Skip to content
TECHNOMATON | Docs SAI Certified Trainers

Scope and Applicability

Guide for determining which EU regulations apply to your organisation.


Quick test

Question 1: Do you use AI systems?

Do you use or develop AI/ML systems?

AnswerResult
YES --- You develop your own AIThe AI Act applies --- Provider obligations
YES --- You use third-party AI (Claude, GPT)The AI Act applies --- Deployer obligations
YES --- You sell AI solutionsThe AI Act applies --- Distributor obligations
NOThe AI Act does not apply (but monitor developments)

Question 2: Do you provide critical services?

Are you in any of these sectors?

SectorNIS2 category
Cloud computing, DNS, data centresEssential
Banking, insuranceEssential
Healthcare, hospitalsEssential
Energy, transportEssential
Public administrationEssential
Online marketplace, search enginesImportant
Manufacturing (machinery, electronics, food)Important
Postal services, waste managementImportant
None of the aboveProbably out of scope (verify with a lawyer based on size)

Question 3: Do you process personal data?

Do you process data about natural persons (names, emails, IP addresses, cookies…)?

AnswerResult
YES --- CustomersGDPR applies --- you must have a legal basis
YES --- EmployeesGDPR applies --- you must have a legal basis
YES --- Website usersGDPR applies --- cookie consent, privacy policy
YES --- B2B contactsGDPR applies --- legitimate interest (but carefully)
NOGDPR does not apply (very rare)

AI Act Scope

Who falls under the AI Act?

RoleDefinitionExampleObligations
ProviderDevelops/trains AIOwn ML modelsHighest
DeployerDeploys AIUses Claude in a productMedium
ImporterImports AI from non-EUUS AI system in the EUMedium
DistributorDistributes AIReselling AILower

Risk classification


NIS2 Scope

Criteria for scope determination

CriterionEssentialImportantOut of Scope
SectorAnnex IAnnex IIOther
Size>250 employees OR>50 employees OR<50 employees AND
Turnover>EUR 50M>EUR 10M<EUR 10M

Annex I - Essential Entities (higher obligations)

SectorExamples
EnergyElectricity, gas, oil, hydrogen, district heating
TransportAviation, rail, waterborne, road
BankingCredit institutions
Financial marketsExchanges, clearing houses
HealthcareHospitals, laboratories, pharmacies, medical device manufacturers
Drinking waterDrinking water suppliers
Waste waterWaste water treatment
Digital infrastructureDNS, TLD, cloud computing, data centres, CDN
ICT services B2BManaged services, security services
Public administrationCentral government bodies, regional (above threshold)
SpaceSatellite operators

Annex II - Important Entities (lower obligations)

SectorExamples
Postal servicesCouriers, postal operators
Waste managementWaste processing
ChemicalsManufacturing and distribution of chemicals
FoodManufacturing and distribution of food
ManufacturingMedical devices, computers, electronics, machinery, motor vehicles
Digital servicesOnline marketplace, search engines, social networks
ResearchResearch organisations

NIS2 Decision Tree


GDPR Scope

Who falls under GDPR?

GDPR applies to every organisation that:

  1. Is established in the EU and processes personal data
  2. Is established outside the EU but:
    • Offers goods/services to persons in the EU
    • Monitors the behaviour of persons in the EU

Types of processing

Data typeExamplesLegal basis
CustomersNames, emails, ordersContract
EmployeesSalaries, attendance, evaluationsContract + Law
MarketingNewsletter, cookiesConsent
AnalyticsIP addresses, device infoLegitimate interest
HealthDiagnoses, recordsExplicit consent + Law

Special Category Data (Art. 9)

Special categories require explicit consent:

  • Racial/ethnic origin
  • Political opinions
  • Religious beliefs
  • Trade union membership
  • Genetic data
  • Biometric data
  • Health data
  • Sexual orientation

Overlap matrix

SectorAI ActNIS2GDPR
SaaS/CloudAppliesAppliesApplies
FinanceAppliesAppliesApplies
HealthcareAppliesAppliesApplies
E-commerceAppliesDepends on sizeApplies
ManufacturingAppliesDepends on sizeApplies
ConsultingAppliesLikely notApplies
MediaAppliesLikely notApplies

Example scenarios

Scenario 1: SaaS Startup (50 employees, EUR 5M turnover)

RegulationApplicable?Reason
AI ActYesUse Claude for customer support
NIS2PossiblyCloud computing, but below threshold
GDPRYesCustomer data, employee data

Scenario 2: Bank (500 employees, EUR 100M turnover)

RegulationApplicable?Reason
AI ActYes (High-Risk)Credit scoring, fraud detection
NIS2Yes (Essential)Annex I - Banking
GDPRYesCustomer financial data

Scenario 3: Manufacturing company (100 employees, EUR 20M turnover)

RegulationApplicable?Reason
AI ActYes (Low-Med)Quality control AI, analytics
NIS2Yes (Important)Annex II - Manufacturing
GDPRYesEmployee data, B2B contacts

Next steps

  1. Determine scope for each regulation
  2. Consult a lawyer for edge cases
  3. Document your decisions for the audit trail
  4. Start with compliance -> Checklists