IT regulations 2026: a compliance and strategy guide
Navigating the technology legal ecosystem in 2026 has become as critical as the software architecture itself. IT regulations 2026 are not just compliance requirements: they are the framework that defines trust in a digital society. The number of regulations, their application deadlines and their overlaps create confusion in many organisations. In this guide we analyse the key regulations, their practical implications and how to build compliance into technology project management.
IT regulations 2026: an overview
This unprecedented European regulatory ecosystem affects practically every sector. The three fundamental pieces of legislation are the EU AI Act (regulation of artificial intelligence), NIS2 (cybersecurity of networks and information systems) and DORA (digital operational resilience in the financial sector).
An interconnected framework
In addition, these regulations do not operate in isolation: they complement and overlap with one another. A financial organisation developing an AI system for credit scoring must comply simultaneously with the EU AI Act (for using AI in decisions about people), with DORA (for operating in the financial sector) and with NIS2 (for managing critical infrastructure). Understanding this regulatory framework in an integrated way is essential to avoid duplication and optimise the compliance effort.
IT regulations 2026: the EU AI Act
The EU AI Act is the world’s first regulation specifically about artificial intelligence. It came into force in August 2024, with phased application deadlines running to 2027.
Classification by risk level
The regulation classifies AI systems into four levels: unacceptable risk (prohibited), high risk (with strict obligations), limited risk (transparency obligations) and minimal risk (no specific obligations). For this reason, any project that includes AI components must start by classifying the system according to these levels before moving forward with its development.
Obligations for providers and deployers
The EU AI Act distinguishes between providers (those who develop the system) and deployers (those who use it in their organisation). According to AESIA, the Spanish Agency for the Supervision of AI, both profiles have differentiated obligations ranging from technical documentation to fundamental-rights impact assessment. Within this regulatory framework, the EU AI Act is the piece that will have the greatest impact on development and project-management teams.
IT regulations 2026: NIS2
Without doubt, the NIS2 directive (Network and Information Security) is the key piece on cybersecurity. It replaces the original NIS and significantly expands its scope and requirements.
Affected sectors and new obligations
NIS2 is no longer limited to traditional critical infrastructure: it affects sectors such as public administration, space, waste management, food and postal services, among others. In addition, it imposes concrete obligations for risk management, incident notification within very tight deadlines (24 hours for the initial alert), cybersecurity governance at board level and supply-chain oversight.
Management responsibility
On the other hand, a fundamental aspect of NIS2 is that it holds management bodies directly responsible for compliance. Executives who fail to ensure the implementation of adequate cybersecurity measures can be held personally liable. Because of this, the regulation has raised cybersecurity from a technical topic to a board-level matter.
IT regulations 2026: DORA
On the other hand, the DORA regulation (Digital Operational Resilience Act) complements this framework with specific requirements for the financial sector: banking, insurance, fund managers, payment platforms and critical ICT service providers.
Digital operational resilience
DORA requires financial entities to demonstrate their ability to withstand, respond to and recover from serious technology incidents. In addition, it includes obligations for advanced penetration testing (TLPT), ICT risk management, incident reporting and oversight of third-party technology providers.
Third-party management
DORA introduces a framework of direct oversight over ICT providers deemed critical. If your company provides technology services to the financial sector, this regulation affects you even if you are not a financial entity. Contracts with clients in the sector must include specific clauses on resilience, auditing and notification.
IT regulations 2026: other relevant regulations
Besides the big three, IT regulations 2026 include other rules that technology leaders must keep on their radar. The EU Data Act deserves a chapter of its own for how it changes data governance in AI projects.
CRA (Cyber Resilience Act)
The CRA sets mandatory cybersecurity requirements for digital products with connected elements, from IoT devices to commercial software. Manufacturers and distributors must guarantee the security of their products throughout their lifecycle, including security updates for a minimum period.
ENS (National Security Framework)
Finally, in Spain, the ENS establishes the security principles and requirements for public administration and its technology providers. Any company working with the Spanish public sector must comply with the ENS in addition to the European regulations.
IT regulations 2026: how to build compliance into your projects
IT regulations 2026 should not be treated as an isolated compliance exercise, but as a cross-cutting axis of project management.
Compliance by design
The first step is to include the regulatory assessment in the initiation phase of every project: which regulations apply? What risk level does the system have? What documentation do we need? Compliance is built into the project backlog, not into a separate document written at the end.
The PM as guardian of compliance
Responsibility for compliance cannot fall on the legal department alone. The Project Manager is the one with the complete view of the project and must ensure that every sprint, every deliverable and every architecture decision takes the applicable IT regulations 2026 into account. In conclusion, regulatory compliance is the new core competency of any technology project leader. Organisations that build it in by design will not only avoid penalties: they will build products and services the market trusts.
Frequently asked questions about IT regulations 2026
One of the areas that generates the most friction in compliance is the unauthorised use of AI tools by employees. I cover it in detail in shadow AI in the company.
Regulatory compliance in the cloud goes hand in hand with cost governance. I cover it in detail in FinOps cloud 2026.
Related frameworks: the DORA regulation and compliance in NIS2 projects.
To meet these frameworks in practice, see the EU AI Act compliance checklist for August 2026 and, if you work with generative AI, the guide on secure enterprise RAG and data-leak prevention.
The key IT regulations in 2026 are: the EU AI Act (regulation of artificial intelligence), NIS2 (cybersecurity of essential infrastructure), DORA (digital operational resilience of the financial sector), the CRA (Cyber Resilience Act on digital products), the ENS (National Security Framework in Spain), the GDPR (data protection), and the Data Act on data generated by IoT devices.
NIS2 regulates the cybersecurity of essential infrastructure (energy, transport, banking, health, digital). DORA is specific to the financial sector and focuses on operational resilience against ICT risks. The EU AI Act regulates AI systems according to their risk level. All three can apply simultaneously: for example, a bank that uses AI must comply with all three.
Penalties can be very high: NIS2 up to €10M or 2% of global turnover; DORA up to 1% per day until compliance; the EU AI Act up to €35M or 7% of global turnover for prohibited uses; the CRA up to €15M or 2.5% of turnover; the GDPR up to €20M or 4% of global turnover. In addition, executives can be personally disqualified.
More on IT regulations 2026
Responsibility rests with company management (NIS2 and DORA state this explicitly), but the operation is distributed between the CISO (cybersecurity), the DPO (personal data), the Compliance Officer, the AI Project Manager (AI systems), the IT managers and the Project Managers of each initiative. The AI Project Manager acts as the cross-cutting integrator of all these requirements.
The “compliance by design” approach builds compliance in from the initiation phase: (1) analysis of the applicable regulations, (2) a DPIA/FRIA if there is personal data or high-risk AI, (3) security requirements as acceptance criteria, (4) technical traceability from the code, (5) audit milestones in the project plan, and (6) mandatory team training. It drastically reduces the cost versus retroactive compliance.
A migration that cannot stop the business? That is what I have done for thirty years.
See the nine case studies