regulation. For organisations in scope, AI services and gateways may still form part of the systems, suppliers, access paths and incidents covered by security risk management.

NIS2 and AI flows

Evidence the DUBSAR journey is designed to organise

DUBSAR is designed to make selected providers, routes, policy denials and decision-service failures visible as evidence for the organisation's wider security process.

  • AI provider and route inventory
  • Access and credential boundaries
  • Fail-closed and recovery evidence
  • Incident references and accountable owners

NIS2 and AI flows

Keep the legal and product boundary explicit

It does not determine whether an entity is in scope, run the full cyber-risk programme or perform statutory incident reporting. NIS2 obligations depend on each Member State's transposition and the national measures applicable to the organisation; the Directive should not be presented as UK law.

Use the resulting record as an input for qualified legal, security, compliance and audit work rather than as a self-issued verdict.

Frequently asked questions

What to know before going further.

Does DUBSAR certify compliance with NIS2?

No. It is designed to organise evidence and apply policies on connected flows, but it is not a certification body or legal adviser.

What can a DUBSAR record contribute to work on NIS2?

A bounded view of the connected system, route, policy, decisions and human review. Governance, people, contracts and wider organisational controls remain necessary.