AI Governance, NIS2, DORA: What a Fractional CISO Helps UK Businesses Track
AI governance has become the most visible item on the cyber compliance agenda for UK businesses, and for good reason, most organisations are using AI tools with no named owner, no policy, and no visibility into how staff are using them. But it isn't happening in isolation. It's one part of a wider shift in cyber and data regulation that's converged over the past eighteen months, and treating it as a standalone project misses the rest of what's landing on the same desk.

What's converging, and who it actually applies to:
AI Act — live since August 2026, with obligations for high-risk systems following in December 2027. Extraterritorial: it can apply to UK businesses whose AI systems reach EU markets, regardless of where the business is established.
NIS2 — an EU directive, not automatically applicable in the UK. But UK businesses operating in its covered sectors (digital infrastructure, energy, health, and others) and supplying into the EU market can fall directly under it. Whether that includes you is a scoping question worth answering properly, not assuming away.
DORA — targets EU financial entities directly, but also reaches UK firms supplying critical ICT services into those entities, even without being a financial business themselves.
Cyber Resilience Act — live reporting obligations since 11 September 2026 for manufacturers of products with digital elements sold into the EU market, with full application from December 2027.
Cyber Security and Resilience Bill — the UK's own regime, expected in force around 2028. Most SMEs are exempt from direct scope, but its requirements are already flowing down contractually through supply chains, ahead of the Bill itself taking effect.
Post-quantum cryptography — not a legal deadline for most businesses yet, but NCSC and EU migration guidance (2028/2031/2035) means the planning window is now, not later.
The pattern across all six: scope depends on sector, on customers, on where data and AI systems end up, not simply on where a business is registered. Most organisations have no reliable process for working out which of these actually apply to them, and getting it wrong in either direction has a cost: over-comply and you're spending on obligations that never applied; under-comply and you find out from a regulator, an insurer, or a lost contract.
Coordinating all initiatives, not just AI Governance
The usual failure mode is treating each of these as its own initiative, run separately, with no one driving it forward consistently. A fractional CISO's approach to AI governance means more than a policy document, someone actively pushing it: visibility into actual usage, AI risk tracked in the same register as everything else, moving rather than filed and forgotten. On NIS2, that means properly scoping whether your sector and EU-facing activity actually bring you into scope, rather than assuming it doesn't apply. On the Cyber Resilience Act, it means working out which side of the manufacturer/supplier line you're on, and what that means for your existing incident processes either way.
That's the pattern across all six regimes: organisations end up compliant on paper in three areas and exposed in a fourth they never checked, because nothing was being driven forward consistently. What's actually needed is someone keeping all of it moving — prioritising what matters now versus later, and bringing the board a single, current risk position rather than six unconnected updates.
That's the role a fractional CISO fills. Not implementation of any one regime, but ongoing oversight across all of them, including AI governance, which is where most engagements start given how live and visible it currently is.
ICA Consultancy offers free online, immediate, assessments, including Cyber Security, AI Governance, and PQC Readiness, if you want a starting position before the conversation. But the conversation to have first is about who owns the whole picture.




Comments