Logiciel Solutions Contact Us
Success Stories Tech News Contact Us
whitepaper

AI Security Under Regulation.

Article 15 of the EU AI Act, the accuracy, robustness and cybersecurity requirement, is the only security duty the Digital Omnibus moved, and it now bites on 2 December 2027. Nothing an attacker can reach moved with it. NIS2 has bound essential and important entities since transposition, DORA has applied to financial entities since January 2025, and GDPR Article 32 has required security of processing since 2018. Their clocks run in hours: four under DORA, twenty-four under NIS2, seventy-two for a personal data breach, each starting while an attacker may still be inside.

In depth

The Only Security Deadline That Moved Is The One Furthest Away.

01

Article 15 is the one security duty the delay touched.

It travels with the rest of the Annex III high-risk package to 2 December 2027 and Annex I to 2 August 2028, while general-purpose model cybersecurity duties have applied since August 2025, NIS2 since national transposition, DORA since January 2025 and Article 32 since 2018. A programme that waits for 2027 is not early on the AI Act, it is late on three regimes. It is also burning the one period in which test histories, access reviews and incident records could have accumulated.

In shortIt is also burning the one period in which test hist…
02

The clocks run in hours, not in quarters.

DORA wants initial notification within four hours of classifying an incident as major and no later than 24 from awareness, NIS2 wants an early warning inside 24 hours and fires on suspicion of malicious action rather than on proof, and the GDPR gives you 72 hours from awareness of a personal data breach. Enterprise contracts now routinely impose 24 or 48 hour windows that no regulator asks for, enforced at renewal by your counterparty. At roughly $1,100 an hour before containment, even the deliberation about whether to file is an expense.

In shortAt roughly $1,100 an hour before containment, even t…
03

Most incident runbooks assume something was copied out.

A poisoned retrieval corpus is an integrity event with nothing leaving the building, model inversion runs as thousands of ordinary queries with no single moment to timestamp, and a compromised agent credential is scoped only by a tool-call log you may never have kept. The GDPR definition covers alteration as well as disclosure, so a corpus changed to alter what your system tells customers about their own accounts can be notifiable with nothing exfiltrated at all. Settle in writing which AI events are notifiable and who makes that call, before the four hour clock is running.

In shortbefore the four hour clock is running
The detail

Three Clocks Already Running, And What Each One Asks You To Produce.

None of these instruments was drafted with AI in mind and all three reach it anyway. Read each as a clock plus an artefact: the moment the duty starts, and the record you have to produce while your responders are still working out what the model did.

Zone · 01

NIS2 at 24 hours

An AI system in the delivery path of an essential service falls under the Article 21 risk management measures like any other component, and the supply chain clause reaches the model provider, the inference host and the vector database. The early warning is due 24 hours after awareness, and a suspicion of malicious action is enough to start it, so this usually fires first.

Zone · 02

DORA at 4 hours

For an EU financial entity the model provider is an ICT third party: in the register of information, on DORA contract terms, with an exit plan that survives a withdrawn model version and testing scope that covers the service. Initial notification lands four hours after classification, which is no time at all to work out what an over-permissioned agent reached.

Zone · 03

GDPR at 72 hours

Article 32 asks for security proportionate to the risk and a process for regularly testing the effectiveness of the measures, which turns an adversarial evaluation suite into evidence you already owe. Article 22 adds a second bar, since an attacker who can alter the model, the corpus or the features can alter a decision that carries legal effect.

By the numbers

The figures that make it a board-level conversation.

4 hours
DORA initial notification once an ICT incident is classified as major
$6.07M
average cost of a model inversion incident, the costliest AI breach type recorded
$1,100
per hour a breach runs before it is contained, on the 2026 global average
Inside the report

What you'll take away.

01

Step 1 - Map each system to the regimes that already reach it

NIS2 entity status, DORA register entry, Article 22 decision path, signed contract windows, and whether the system sits inside your ISO/IEC 27001 or SOC 2 scope. One page per system, dated.

02

Step 2 - Put access control on weights, corpora and prompt logs

The finding IBM reports most often behind AI-related breaches, and it answers Article 32, NIS2 Article 21 and Article 15 in one move. Only 40 per cent of organisations do it today.

03

Step 3 - Log every tool call, retrieval and credential use

This is what bounds an incident inside a four hour window. Set retention against the longest obligation you carry, classify the log as sensitive, and switch it on well before you need to query it.

04

Step 4 - Write the AI incident classification rules early

Which events are significant under NIS2, major under DORA and notifiable under Article 33, who decides, and how the awareness timestamp is captured. Then rehearse it once against a real system.

Questions

Frequently asked.

Does the December 2027 delay cover our AI security obligations?

It covers one of them. Article 15 moved with the Annex III package, and nothing else did. General-purpose model cybersecurity duties applied from August 2025, NIS2 binds from national transposition, DORA from January 2025 and Article 32 from 2018. Three of those carry notification windows measured in hours.

What starts the notification clock when the compromised component is a model?

This is genuinely unsettled. The defensible reading follows the definitions: alteration counts as a personal data breach, so a poisoned corpus can be notifiable with nothing copied out. For model inversion, awareness often arrives through an evaluation result, which makes your test schedule the thing that starts the clock.

We are outside NIS2 and DORA, so how much of this reaches us?

Article 32 reaches any organisation processing personal data, and your customers reach you sooner than that. Enterprise security schedules now carry AI terms: no training on customer data, model providers disclosed as subprocessors, retention limits on prompt logs, and notification windows of 24 or 48 hours enforced at renewal.

Do ISO/IEC 27001 or SOC 2 already cover our AI systems?

Only if the scope statement names them. Assessors ask whether the model, the retrieval corpus and the prompt logs sit inside the boundary or shipped after it was written. A SOC 2 Type II covers an observation period, so a system brought into scope now produces a meaningful report several quarters out.

Where does this stop and your engineering reference start?

This paper is the obligation side: which duty applies, by when, and the artefact that satisfies it. AI Security: An Engineering Reference is the control catalogue, with a test against each control. AI Governance Under Regulation covers the same calendar from the accountability angle instead.

Who is this report written for?

CISOs, security assurance leads and general counsel who own the answer when a regulator, an auditor or a customer asks what happened and when you knew. It assumes you run AI in production already and need the clocks, the triggers and the evidence list rather than an introduction to the technology.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send AI Security Under Regulation straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Appropriate security gets judged after the incident, with the incident in view.

Bring one live AI system and we will map the regimes that already reach it, the windows you have signed, and the records you could actually produce this afternoon. Engineers, not account managers. SECTION 7 - FAQ - 5 to 8 questions

Book an AI security review