NIS2 and AI Incidents: The 24-Hour Clock Nobody Has Rehearsed
An assistant that leaks customer data is a reportable incident in most EU member states. Very few security teams have a written answer for what counts, who decides, and what goes in the first notification.

NIS2 transposition is now largely complete across the member states, and the enforcement posture has shifted from guidance to inspection. Meanwhile most AI incidents in enterprises are still handled as product bugs — logged in a backlog, never assessed against a reporting obligation.

What actually triggers a report
The threshold is significance of impact on service continuity or on recipients of the service — not whether the root cause was novel. An LLM assistant that returned another customer's data, an agent that mis-executed a bulk operation, or a poisoned index that produced systematically wrong advice can each cross it.
The regulator is not interested in whether the model "hallucinated". They are interested in who was affected, when you knew, and what you did.
The three-stage timeline
- Within 24 hours: an early warning. Minimal content: is it suspected malicious, is there cross-border impact, what is the initial assessment.
- Within 72 hours: an incident notification with severity, impact and indicators of compromise.
- Within one month: a final report with root cause, applied mitigations and, where relevant, cross-border effects.
What to prepare before you need it
A written trigger list for AI systems
Two pages, agreed with legal, mapping concrete AI failure modes to a yes/no reporting decision. Include the ambiguous cases and pre-decide them. Arguing definitions during hour three is how deadlines are missed.
A single named decision maker
One accountable role, with a deputy, empowered to file. Committees do not make 24-hour deadlines.
Evidence that survives the incident
Prompt and completion logs, retrieval logs, tool-call logs and model version history — retained long enough to reconstruct an event a month later, and stored where an incident cannot delete them.
A rehearsed tabletop
Run one scenario per year against the AI trigger list. The output is not a certificate; it is the discovery of which log you do not actually have.
The obligation is not new. What is new is that your most likely reportable incident is now produced by a system your security team does not own.

