TÜV Rheinland points to growing regulatory requirements under the Cyber Resilience Act, the NIS2 Directive and the EU AI Act. Training on Privacy and artificial intelligence should increasingly cover cybersecurity and digital resilience as well, the company says.
Regulatory requirements for companies in the areas of Privacy and artificial intelligence (AI) are increasing. Several new or recently enacted EU regulations require additional expertise from those responsible and their employees. At the same time, AI is being used more widely in daily business operations, while the threat from cyberattacks remains high.
According to TÜV Rheinland, this is increasing the need for qualification within companies. “Requirements around Privacy, AI and cybersecurity are increasingly intertwined in day-to-day business. Training on Privacy and AI should therefore increasingly include requirements on cybersecurity and digital resilience,” says Sandra Fahling, Business Manager at TÜV Rheinland Akademie, according to a statement from the company. What matters most, she says, is that those responsible and employees know which requirements and risks are relevant to their particular role.
Three regulations in focus
According to TÜV Rheinland, the General Data Protection Regulation (GDPR) remains the central framework for handling personal data. In addition, requirements now arise from three further pieces of regulation.
The EU Cyber Resilience Act primarily addresses the cybersecurity of products with digital elements. Since September 11, 2026, manufacturers have been required to report actively exploited vulnerabilities and serious security incidents that affect product safety. Further requirements under the regulation take effect from December 2027.
The EU’s NIS2 Directive focuses more directly on the cybersecurity of companies and organizations. Entities covered by NIS2 must systematically manage cyber risks, register, and report significant security incidents. Required risk management measures also include cybersecurity training. Germany’s national implementation of the directive has been in force since December 2025.
Since August 2, 2026, new transparency obligations under the EU AI Act have also applied. People must generally be informed when they interact directly with an AI system, unless this is already obvious. Certain AI-generated or manipulated content is also subject to labeling requirements. Since February 2025, the AI Act has additionally required companies to promote AI literacy among employees who work with AI systems. Where AI systems process personal data, GDPR requirements continue to apply as well.
Qualification affects several business areas
Training is not only relevant for Privacy officers and IT specialists, TÜV Rheinland states. Those responsible and employees in HR, sales, operations and management must also know which requirements apply to their work and how risks can be minimized. TÜV Rheinland recommends a qualification approach that combines legal, organizational and technical questions and accounts for different roles within a company. TÜV Rheinland Akademie offers corresponding training courses covering privacy, AI, and cyber and information security, among other topics.
Background: TÜV Rheinland
TÜV Rheinland is an internationally active testing service provider headquartered in Cologne, Germany. According to the company, it employs more than 29,000 people at around 500 locations in about 50 countries, where it tests, inspects and certifies products, installations and processes. Annual revenue is reported by the company at approximately 3 billion euros. TÜV Rheinland has been a member of the UN Global Compact since 2006.
Outlook: Privacy Conference on November 5
These topics also feature in the program of the 8th TÜV Rheinland Privacy Conference, taking place on November 5, 2026, as a hybrid event in Cologne and online. The agenda includes the handling of unmanaged AI use in companies (“shadow AI”), common errors in AI-supported systems, and questions of privacy management.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de