NIS2 vs DORA vs AI Act and Which One Applies to You
NIS2 vs DORA vs AI Act reads like a contest, but the three regimes rarely fight over the same company. They ask three different questions. NIS2 asks which sector you operate in and whether you are big enough. DORA asks one thing only, whether you are a financial entity. The EU AI Act asks whether you build or use AI. Answer those three and you know which regime, or which stack of them, lands on your desk. If you want the short version first, you can run the three questions side by side in the comparison matrix before reading a single Article.
The regimes overlap in wording far more than in reach. Most of the confusion online comes from treating them as three fines waiting to hit every company at once. They are not. One of them can switch another off, at least in part, and where that happens is the part worth reading closely.
NIS2 vs DORA vs AI Act split companies three different ways
The three regimes sort companies by different tests, so a single company can fall under one of them, several, or none. NIS2 sorts by sector and size, DORA by whether you are a financial entity, and the AI Act by whether you build or use AI.
| Regulation | Who is covered | What triggers scope | When it applies | Scope Article |
|---|---|---|---|---|
| NIS2Directive (EU) 2022/2555 | Medium-sized and larger entities in 18 listed sectors, split into essential and important | Sector (Annex I or II) plus size (50+ staff, over €10m turnover or balance sheet) | Transposition deadline 17 October 2024, applied unevenly across Member States | Article 2 |
| DORARegulation (EU) 2022/2554 | 20 named types of financial entity, plus designated critical ICT providers | Being a financial entity, regardless of size | Applies since 17 January 2025 | Article 2 |
| AI ActRegulation (EU) 2024/1689 | Providers, deployers, importers and distributors of AI systems | Building or using AI, sorted by risk tier | Phased, standalone high-risk under Annex III from 2 December 2027 | Article 2 |
Reading down the table, the tests barely touch. The overlap they do produce is narrow and predictable, and it sits almost entirely in regulated finance that has moved into AI.
NIS2 asks which sector you are in and whether you clear the size line
NIS2 applies to entities in eighteen listed sectors that qualify as medium-sized or larger, per Article 2 of Directive (EU) 2022/2555. Sector first, size second. If you are not in one of the Annex I or Annex II sectors the headcount is irrelevant, and if you are in a sector but sit below the size line, you are usually out.
The Directive splits those in scope into essential and important entities, which sets both the supervision regime and the fine ceiling. Essential entities are the larger operators in the eleven high-criticality Annex I sectors, energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Important entities are most of the rest, including the seven Annex II sectors such as postal services, waste management, chemicals, food, manufacturing, digital providers and research. The size line runs off Commission Recommendation 2003/361/EC, so medium-sized means at least 50 staff or more than €10 million in turnover or balance sheet total.
Some entities are pulled in whatever their size, among them public electronic communications providers, trust service providers, DNS providers and the sole provider of a service in a Member State. National security, defence and law enforcement bodies are pushed out, per Article 2(7). If you want the answer for one company rather than the sector map, the NIS2 checker walks the Annex tests in order.
Two things make NIS2 slippery. It is a Directive, so the version that binds you is the one your Member State transposed, and transposition has been uneven. On 7 May 2025 the Commission sent reasoned opinions to nineteen Member States for failing to notify full transposition, with Germany only bringing its implementation law into force on 6 December 2025. The fines carry the same national colouring. The Directive sets floors of at least €10 million or 2% of worldwide turnover for essential entities and at least €7 million or 1.4% for important entities, but the figure that reaches you is the one written into your national law, not a single EU number. How often those ceilings become actual fines is a separate question, and the enforcement record across all eight EU frameworks is easier to track on one page than to assume.
DORA asks one question and it has nothing to do with your size
DORA applies to twenty named types of financial entity, regardless of headcount, per Article 2 of Regulation (EU) 2022/2554. A three-person crypto-asset service provider is as much in scope as a global bank. Size proportionality changes how much you do, not whether you are in.
The list runs from the obvious to the easily missed. Credit institutions, payment institutions, electronic money institutions, investment firms, insurers and reinsurers sit alongside crypto-asset service providers, central securities depositories, central counterparties, trade repositories, fund managers, credit rating agencies, crowdfunding service providers and administrators of critical benchmarks. DORA has applied since 17 January 2025, per Article 64. A separate track pulls in the technology firms these entities depend on. Under the oversight framework in Articles 31 to 44, the European Supervisory Authorities designated the first nineteen critical ICT third-party providers on 18 November 2025, a list that reaches past the hyperscalers into financial-data and services names like Bloomberg, LSEG Data and Risk and FIS.
Exclusions exist and they are specific rather than generous. Small alternative investment fund managers, occupational pension schemes with fifteen members or fewer in total, and insurance intermediaries that are micro, small or medium-sized enterprises fall outside, per Article 2(3). To see which parts of the resilience regime attach to your entity type, the DORA assessment maps the obligations against the Article 2 categories.
The AI Act asks whether you build or use AI, not what business you run
The AI Act applies by role and by risk tier, per Article 2 of Regulation (EU) 2024/1689. Your role, provider, deployer, importer or distributor, decides what you owe, and the tier of the system, prohibited, high-risk, general-purpose or limited, decides how heavy it is. Industry is almost beside the point. A hospital, a bank and a recruitment software vendor can all land in the same high-risk bracket for entirely different systems.
The obligations arrived in phases, and the phases moved. Prohibited practices under Article 5 have applied since 2 February 2025, and general-purpose AI model obligations since 2 August 2025. The high-risk dates are where the calendar shifted. The enacted text put standalone high-risk systems under Annex III at 2 August 2026, but the Digital Omnibus, which the Council gave its final green light on 29 June 2026, moved that to 2 December 2027, with product-embedded high-risk systems under Annex I following on 2 August 2028. If you are still working to the old August 2026 date, the figure your obligation runs from has changed under you.
Financial firms do not get a pass. Annex III names AI used to evaluate the creditworthiness of natural persons and AI used for pricing in life and health insurance as high-risk. The penalties scale with the breach, up to €35 million or 7% of worldwide turnover for the prohibited practices in Article 5, up to €15 million or 3% for most other obligations, and up to €7.5 million or 1% for supplying incorrect information, per Article 99. Before you assume a system is low-risk, the AI Act classifier sorts it into its tier.
Does DORA replace NIS2 for financial entities
For financial entities, DORA displaces the ICT parts of NIS2 but not NIS2 as a whole. DORA is lex specialis, the more specific law that takes precedence, per Article 4 of Directive (EU) 2022/2555, and DORA Recital 16 says plainly that the Regulation “constitutes lex specialis with regard to Directive (EU) 2022/2555”. This is the part most three-way summaries skip.
Article 4 switches off NIS2 wherever a sector-specific Union act imposes at least equivalent cybersecurity risk-management and incident-reporting duties. For financial entities DORA is that act, and the Commission’s Article 4 guidelines list it as the only sector-specific act that has so far met the test. So a bank does not run DORA’s ICT resilience programme and NIS2’s version alongside it. Being caught by both NIS2 and DORA on ICT risk does not usually mean two sets of obligations, it means DORA’s set, once.
The carve-out has an edge worth reading closely. It covers ICT risk management, incident reporting, resilience testing, third-party risk and information sharing, and nothing past that line. Residual NIS2 duties, registration and general cooperation among them, can still attach to a financial entity depending on how the Member State drafted its transposition. Germany’s implementing law, for instance, disapplies the ICT provisions for DORA entities without granting a clean exemption from every NIS2 obligation. In our assessment this is where the “DORA replaces NIS2” shorthand quietly misleads, because it promises a full exemption that the text does not give.
Who falls under all three, exactly one, or none
A mid-sized bank or insurer that runs an AI credit-scoring or insurance-pricing model can sit under all three regimes at once, while most companies sit under one or none. The overlap is real but narrow, and it clusters in regulated finance that has gone into AI.
Take a 500-person insurer using an AI model to price life cover. DORA governs its ICT resilience, the AI Act treats the pricing model as high-risk under Annex III, and NIS2 applies only in the residual areas DORA’s lex specialis does not reach. That is the genuine all-three case. Move one variable and the stack collapses. A 300-person hospital with no high-risk AI is NIS2 only. A small payment institution that uses no high-risk AI is DORA only, its ICT obligations sitting under DORA rather than NIS2. A recruitment-software vendor selling an AI screening tool, below the NIS2 size line and in no Annex sector, is AI Act only. And a thirty-person non-financial consultancy in no listed sector, running no high-risk or prohibited AI, is under none of the three, though GDPR and the AI literacy duty still sit in the background.
Four assumptions cause most of the wrong self-assessments. That everyone under NIS2 is also under DORA, when DORA is narrow and most NIS2 entities never touch it. That DORA switches NIS2 off entirely, when it only displaces the ICT lane. That the AI Act leaves regulated finance alone, when credit scoring and insurance pricing are named high-risk. And that DORA is simply a replacement for NIS2, when it is a specific carve-out for financial entities and nothing wider.
The scope answer you can settle before any deadline lands
The most useful work here does not wait on any transposition or delayed date, it is classification. Knowing which of the three regimes reaches you, and in which lane, is the step everything else depends on, and it can be settled before any of the dates bite.
The sequence is more description than instruction. The first move is the three-question comparison matrix, which shows which regimes reach you at all before you open a single Article. For anyone landing in NIS2, the classification that counts is the national one rather than the Directive’s, since the fine ceilings and residual duties were set in transposition and several Member States only finished in late 2025. For a financial entity, DORA is the ICT regime from 17 January 2025, and NIS2 is worth reading only for the residual duties left after the Article 4 carve-out. For anyone building or using AI, each system needs testing against Annex III, because the substance of high-risk classification did not change when the application date slid to 2 December 2027. Where the NIS2 side needs outside help, the compliance provider directory lists firms by Member State.
Settle those four and the three-way question stops being a threat and becomes a filing exercise, which is about the most any of us can ask of a regulation.
RegDossier
Making EU compliance almost enjoyable. Almost.
EU regulatory updates in your inbox every two weeks. Free.
Get the next briefing