Security & AI training · NIS2 and the EU AI Act

The training your team will actually finish.

National laws implementing the NIS2 Directive made security training a legal duty for the organisations in their scope, and the EU AI Act added AI literacy on top of it. Cyberact covers both in two minutes a day, in a format people don't resent, with every lesson mapped to the clause it evidences.

249
lessons live
8
frameworks mapped
2 min
per lesson

Founding customers

Your logo here.

We are new, and our first customers help decide what we build next. With your permission, your logo goes up in this spot.

Start for free
  • Your logo
  • Your logo
  • Your logo
  • Your logo
  • Your logo
  • Your logo

Cyberact in 36 seconds

Why training became the law, and what it looks like done well.

The problem

You're already paying for training nobody remembers.

Annual compliance modules get clicked through in eight minutes and forgotten by February. The certificate still prints. The risk doesn't move.

We measure what stuck

Everyone reports completion. We weight retention at 40% of the readiness score — because a course someone clicked through in eight minutes protects nobody.

The AI Act is already covered

Article 4 has applied since 2025, and in July 2026 it became a duty to take measures that support AI literacy, with no set level required. Most vendors bolted on a ChatGPT module. We built two whole paths — and the record that evidences them.

Built in the EU, under EU law

Cyberact is designed and built in Finland, with EU law as the starting point rather than something retrofitted afterwards. Digital sovereignty has become a procurement question across Europe — and when your training record is the legal evidence, whose jurisdiction holds it is not a detail. Ours stays in the EU, hosted in Germany.

Does this apply to you

Three questions, and you know which class you are in.

NIS2 does not ask whether you would like to be in scope. Under the Directive it falls out of your sector and your size, and you already know both. Your country's NIS2 law applies the same test and may add to it. Nothing here is stored and no email is asked for.

Staff

Turnover

Choose a sector.

Self-test

A supervisor does not start with your firewall. They start with these three.

Article 20 puts the duty on the management body. When the authority arrives, the opening questions are not technical — they come out of the board papers. Answer honestly; nobody can see this.

01Show me where the management body approved the risk-management measures, and when.

NIS2 Article 20(1), as your country's NIS2 law transposes it. Not that the measures exist — that the management body approved them, dated and minuted.

02Show me how the management body has overseen them since.

Meetings, decisions, and what changed as a result. Oversight that changed nothing is hard to tell apart from oversight that did not happen.

03Show me that the members of the management body have followed training.

Article 20(2) of the Directive requires members of the management body to follow training. National laws word it differently (Finland's, for example, asks management to be sufficiently familiar with cybersecurity risk management), but the training record is the easiest way to show it.

Compliance

One programme. Every box you already have to tick.

In the EU this stopped being a nice-to-have. NIS2 applies through the national law of every member state, the AI Act and the Cyber Resilience Act apply directly across the EU, and awareness training is also named in your ISO certificate, your SOC 2 report, your PCI scope and your insurance renewal. Cyberact maps each lesson to the specific clause it evidences.

FrameworkWhat it requires of you
NIS2 DirectiveArt. 20 / 21Basic cyber hygiene and cybersecurity training are among an in-scope entity's risk-management measures (Art. 21(2)(g)). The management body approves and oversees them, and its members are required to follow training (Art. 20). Your country's NIS2 law sets out the detail.
SOC 2CC1.4 / CC2.2Show staff are competent for their control responsibilities, with evidence.
ISO 27001Annex A 6.3Awareness, education and training: an Annex A control you apply through your Statement of Applicability.
GDPRArt. 32 / 39Staff awareness can be part of the organisational security measures Article 32 asks for, and awareness-raising and training of staff are a task of the DPO, where you have one (Art. 39).
EU AI ActArt. 4Take measures to support AI literacy for anyone using AI on your behalf. Article 4 carries no fine of its own; national supervision applies from August 2026, on terms each country sets. The training record is the whole artefact — Article 4 leaves nothing else behind.
CRAArt. 14If you make software and market it under your own name, an actively exploited flaw gets an early warning within 24 hours — since September 2026. The Act asks for no training; the deadline depends on whoever hears first knowing what starts the clock.
PCI DSS12.6An awareness programme, at least annually, with proof of participation.
Cyber insuranceRenewalAsked on every underwriter questionnaire. Affects your premium.

Evidence pack

One-click CSV: every person, every control, coverage and score, dated. That's what the auditor asks for.

Retention-adjusted risk

A single number blending completion, quiz quality and what people still remember weeks later.

Board report

A print-ready report for the board and the auditor, with an AI-written summary.

AI leverage

Compliance is the floor. What your team does next is the upside.

Article 4 makes supporting AI literacy something you have to do. Worth More is the path your team opens anyway, because it is the one that pays them back — 41 lessons on where their hours actually go, how to get output they'd send without rewriting, and how a saved hour becomes capacity instead of a shorter afternoon.

41
lessons in the path
8
modules, from basics to business case
Art. 4
the obligation it evidences

Start with the week, not the tool

Most AI training teaches features. This starts by auditing where your people's hours actually go, then hands over only the work a model is genuinely good at — repetitive, low-stakes, and fast to check.

Output you'd send without rewriting

Context, one worked example, and constraints instead of adjectives. Habits that survive the next model, rather than prompt tricks that expire with it.

One person's trick becomes the process

A prompt that works is a written-down process. The path covers sharing it, standardising a house style, and keeping a human in exactly the places that need one.

Hours only count when you spend them

The last module is the business case: turning a saved hour into capacity, quality, or work you couldn't afford before — and putting a number on it the person holding the budget will accept.

How it works

Four steps, every day.

  1. 01

    Pick a path

    Six paths, from phishing and payment fraud to data protection, how AI actually works, how to get real work out of it, and what the law asks of management.

  2. 02

    Listen for 2 minutes

    A focused micro-lesson with a simple animation. It reads itself aloud, so people can just listen.

  3. 03

    Prove it in a quiz

    A few questions with real explanations. Miss one and it comes back tomorrow, not never.

  4. 04

    Keep the streak

    A daily quiz spaces the review out. That's what turns a session into a memory.

The curriculum

Six paths people open on purpose.

Written for the person doing the job, not the auditor reading the report — which is why people finish it. The security paths make you harder to fool. The AI paths teach what employers are hiring for right now: how these models actually work, and how to get real work out of them. Skills that follow you to the next job, not a certificate that expires.

Attack Surface

Every way in that runs through a person — and how to close it.

  • Phishing & scams
  • Passwords & accounts
  • Using AI tools safely
  • Devices & networks
  • When the risk arrives from outside
  • When something goes wrong
  • Where the work actually lives
  • When the rules apply to you
  • Where the old advice runs out
  • When your product is the risk

Follow the Money

The scams aimed at your inbox, your phone and your finance team.

  • How the con starts
  • Invoice and payment fraud
  • Voice, video and text
  • Scams that walk into the office
  • The controls that actually hold
  • The first hour after
  • Money that doesn't come back

Need to Know

Who can see what, why it matters, and what happens when data escapes.

  • What actually counts as data
  • Need to know, not nice to know
  • Sharing without leaking
  • Keeping it, then losing it properly
  • People have rights over this
  • When data escapes
  • The ordinary moments

Inside the Machine

How AI actually works, where it breaks, and how not to get burned.

  • How language models work
  • Prompting well
  • Giving a model your knowledge
  • Agents and tools
  • Judgement
  • Shipping AI responsibly
  • Feeding the model well

Worth More

The AI skills that keep you relevant — and turn up in your next pay review.

  • Where the hours actually are
  • Getting output you can send
  • The everyday jobs
  • From your habit to the team's
  • Automating a process
  • Turning hours into business
  • Doing it safely
  • The AI Act in practice

On the Hook

What the law asks of the people who approve the measures — and carry the liability.

  • What the law asks of you personally
  • The ten measures
  • When the clock starts
  • Supply chain and contracts
  • AI risk tiers and the red lines
  • AI in the workplace
  • Evidence and supervision
  • The law on what you sell
This weekToday
1Aino K.940
2Mikko L.875
3Sanna V.810
4Jukka P.765

Engagement, honestly

Competition that doesn't become pressure.

Opt-in leaderboards: only the people in your own organisation who chose to join appear on them. No lives, no countdowns, no loot boxes, and a streak freeze so one missed day doesn't undo a month.

Opt-in by defaultYour organisation onlyStreak freeze included

For managers

Know exactly where your risk is.

The Platform + manager console + audit plan adds the console: audit readiness per framework, a competency matrix by department, the roster, and an evidence export.

  • Audit readiness across every mapped control
  • Competency by department — see which team is the gap
  • Retention-adjusted risk, trended over time
  • Evidence pack and board summary, exportable
Manager console

Huomiva Health · this week

▲ readiness

Audit ready

54%

Risk score

27

Active

82%

ISO 2700155%
SOC 248%
GDPR19%

Guides

What the law expects your people to know

Short guides to NIS2, the EU AI Act and the other duties behind security training.

All guides