The amended UKSC entered force on 3 April 2026. By 3 October 2026, every key and important entity in Poland must register in the national register. The Article 21 risk management obligations, supply chain security included, have to be in place by 3 April 2027. That is the deadline that matters for almost everyone reading this, because Article 21 applies to both categories.
The mandatory cybersecurity audit is narrower than it is usually presented. According to the Ministry of Digital Affairs, the first audit by 3 April 2028 covers only key entities that were not previously operators of essential services. The same date starts the penalty regime. So if you are an important entity, the question is not "will we pass the audit". It is "can we document, under Article 21, who processes our documentation and where".
This isn't a vague regulatory wave. It's a concrete timeline that changes how key and important entities evaluate every vendor in their supply chain. AI vendors included.
And that's where it gets complicated.
Most AI tools currently landing inside European manufacturing run on public cloud: ChatGPT Enterprise, Copilot, Gemini Workspace. Excellent products. In a different context. Inside a key or important entity under NIS2, each one is a supply-chain vendor that:
- processes your technical documentation, service records and commercial offers outside your perimeter,
- can't show your team where, physically, your data sits at any moment,
- can't give you what Article 21 documentation requires: a full audit trail and explicit mapping of the measures you rely on. Source grounding is not an Article 21 measure, NIS2 does not regulate AI; it is our answer to supply-chain security under Article 21(2)(d) and to the human-oversight and transparency duties of the AI Act.
The model itself isn't the issue. The layer it runs on is. And you don't control it.
What this looks like in practice
The European manufacturers we talk to in 2026 land on one of three positions:
- Wait for the audit, worry then. The most common stance, also the riskiest. With personal liability on the management board, every quarter of delay is concrete exposure.
- Pull AI out of critical processes. Safe, but it costs competitiveness against companies that operationalize AI properly.
- Change the deployment model. On-prem. Data never leaves the perimeter. Every answer grounded in your own sources. Full audit trail.
For key and important entities under NIS2, the third path isn't a premium option. Long term, it's the only defensible one.
We built CortexMine for exactly this profile: a private AI platform for European manufacturers, deployed on-prem. Digital Workers for service, instructions, and offers, running on your infrastructure.
If your IT, legal, or compliance team is starting to ask "what do we do about AI under NIS2", this is a good time for a 30-minute conversation with no pitch. We'll show you how we map to Article 21 and what concretely changes when AI runs on your own iron.
Book 30 minutes with a founder → No pitch. Concrete questions.
Prefer to check on your own first? The readiness mini-audit takes 10 minutes and leaves no data behind.
