Compliance Convergence: AI Act + DORA + NIS2 as One Programme

Most regulated EU firms are now in scope of the AI Act, DORA and NIS2 simultaneously, and most are running them as three separate programmes with three teams, three registers and three sets of evidence. That is expensive, and worse, it produces three versions of the truth that a supervisor will find and question. The three regimes overlap heavily in what they actually demand of a technology function, and the firms that treat them as one control set feeding three regulators spend far less and defend far better.

Where the three regimes actually overlap

Read past the different vocabularies and the same demands recur. All three require you to know your assets — AI systems for the AI Act, ICT systems and third parties for DORA, network and information systems for NIS2. All three require risk management, incident detection and reporting on tight clocks, and third-party or supply-chain oversight. All three make governance and board accountability explicit. A single, well-built ICT risk framework, asset inventory, incident process and third-party register can satisfy the common core of all three — because the underlying question (“do you understand and control your technology risk, and can you prove it?”) is the same one asked three times.

Where they genuinely diverge

Convergence is not sameness, and pretending it is creates gaps.

Free · 4 minutes

Is your engineering team shipping safely, or quietly accumulating risk?

Fourteen questions on how work gets from idea to production — cadence, testing, rollback, and the key-person risk in your delivery. Banded finding on screen, full sheet by email.

  • The object differs. The AI Act cares about AI systems and their risk classification; DORA about operational resilience and third-party ICT; NIS2 about the security of network and information systems. The same system may appear in all three inventories for different reasons.
  • The clocks differ. DORA has applied since January 2025; NIS2’s national laws are landing across 2025-2026; the AI Act arrives on a staggered schedule. One programme has to respect three timelines.
  • The reporting routes differ. Each regime reports incidents to different authorities on different thresholds, so the mapping matters even where the detection is shared.

Running it as one programme

The efficient architecture is a shared foundation with regime-specific overlays. Build the common core once — inventory, risk framework, incident capability, third-party register, governance — and map each element to the specific obligations of each regime, adding only the pieces unique to each (AI risk classification for the AI Act, resilience testing specifics for DORA, the national NIS2 deltas). The alternative — three parallel builds — duplicates the expensive shared work, and then the three registers drift apart until a supervisor finds the inconsistency.

The board-level reading is that “three compliance projects” is usually the wrong framing and the expensive one. A firm that maps AI Act, DORA and NIS2 to one control set gets a coherent technology-risk posture that answers all three regulators from a single source of truth — which is cheaper to build, cheaper to maintain, and far more defensible than three siloed programmes that agree with each other only by accident.

Who this is for

This reading is for:

  • CTOs and CISOs running three overlapping EU compliance programmes
  • Boards funding what look like three separate technology projects
  • Compliance leads tired of the same control being audited three ways
  • Regulated firms in scope of all three regimes at once

Sixteen Pillars maps the AI Act, DORA and NIS2 to one control set with regime-specific overlays, so you answer three regulators from a single source of truth. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming