Companies that use or build AI systems often do not know which risk category they fall into, nor what documentation is required. The mapping is done by hand, against an evolving regulation, and has to be redone for every new model introduced.
DataGovern
EU AI Act readiness, NIS2 and GDPR: three examples of what DataGovern's agents oversee across your documents and processes, configured company by company.
EU AI Act readiness
From classifying your AI systems to the documentation, before the August 2026 deadline.
DataGovern classifies AI systems under the EU AI Act, generates the required technical documentation, ready to validate, and tracks the deadlines: readiness for August 2026 becomes a mapped path, not a last-minute rush.
What it is
The EU AI Act classifies AI systems by risk level: unacceptable, high, limited, minimal. Each category carries different obligations, from risk management to technical documentation. It applies in phases, with the relevant obligations becoming operative from August 2026.
References
Regulation (EU) 2024/1689 (AI Act), phased application with relevant obligations from August 2026. Interaction with the GDPR (Reg. (EU) 2016/679) for automated processing.
What DataGovern surfaces
NIS2 Compliance Manager
From security posture to 24/72h notifications, with NIS2 obligations already in force.
Without a dedicated team, posture, measures and response plans stay in separate documents. When an incident hits, the 24/72h deadlines arrive before the evidence, and the notification is prepared under pressure.
DataGovern measures posture, surfaces the gaps against NIS2 requirements, keeps the measures registry and guides incident notification within the 24/72h windows, with the documentation ready for the competent authority.
What it is
NIS2 extends cybersecurity obligations to thousands of SMEs in essential and important sectors. It requires adequate technical and organizational measures, risk management and the notification of significant incidents within tight windows: 24 hours for early warning, 72 hours for the full notification.
References
Directive (EU) 2022/2555 (NIS2); Legislative Decree 138/2024 (Italian transposition). Reference framework: ISO/IEC 27001.
What DataGovern surfaces
DataGovern covers the documentation side of NIS2: registers, evidence and 24/72h notifications. For attack surface, vulnerabilities and technical posture, see CyberAgent.
GDPR and cross-regulation gaps
From records of processing to a single gap analysis across GDPR, NIS2 and AI Act.
Records of processing in Excel, DPIAs in separate documents, data subject requests handled over email. The three regulations are tackled one at a time, without seeing where requirements overlap or contradict each other.
DataGovern keeps records of processing, DPIAs and data subject rights in one hub and cross-references GDPR, NIS2 and AI Act requirements: it spots the overlaps and produces one unified remediation plan, not three disconnected ones.
What it is
The GDPR governs the processing of personal data: records of processing, DPIAs, lawful bases, data subject rights. Many of these obligations overlap with NIS2 and the AI Act, but they are handled in separate silos, with duplicated work and inconsistent views.
References
Regulation (EU) 2016/679 (GDPR); Directive (EU) 2022/2555 (NIS2) with Legislative Decree 138/2024; Regulation (EU) 2024/1689 (AI Act).
What DataGovern surfaces
DataGovern runs on-premise, with open-weight LLMs inside your perimeter: no compliance data leaves your organisation and approval stays with your team. Audit scope and priorities are agreed on your case.
