Recital 51
Directive on the security of network and information systems · UE 2022/2555
| (51) | Member States should encourage the use of any innovative technology, including artificial intelligence, the use of which could improve the detection and prevention of cyberattacks, enabling resources to be diverted towards cyberattacks more effectively. Member States should therefore encourage in their national cybersecurity strategy activities in research and development to facilitate the use of such technologies, in particular those relating to automated or semi-automated tools in cybersecurity, and, where relevant, the sharing of data needed for training users of such technology and for improving it. The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimisation, fairness and transparency, and data security, such as state-of-the-art encryption. The requirements of data protection by design and by default laid down in Regulation (EU) 2016/679 should be fully exploited. |
In Luxembourg, the ILR (national cybersecurity authority designated by the law of 28 July 2023 as amended by the law of 28 July 2025) and the CNPD coordinate their inspections when an essential or important entity deploys AI detection processing personal data. The law of 28 July 2023 on cybersecurity explicitly refers to the GDPR framework for any technical measure involving processing, opening the door to a joint ILR + CNPD inspection on the same AI tool.
Luxgap practice: document every AI brick in a single file opposable to both authorities (NIS 2 purpose + GDPR legal basis + DPIA + encryption measures), and have the privacy by design configuration validated before go-live.