Skip to content
The rules

Who reports what when NIS2, DORA and the AI Act overlap

Sweden's Cybersecurity Act exempts firms covered by DORA from incident reporting altogether. The two cyber clocks therefore never start together, and what remains is the deadline nobody gave an outer limit.

Andreas Olsson7 min read

Photomontage: a heavy industrial rotary selector switch, cut out with a hard edge and mounted flat on a printed surface. It has exactly two detent positions and nothing between them, with the lever seated firmly in one of them. The occupied position is the only gold in the image.

Key insights


  • Sweden's Cybersecurity Act (2025:1506) exempts operators covered by DORA from the duties in Chapter 2, Sections 3 to 10, which is where both risk management and incident reporting sit.
  • Financial firms must still register their activity under the Cybersecurity Act, since 1 July 2026 with the Swedish National Cyber Security Centre, while incidents are reported under DORA to Finansinspektionen.
  • The AI Act's two-day deadline for a serious incident in critical infrastructure, Article 73(3), rests on the provider, but runs from when the provider or the deployer became aware of it.
  • The relief in Article 73(9) requires the provider itself to be subject to equivalent reporting duties under Union law. What counts as equivalent is undefined, and the Commission's guidance is still a draft.
  • No organisation carries all three sets of clocks. Critical infrastructure gets NIS2 and the AI Act, financial firms get DORA and the AI Act, and the AI deadline belongs to the provider.

Sweden's Cybersecurity Act entered into force on 15 January 2026. DORA has applied since 17 January 2025. Article 73 of the AI Act, on the reporting of serious incidents, sits in Chapter IX and applies from 2 August 2026. Three regimes, drafted independently of one another, and an operations team that has to know which of them governs the night something breaks.

Two of the three are Union regulations that apply directly in every Member State. NIS2 is a directive, so what binds an operator is the national law implementing it, and the Swedish version of that law is where the most useful provision in this article is found. The belief that travels with the headlines is that a business running AI in an essential service picks up three sets of deadlines at once. It does not. What is true instead is less comfortable, because it concerns a clock nobody gave an outer limit.

Two of the clocks can never start together

The Cybersecurity Act (2025:1506) implements NIS2 in Sweden. In Chapter 1, Section 11 it exempts operators covered by Regulation (EU) 2022/2554, that is DORA, from the duties in Chapter 2, Sections 3 to 10. Both the risk management requirements and the whole of incident reporting sit there.

Finansinspektionen, the Swedish financial supervisory authority, says the same thing plainly in its note on the new law from January 2026: DORA takes precedence over the new Cybersecurity Act for financial firms.

The exemption is not total, and that is the part usually lost. Financial firms are still covered by the registration requirement in the Cybersecurity Act, the authority writes in the same note. A credit institution therefore registers its activity under the Cybersecurity Act, since 1 July 2026 with the Swedish National Cyber Security Centre at Försvarets radioanstalt, which took the registrations over from Myndigheten för civilt försvar, but reports its incidents under DORA, to Finansinspektionen, which passes them on.

Precedence means another regime takes over, not that an obligation disappears.

For anyone building the process this has a concrete consequence. No Swedish business has both the NIS2 clock and the DORA clock to answer to in the same incident. Either you are an operator under the Cybersecurity Act, or you are a financial entity under DORA. What can be laid on top of either is the AI Act's reporting, and it behaves like neither of them.

The clocks side by side

The Cybersecurity Act's deadlines sit in Chapter 2, Sections 5, 6 and 8. DORA sets out in Article 19 which reports are due, while the deadlines themselves sit in Article 5 of the delegated regulation and are restated by Finansinspektionen. The AI Act's deadlines sit in Article 73.

ReportWho reportsTo whomDeadlineCounted from
Early warning, Cybersecurity Act Ch. 2 s. 5The operatorThe CSIRT unit24 hoursAwareness of the incident
Incident notification, Ch. 2 s. 6The operatorThe CSIRT unit72 hours, and 24 for trust service providersAwareness of the incident
Final report, Ch. 2 s. 8The operatorThe CSIRT unitOne monthThe incident notification
Initial notification, DORA Article 19The financial entityFinansinspektionenFour hours, and in any event no later than 24 hoursClassification as major, and awareness respectively
Intermediate report, DORA Article 19The financial entityFinansinspektionen72 hoursThe initial notification
Final report, DORA Article 19The financial entityFinansinspektionenOne monthThe intermediate report, or the latest updated one
Serious incident in critical infrastructure, AI Act Article 73(3)The providerThe market surveillance authorityImmediately, and no later than two daysAwareness of the provider or, where applicable, the deployer
Other serious incidents, Article 73(2)The providerThe market surveillance authorityImmediately, and no later than 15 daysAwareness of the provider or, where applicable, the deployer
Established serious incident, Article 26(5)The deployerFirst the provider, then the importer or distributor and the market surveillance authoritiesImmediately, no outer limit statedThe incident having been established

Three things separate the rows more than the hours do. The recipient differs in every regime. The starting point differs: awareness in one case, a completed classification in the other. And the bottom row has no outer limit, while being the only one of the AI Act's rows that rests on whoever actually runs the system. The same two-day deadline in Article 73(3) also applies to a widespread infringement, not only to disruption of critical infrastructure. Where a person dies, Article 73(4) gives ten days instead of fifteen.

The Article 73 exemption requires the provider itself to be regulated

Article 73(9) holds the coordination rule most often invoked and least often read: "For high-risk AI systems referred to in Annex III that are placed on the market or put into service by providers that are subject to Union legislative instruments laying down reporting obligations equivalent to those set out in this Regulation, the notification of serious incidents shall be limited to those referred to in Article 3, point (49)(c)."

The condition attaches to the provider, not to the organisation using the system. Where the provider is a software company with no reporting duties of its own under Union law the relief falls away, and that describes most vendors of models and decision support. Where the provider is itself a regulated entity, the duty shrinks to Article 3(49)(c), meaning incidents that infringe obligations under Union law intended to protect fundamental rights. The category covering critical infrastructure, Article 3(49)(b), then drops out of reporting altogether.

What counts as equivalent reporting obligations is not defined in the article. Article 73(7) requires the Commission to issue dedicated guidance by 2 August 2025. The guidance and its reporting template were published in autumn 2025 and are still listed as a draft on the Commission's AI Act Service Desk. For now the assessment is made by whoever has to report.

The relief for financial institutions covers monitoring, not notification

Article 26(5) has a second subparagraph worth reading slowly. For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation in the first subparagraph is deemed to be fulfilled by complying with those rules.

The word is monitoring. The same first subparagraph also carries the duty, on establishing a serious incident, to immediately inform first the provider and then the importer or distributor and the market surveillance authorities. That duty is not named in the exemption. A bank leaning on its internal governance framework has therefore covered its oversight of the system, but has been told nothing about notifying an incident it has established.

Who is covered by what, and how few are covered by everything

The Cybersecurity Act reaches operators in eighteen sectors, according to the Swedish National Cyber Security Centre. The size criterion is that the activity is equivalent to or larger than a medium-sized enterprise, measured against Commission Recommendation 2003/361/EC, while municipalities and regions are covered regardless of size.

DORA reaches a different set. In the consultation memorandum to its DORA regulations, dated September 2024, Finansinspektionen writes that the number of firms affected by the new regulations comes to around 1,300 in total. The figure covers the firms those regulations are addressed to and is the authority's own estimate made before the regime began to apply.

The AI Act's reporting is narrower than either. It is triggered by a serious incident in a high-risk AI system, and the primary duty rests on the provider. Which systems are high-risk is settled by Annex III and Annex I, and those requirements begin to apply on 2 December 2027 and 2 August 2028 respectively. What moved and what did not is covered in Two reporting clocks start when an AI system fails.

The split can therefore be written down in a line. An operator under the Cybersecurity Act, an energy company or a grid owner, gets the NIS2 clock and the AI Act's, because the exemption in Chapter 1, Section 11 reaches only those covered by DORA. A financial firm gets the DORA clock and the AI Act's. Nobody gets all three. For critical infrastructure it is still NIS2 and the AI Act that meet in the same incident.

The coordination exists. It simply does not coordinate time.

Three genuine coordination mechanisms have just been listed, and they weigh more than the tally of clocks: Chapter 1, Section 11 of the Cybersecurity Act, Article 73(9), and the second subparagraph of Article 26(5). They remove duplicate reporting, they name which regime governs, and they make the combined burden considerably smaller than the market that sells alarm suggests. A business that has read them has less to do, not more.

The receiving end points the same way for some readers. Under the government decision of 12 June 2026, reference Fi2026/01365, Finansinspektionen is the market surveillance authority for the financial sector, the Swedish Post and Telecom Authority for telecommunications and radio equipment, the Medical Products Agency for medical devices, and the Swedish Authority for Privacy Protection for remaining areas. The decision covers a fifth authority, Swedac, the Swedish Board for Accreditation and Conformity Assessment, whose role sits outside incident reporting. A bank therefore sends both its DORA incident and its AI incident to the same authority. An energy company reports to the CSIRT unit and to the privacy authority, which have nothing to do with each other. The decision states that the assignment runs until 31 December 2026, and the permanent arrangement is still a proposal in the public inquiry SOU 2025:101.

What none of the mechanisms does is coordinate time. They allocate duties between regimes, never between hours. No rule says in which order the thresholds are to be tested, and the thresholds measure different things: a significant incident under the Cybersecurity Act, a major ICT-related incident under DORA, a serious incident under the AI Act.

The threshold with the shortest clock is rarely the one an operations team tests first.

The difference between the three thresholds is not academic. A disruption fully restored within a few hours can be significant without being irreversible, and a model that has produced systematically wrong outputs for months can be irreversible without any single outage having occurred.

The question that decides which clock is yours

Ask two questions about every AI system you run, in this order.

The first: which cyber regime governs the organisation, the Cybersecurity Act or DORA? The answer is always one of the two, never both, and it settles the recipient, the deadlines and the threshold for the entire incident procedure.

The second: is the provider of the system itself obliged to report under Union law? For a business that bought its model from a systems vendor under no supervision of its own the answer is no, and the AI Act's two-day deadline then stays with that provider, counted from when the provider or, where applicable, you became aware. For a business that bought the function embedded with a regulated counterparty the answer is yes, and the duty shrinks to a category that rarely arises in operations.

The two answers give four outcomes, and every organisation has exactly one of them. Which one it is should be written down in a single place, together with the threshold, the recipient and the name of the person who makes the assessment. Without that document two teams make separate assessments at separate times, and one of them has twenty-four hours.


Common questions

Not for incident reporting. Sweden's Cybersecurity Act (2025:1506), which implements NIS2, exempts in Chapter 1, Section 11 operators covered by Regulation (EU) 2022/2554 (DORA) from the duties in Chapter 2, Sections 3 to 10. Both risk management and incident reporting sit there. Finansinspektionen states that DORA takes precedence over the new Cybersecurity Act for financial firms. The registration requirement in the Cybersecurity Act still applies to them.

A significant incident must be notified as soon as possible and no later than 24 hours after the operator becomes aware of it, under Chapter 2, Section 5. The incident notification under Section 6 is due no later than 72 hours after awareness for entities other than trust service providers, which have 24 hours. The final report under Section 8 is due no later than one month after the incident notification. Reports go to the CSIRT unit.

According to Finansinspektionen, which refers to Article 5 of the delegated regulation, the initial notification is due as early as possible and in any event within four hours of the incident being classified as a major ICT-related incident, and no later than 24 hours after the financial entity became aware of it. The intermediate report is due within 72 hours of the initial notification, and the final report no later than one month after the intermediate report. Reports go to Finansinspektionen.

The primary duty rests on the provider. Article 73(1) of the AI Act requires providers of high-risk AI systems placed on the Union market to report serious incidents to the market surveillance authorities of the Member States where the incident occurred. The deployer has a separate duty under Article 26(5): on establishing a serious incident it shall immediately inform first the provider, then the importer or distributor and the relevant market surveillance authorities.

It narrows reporting where the provider is already regulated. The provision covers high-risk AI systems referred to in Annex III placed on the market or put into service by providers subject to Union legislative instruments laying down reporting obligations equivalent to those in the AI Act. For those, notification of serious incidents is limited to those referred to in Article 3, point (49)(c), meaning infringements of Union law intended to protect fundamental rights. The condition attaches to the provider, not to the organisation using the system.

Not in final form. Article 73(7) requires the Commission to develop dedicated guidance to facilitate compliance with Article 73(1), and states that the guidance was to be issued by 2 August 2025. A draft guidance document and a reporting template were published in autumn 2025 and are still listed as a draft among the resources on the Commission's AI Act Service Desk. Until then the assessment is made by whoever has to report.

It depends on the sector, and the arrangement is for now a government assignment. Under decision Fi2026/01365 of 12 June 2026, Finansinspektionen is the market surveillance authority for the financial sector, the Swedish Post and Telecom Authority for telecommunications and radio equipment, the Medical Products Agency for medical devices, and the Swedish Authority for Privacy Protection for remaining areas. The decision states that the assignment runs until 31 December 2026. The proposal for a permanent arrangement sits in the public inquiry SOU 2025:101.

Operators in eighteen sectors, according to the Swedish National Cyber Security Centre. The size criterion is that the activity is equivalent to or larger than a medium-sized enterprise, measured against Commission Recommendation 2003/361/EC. Municipalities and regions are covered regardless of size. The Act entered into force on 15 January 2026.


If this lands on your desk, we should talk.

Ampliro Insights

New analysis, roughly weekly.

We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.

We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.