MICKAI®ArticlesCan directors be personally liabl…
Article · 21 July 2026

Can directors be personally liable for AI risk under NIS2?

Yes in a specific sense: NIS2 Article 20 places approval, oversight and training duties on management bodies personally, with liability for infringements.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign ainis2director liabilityai governancecybersecurity regulation

Yes, in a specific sense. Article 20 of NIS2 requires the management bodies of essential and important entities to approve their cybersecurity risk-management measures, to oversee their implementation and to follow training, and it states that management bodies can be held liable for infringements. For essential entities, national authorities can go further and seek a temporary suspension of managerial functions for persistent non-compliance. Where AI forms part of the entity's network and information systems, and it increasingly does, those personal duties reach the AI estate too.

The question matters in 2026 because many member states have carried NIS2 into national law and supervision is under way, at the same moment AI has moved into the operational core of the entities the directive covers. Boards that treated AI as an innovation topic are discovering it is a governance topic with their own names attached.

What does NIS2 Article 20 actually require of the board?

Three duties, each addressed to the management body rather than to the security team. The body must approve the cybersecurity risk-management measures the entity takes. It must oversee their implementation, which is a continuing duty rather than a signature. And its members must follow training, so that the people approving the measures understand the risks behind them. Article 20 then states that management bodies can be held liable for infringements. The structure is deliberate: the directive does not permit cybersecurity to be something the board delegates and forgets.

Does AI count as cybersecurity risk under NIS2?

NIS2 governs the security of network and information systems, and deployed AI runs on and within those systems. A model that reads internal documents, drafts customer correspondence or executes agent workflows is part of the estate the approved measures must cover. The board's oversight therefore extends to concrete questions: what data can the AI reach, what actions can it take, who approved each use, and what record exists of all three. An entity whose approved measures cover everything except its fastest-growing category of software has a gap its supervisor will eventually find.

How real is the personal liability?

Real, and national. NIS2 is a directive, so the precise liability mechanics are set by each member state's transposition rather than by the directive itself, and they differ between countries. What the directive fixes is the direction of travel: management bodies approve, oversee and train, and can be held liable when the entity infringes. For essential entities the powers go further, because authorities can seek a temporary suspension of managerial functions where non-compliance persists. It would be an overstatement to describe one uniform liability regime across the EU, and a worse mistake to conclude the risk is theoretical.

Does any of this reach UK directors?

Not directly, because the UK is outside NIS2. It reaches UK boardrooms through group structure. A group with essential or important entities operating in the EU meets the directive through those entities, and a director who sits on the management body of an in-scope entity carries the Article 20 duties wherever the parent is registered. UK directors in that position should assume the approval, training and oversight questions will be asked of them personally, under the national law of the member state concerned.

What is the three-question test a director should be able to pass?

When a regulator, or a shareholder action, examines an AI-related security failure, the questions are short.

  • Did you approve the risk-management measures covering the AI systems, and is that approval recorded?
  • Did you follow training that covers the risks those systems actually present?
  • Can you show that you oversaw implementation, rather than assumed it?

Two of the three are answered by governance paperwork. The third is the hard one, because oversight of systems that generate thousands of actions a day cannot be evidenced by board minutes alone. It needs an operational record of what the AI did, and that record has to be one the board can trust under challenge.

What evidence makes AI oversight checkable?

A record that cannot be quietly edited. On Mickai, a Sovereign Intelligence Operating System, every action is sealed to an audit ledger signed under FIPS 204, the primary post-quantum digital signature standard, and bound to hardware-attested identity, so the record shows who invoked the system, what it did and who approved what. Because the system runs offline on operator-owned hardware, the ledger verifies without trusting any external service, or us. For a director, that converts oversight from an assertion in a board pack into an artefact that can be produced when the Article 20 questions arrive.

Oversight without evidence is assertion, and assertion is exactly what personal liability regimes exist to test.

How the sealed record and the wider architecture fit together is set out at /sovereign-ai, and the film at /film shows the interface, audit trail included, in operation.

Frequently asked questions

Am I personally liable if my company's AI is involved in a security breach under NIS2?

Article 20 states that management bodies of essential and important entities can be held liable for infringements of the risk-management duties, with the precise mechanics set by national transposition. The test a regulator applies is whether the measures were approved, overseen and understood, including for the AI systems involved in the incident.

Does NIS2 apply to my UK company?

The UK is outside NIS2, so a purely domestic UK entity is not in scope. A group with essential or important entities operating in the EU meets the directive through those entities, and directors sitting on the management bodies of in-scope entities carry the Article 20 duties regardless of where the parent is registered.

Can a director really be suspended under NIS2?

For essential entities, national authorities can seek a temporary suspension of managerial functions where non-compliance persists. It is a last-resort power whose operation depends on national law, but its existence has changed the board conversation, because persistent cybersecurity failure now carries a consequence aimed at the individual rather than the balance sheet.

What records should a board keep about AI risk?

Three sets: approval records for the measures covering AI systems, training records for the members of the management body, and a verifiable operational record of what the AI systems actually did. The first two show the duties were performed. The third makes oversight checkable rather than asserted, and it is what a regulator asks for first.

Does delegating to a CISO remove the board's NIS2 liability?

No. Article 20 places approval and oversight on the management body itself, so executing through a CISO is expected, but accountability does not travel with the task. The board remains responsible for approving the measures, following training and overseeing implementation, and it needs evidence that it engaged with what was reported to it.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/can-directors-be-personally-liable-for-ai-risk-under-nis2. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles