Cybersecurity Obligations in E.U.’s Digital Laws: AI Act, CRA and NIS2

The E.U. has issued a wide range of new, fit-for-purpose legislation that imposes novel cybersecurity and incident reporting requirements on AI systems and models. Companies both within and outside the E.U. must be mindful of the new obligations these digital laws introduce. In this first installment of a two-part guest article series, Alston & Bird partners Jennifer Everett and Wim Nauwelaerts examine a selection of E.U. digital laws that impose cybersecurity obligations on businesses within their scope, including the AI Act, Cyber Resilience Act and NIS2 Directive. Part two will cover additional E.U. digital laws – the Digital Operational Resilience Act and Data Act – as well as practical compliance steps for businesses. See our three-part series answering top questions about the E.U. AI Act: “Reach and Unique Requirements” (Apr. 24, 2024), “Risk Tiers and Big-Player Transparency” (May 1, 2024), and “Practical Steps and What’s Next” (May 8, 2024).

To read the full article

Continue reading your article with a CSLR subscription.