The video supports management orientation and prioritisation. It does not determine legal applicability or confirm compliance with individual obligations. The official starting sources and material claims were last checked on 22 July 2026; concrete application still requires qualified legal and technical assessment.
Management video
EU digital regulation for mid-market companies
The video connects the AI Act, NIS2, Cyber Resilience Act and Data Act in one management radar. It shows which company characteristics warrant a closer look, what information to prepare and where qualified specialist review begins.
Read transcript
Which four EU digital rules belong on your management radar? Start with four review lanes. The AI Act addresses roles and risks around AI systems: look closer if you develop, provide, procure or deploy AI. NIS2 covers cybersecurity risk management in specified sectors: check sector, size, entity role and Germany's current BSI Act. The Cyber Resilience Act covers cybersecurity of products with digital elements: review your role around digital hardware or software. The Data Act structures access to and use of data from connected products and related services: map users, data holders and recipients. These are review lanes, not automatic scope decisions, and they are not the complete EU digital rulebook. First, the AI Act. Make AI visible before classifying it. List systems and use cases, who provides or deploys them, and which decisions they influence. Turn that inventory into an AI policy, accountable owners and risk-oriented review. Add role-appropriate competence evidence. The inventory governs the work; it does not decide the legal classification. Second, NIS2. Keep one memory anchor: leadership, cyber risk, supply chain, incidents and evidence. Management should verify the entity's sector and characteristics under Germany's current BSI Act, then connect responsibilities, measures and reporting routes. Concrete scope and obligations need specialist review. Third, the Cyber Resilience Act. Treat product security as a lifecycle: product role and scope, components and SBOM, vulnerability handling, security updates and release evidence. This is the review lane for hardware and software with digital elements made available in the EU. Conformity and technical implementation remain specialist work. Fourth, the Data Act. Map connected products and related services to the data they generate, then map user, data holder and recipient. Add technical access and contract flows. Keep personal data, trade secrets and existing rights as separate safeguards. Start with the map, not a blanket assumption that data must be handed over. My recommendation: take the four-lane radar into your next management meeting. Mark only the lanes with concrete company signals; assign one owner and one specialist review to each. Use the Momentum Advisory radar checklist as your structured starting point. It supports prioritisation, not legal compliance.
Key moments
- 00:00
Four rulebooks: overview and company signals
- 00:49
AI Act and AI governance
- 01:11
NIS2 and cyber governance
- 01:33
Cyber Resilience Act and product security
- 01:55
Data Act and data roles
- 02:17
Recommendation for the next management meeting
AI-generated presenter; editorial and subject-matter responsibility: Momentum Advisory.
Editorial: Momentum Advisory
Content version: 2.1-question-led-cumulative-support · Reviewed: 22/07/2026
Subject-matter review: Momentum Advisory publication review against official sources; concrete applicability requires qualified specialist assessment · 22/07/2026
Choose your next step
Explore the management radar
Connect company characteristics, the four regulation lanes and the shared operating model.
Use the radar checklist
Prepare ownership, available evidence and open specialist reviews for an internal workshop.
Structure digital implementation
Connect regulatory requirements with processes, data, systems and a practical delivery roadmap.