RAVNSecurity

Regulation · SE/EU

The rules tighten on 1 October.By then, know where your test runs.

Johan Almgren · Pentester and founder

Published 2026-07-31 · 7 min read

The calendar is the easy part. The law has applied since January, the rest of the rules arrive in October. The hard question is a different one: when an AI helps test your application, where in the world does that AI run, and what does it get to see?

What the law says

Sweden's cybersecurity act was issued on 11 December 2025 and took effect on 15 January 2026. It replaces an older law from 2018 and is how Sweden implements the EU's NIS2 rules.[01]

The second chapter of the act lists the measures an organisation has to take. One point requires policies and procedures to assess the effectiveness of the security measures. In plain terms: you need a way to find out whether your security work actually works, not merely that it exists.[01]

The supervisory authority gets tools of its own. It can carry out recurring security audits, or have an independent body do it. It can also run security scans against a supervised organisation, in cooperation with that organisation.[01]

15 jan · 1 okt

The act took effect on 15 January 2026. The regulations on security measures and on management training take effect on 1 October 2026. The rules on security audits and security scanning start the same day.[02]

What the law does not say

Here is something you will be told wrongly. NIS2 does not require penetration testing. The words do appear in the directive, but in a background recital about companies that sell security services. They are not in the list of obligations.[03]

The obligations cover two things instead. Security in how systems are acquired, developed and maintained, including how you handle vulnerabilities. And being able to assess whether your measures are effective.[03]

We say that plainly, because the opposite is easy to sell. Nobody can show you a clause saying you have to buy a pentest. A test is one of the few ways to answer the question with evidence in hand, but that is our conclusion, not the law's words.

The GDPR is clearer on this. It requires a process for regularly testing, assessing and evaluating the effectiveness of security measures. If you handle personal data, the requirement to test regularly has been sitting there since 2018.[04]

A duty to assess effectiveness is not a duty to buy a pentest. It is weaker than the sales pitch, and stronger than most people assume.

What actually leaves the country

An ordinary security tool sends in prepared test patterns and only looks at whether the answer comes back right or wrong. An AI has to do something else. It has to read the answer in order to understand it and decide what to try next.

In practice that means a fair amount of your application's content is passed on to the AI running the test. Page content, error messages, sometimes technical error output that reveals how the system is built, sometimes code excerpts if you hand over source code, and the running text in which the AI describes what it is doing.

All of it goes to the machine where the AI model runs. If that machine is in the United States, the material leaves European jurisdiction, meaning the reach of European rules, the moment it is sent. That is true regardless of where the supplier is incorporated, and regardless of what their website says.

Why the country the machine sits in matters

US law can in some cases compel US companies to hand data to US authorities, even when the data is stored in Europe. That question was put directly to Microsoft under oath in the French Senate in the summer of 2025.[05]

Non, je ne peux pas le garantir, mais, encore une fois, cela ne s'est encore jamais produit.
Anton Carniaux · Microsoft France · franska senaten · 2025-06-10

He was asked whether he could guarantee that French citizens' data would never be handed to US authorities without French agreement. The answer was no, with the addition that it had never yet happened. It is the most honest description of the situation anyone has put on the record.[05]

The legal picture is not settled either. In 2020 the EU Court of Justice struck down the data transfer arrangement with the United States, in the ruling usually called Schrems II. The court held that anyone sending personal data out of the EU must assess the recipient country's laws themselves.[06]

The arrangement that replaced it is still in force. But it has been challenged in court, and the appeal now sits with the EU Court of Justice. Our point is not that it will fall. It is that you cannot build your risk assessment on the question being settled, because it is not.[07]

Four questions that make sovereignty measurable

Sovereignty is a large word that often means nothing. It becomes concrete only when you can get answers to four questions about a specific engagement, after the fact, with evidence.

  • Where did the AI model run, and whose laws applied there?
  • What data left our systems, and in what form?
  • Which subcontractors were involved while it ran?
  • How long is the test material kept, and when is it deleted?

Those questions belong in the scoping conversation and the answers belong in the quote. If a supplier cannot answer them, sovereignty is just a colour on a website.

The European Commission is moving the same way. A legislative proposal from June 2026 sets out a four-step scale for how sovereign a cloud service is. The lowest step is data processed on European infrastructure. The highest is full control of the software supply chain, with no involvement from outside the EU.[08]

What to demand, from us and from everyone else

  • That the supplier names the AI model and where it runs, in the quote, not in an email afterwards.
  • That it is written down what data the test is allowed to see, and what never leaves your systems.
  • That a named person is accountable for the engagement and for every finding in the report.
  • That every finding is checked by hand before it reaches the report. Ask what was discarded, too.
  • That the test material is deleted, with a date or a number of days stated.

None of that requires you to choose us. It only requires whoever you choose to have answers. The rules take effect on 1 October, and that is late to start wondering where the AI runs.

Sources

  1. [01]Cybersäkerhetslag (2025:1506)Sveriges riksdag · 2025-12-11
  2. [02]Tidsplan för införandet av cybersäkerhetslagen i Sverige (hämtad 2026-07-31)NCSC · 2026-07-31
  3. [03]Direktiv (EU) 2022/2555 (NIS2), artikel 21.2EUR-Lex · 2022-12-14
  4. [04]Förordning (EU) 2016/679 (GDPR), artikel 32EUR-Lex · 2016-04-27
  5. [05]Compte rendu, commission d'enquête sur la commande publique, audition de Microsoft FranceSénat · 2025-06-10
  6. [06]Dom i mål C-311/18, Schrems IIEU-domstolen · 2020-07-16
  7. [07]European Court of Justice to Review Challenge to EU-US Data Privacy FrameworkWilmerHale · 2025-12-01
  8. [08]Cloud and AI Development ActEuropeiska kommissionen · 2026-06-03
All articles
Next step

Test it beforesomeone else does.

Free scoping. Fixed price before we start.

[AI] depth and pace[HUMAN] judgement and accountability[EU] residency in Sweden