Compliance
NIS2 and the AI Act
Both rules reach every company working with artificial intelligence — one through the supply chain, the other directly. This page states what you inherit by building on AICLOUD, and what remains yours.
Last revised: 7 August 2026
1. What you inherit
AICLOUD is built on the OpenKBS infrastructure, which runs on AWS. That is where the independently audited certifications come from — none of which we issued ourselves: ISO/IEC 27001 (information security management), ISO/IEC 27017 (cloud security), ISO/IEC 22301 (business continuity), SOC 2 Type II and C5. Platform data sits in the Frankfurt, Germany region — inside the European Union.
2. If you fall under NIS2
The directive obliges regulated entities to manage supply-chain risk — that is, to vet you and your suppliers. If you are such an entity, AICLOUD is a supplier you have something to write down about: certified infrastructure, data in the EU, encryption in transit and at rest, a log of operator actions and a contractual incident notification duty. The full answers, including the section on what we do not yet have, are on the Data security page.
3. The AI Act
Regulation (EU) 2024/1689 applies in stages. Since February 2025 the prohibited practices (Art. 5) and the AI literacy duty (Art. 4) are in force — staff who use such tools, or who decide on their output, have to understand what they are doing. Since August 2026 the rules for high-risk systems under Annex III apply too: recruitment, credit and insurance, education, critical infrastructure. If your application falls there, the obligations are yours as the deployer — the platform does not assume them for you, but it gives you what you need to meet them.
4. What the platform provides
- Traceability: every request records which model and which version of it was used, when, and at what cost — per project. This is the log a regulator asks to see.
- A human in the decision: model output is not executed automatically. Critical actions go through approval rather than happening on their own.
- Disclosure: content generated by artificial intelligence is marked as such — the transparency requirement of Art. 50.
- Data in the EU: the platform and your database are in Frankfurt. Language model processing is the exception — the detail is on the Data security page.
5. Where the line runs
The certifications above belong to the infrastructure, not to 3Д Код ЕООД. Compliance with NIS2 and with the AI Act is carried by the entity that uses them — software does not make a company compliant and no supplier can assume that for you. What we can do: complete and sign your questionnaire, enter into a data processing agreement, and put in writing what sits underneath your application. Write to us from Contact.