Germany’s NIS2 implementation requires approximately 30,000 companies starting in 2026 to conduct mandatory annual cybersecurity training for their employees.
Bavaria’s police use Palantir for data analysis, but data protection officers doubt whether the U.S. software can actually be controlled when handling sensitive government data.
German intelligence services gain statutory authority to actively penetrate foreign attackers’ IT systems, copy and delete data, and deliberately spread disinformation under strict conditions.
The NIS2 Directive requires approximately 30,000 German businesses to implement uniform IT security standards and establishes binding notification requirements for security incidents.
From July 2025, companies must train all employees in cybersecurity and AI governance under NIS2 and the EU AI Act, with documented programs and penalty risks for non-compliance.