From GDPR to NIS2 to the AI Act: How to deal with the EU’s increasing compliance pressure
Key 2026 compliance milestones at a glance
1. NIS2
Active enforcement phase; CCB supervision live; 18 April 2026 self-assessment deadline for essential entities now passed
2. EU AI Act
Prohibited practices ban in force since February 2025; high-risk system obligations deferred to December 2027 under the AI Omnibus agreement
3. CSRD
Wave 2 first reporting deferred to 2028 under Omnibus; 2026 is a preparation year for companies that remain in scope
4. DORA
Fully in force since January 2025; 2026 focus is ongoing supervision and enforcement
5. Data Act
Core obligations in force since September 2025; new product design requirements apply to connected products from September 2026
If you lead a legal team in Belgium, the past several years have felt like a continuous compliance sprint with no finish line in sight. GDPR set the tone. Then came new waves of EU legislation: NIS2, the EU AI Act, the Corporate Sustainability Reporting Directive, the Data Act, DORA. Each brought its own deadlines, its own specialist demands, and its own pressure on teams that were already stretched.
What is different about 2026 is not that this legislative agenda has suddenly appeared. It is that multiple directives and regulations are now hitting their enforcement and implementation phases simultaneously. Awareness has given way to obligation. And for many organisations, the gap between what their legal team can absorb and what compliance actually requires has never been more visible.
That gap is driving a very specific kind of demand: senior interim legal talent with specialist compliance expertise, deployable at pace, for exactly as long as the work requires.
What each piece of legislation is actually asking of legal teams
NIS2: cybersecurity becomes a board-level legal obligation
The NIS2 Directive, transposed into Belgian law in April 2024, significantly extends the scope of the original NIS legislation. Where previously only operators of essential services were covered, the Belgian NIS2 Law now reaches a much wider range of entities across energy, transport, healthcare, digital infrastructure, manufacturing, and beyond.
The legal implications are substantial. Companies need to map their obligations, assess supply chain risks, formalise incident reporting procedures, and ensure that senior management understands and can be held accountable for cybersecurity governance. This is not purely a technical exercise. It demands legal drafting, contract review, board-level advice, and ongoing monitoring.
The CCB’s self-assessment deadline for essential entities passed on 18 April 2026, and active supervision is now underway. For organisations that have not yet fully addressed their obligations under the Belgian NIS2 Law, enforcement is no longer theoretical.
The EU AI Act: obligations for a technology most companies are already using
The EU AI Act is an EU Regulation, meaning it applies directly in Belgium without requiring national transposition. It introduces a risk-based legal framework for artificial intelligence unlike anything the European regulatory landscape has seen before.
The prohibition on certain AI practices has been in force since February 2025, covering practices such as social scoring, workplace emotion recognition, and real-time biometric identification in public spaces. The broader high-risk system obligations, which will require documentation, human oversight mechanisms, and conformity assessments for AI systems in areas like recruitment, credit scoring, and law enforcement, have been deferred to December 2027 under the AI Omnibus agreement reached in May 2026.
That deferral does not reduce the legal workload. It changes its character. Most large Belgian organisations are already deploying AI tools in some capacity. Legal teams now need to audit existing AI deployments, determine which practices fall under the existing prohibitions, draft or update AI governance policies, and begin building compliance structures ahead of the 2027 obligations. That is significant, sustained specialist work.
For a broader look at how AI is reshaping the legal profession itself, see our article AI and the Legal Profession: From Efficiency Tool to Strategic Shift.
CSRD: sustainability reporting as a legal and governance obligation
The Corporate Sustainability Reporting Directive has been transposed into Belgian law through an update to the Belgian Code of Companies and Associations (FR: Code des sociétés et des associations, NL: Wetboek van Vennootschappen en Verenigingen). It shifts sustainability from a communications exercise to an audit-grade reporting obligation, but the timeline has shifted significantly under the EU Omnibus package.
Wave 2 companies, being large non-listed companies that were originally due to report for financial year 2025, have had their first reporting obligation deferred to 2028, covering financial year 2027. The Omnibus package has also narrowed the scope considerably: mandatory CSRD reporting now applies primarily to companies with more than 1,000 employees and more than €450 million in net annual turnover.
For legal teams, 2026 is therefore a preparation year rather than a reporting year. But that does not mean the work is light. Companies need to confirm whether they remain in scope under the revised thresholds, refresh their double materiality assessments, and build the governance and data collection infrastructure that audit-grade reporting will require. Legal counsel with expertise at the intersection of corporate governance, ESG regulation, and financial reporting is in real demand.
DORA and the Data Act: already in force, still generating legal work
DORA, the Digital Operational Resilience Act, has been directly applicable across the EU since January 2025. For financial entities, including banks, insurers, investment firms, and payment institutions, the 2026 focus has shifted from initial implementation to continuous supervision and audit readiness. ICT third-party risk management, incident reporting obligations, and register of information requirements are all live. Legal teams in the financial sector are managing ongoing compliance, contract reviews, and the management accountability implications that come with an active enforcement environment.
The Data Act, also an EU Regulation, has been in force since September 2025. Its core obligations around user access rights and B2B data sharing contract fairness are already applicable. A further milestone arrives in September 2026, when new product design requirements take effect: connected products placed on the EU market from that date must be built with accessible data pathways for users. For companies manufacturing or distributing connected products in Belgium, this creates concrete legal work around contract review, product compliance, and governance.
Why interim talent has become the strategic response
There are a few ways organisations typically respond to a surge in legislative compliance demand:
- They can ask their existing team to absorb the workload, which tends to produce burnout and bottlenecks.
- They can launch a permanent hire process, which takes time that the regulatory calendar does not allow.
- Or they can bring in specialist interim legal counsel: senior professionals with direct, hands-on experience in the relevant legislation, available quickly, and deployable for exactly the duration the work requires.
The third option has become noticeably more popular, and the reasons are structural, not just practical.
Compliance projects have a clear beginning and end. A NIS2 gap analysis under Belgian law does not run forever. An AI Act prohibition audit has a defined scope. A CSRD governance structure, once built, becomes embedded in the organisation. These are precisely the kinds of assignments where interim legal management excels: high-value, time-bounded, expertise-intensive work that delivers a tangible output.
There is also a cost dimension that legal leaders increasingly understand. Hiring a permanent specialist for a six-month compliance project is inefficient. Engaging an external law firm for sustained internal advisory work is expensive. A senior freelance legal consultant, brought in at the right moment with the right background, offers a sharper balance of cost, quality, and agility.
For a practical guide to getting this right, see our article on when to bring in interim legal talent and how to get it right. And for a fuller overview of how the model works, visit our legal interim management page for companies.
What strong interim legal talent looks like in this context
Not every experienced lawyer is the right fit for compliance-intensive interim work. The profiles generating the most demand in 2026 share a few consistent characteristics:
- They have real depth in the relevant legislation. General commercial law experience is valuable, but what legal leaders are specifically seeking are practitioners who have worked directly on NIS2 implementation under Belgian law, AI governance under the AI Act, or sustainability reporting under CSRD, not those who have simply read the texts.
- They combine legal expertise with commercial pragmatism. Advice that is technically correct but operationally unworkable does not serve organisations well. The best interim legal consultants understand how to translate the obligations in a directive or regulation into policies, contracts, and internal processes that organisations can actually implement.
- They are genuinely autonomous. Interim managers at the senior level should be able to step in, assess the situation, and drive progress without requiring extensive hand-holding. That is the value proposition.
How Limine connects compliance expertise to the organisations that need it
At Limine, we have seen a clear shift in the briefs we receive from clients. A year ago, the majority of interim requests were for coverage of parental leave or vacancy bridging. Today, a growing proportion are project-based compliance assignments, with NIS2, the AI Act, and CSRD consistently at the top of the list.
What makes Limine’s approach effective in this context is the depth of vetting we apply before a consultant ever appears on our platform. Every legal professional in our network has been personally assessed by our team. We verify not just their CV, but their actual expertise, their working style, and the quality of their prior engagements. When a client needs an interim legal manager with genuine NIS2 or AI Act experience, we can move quickly and with confidence, because we already know who in our network has that background.
Our digital platform also means that transparency is built into the process. Clients can review consultants’ profiles, rates, and availability directly, without the friction and cost of traditional recruitment intermediaries.
You can explore our on-demand legal solutions if your compliance needs are more project-specific, or visit our for companies and law firms overview for the full picture of what we offer.
The outlook beyond 2026
The legislative pipeline shows no sign of easing. High-risk AI system obligations under the AI Act are now anchored at December 2027, giving organisations more runway but also less excuse for delay. CSRD preparation work is live for companies that remain in scope under the revised Omnibus thresholds. NIS2 enforcement by the CCB is active and growing and the Data Act’s product design obligations arrive in September 2026.
Legal teams that try to handle all of this with existing headcount risk more than overload. They risk being in reactive mode when regulatory pressure becomes regulatory exposure.
The organisations that will navigate this period most effectively are those that plan their legal capacity with the same intentionality they bring to their business strategy. That means knowing which compliance priorities require permanent expertise embedded in the team, which ones call for a defined interim engagement, and which can be handled through targeted on-demand support.
If you are working through that question, our eBook The Strategic Advantage of Freelance Legal Consultants offers a practical guide to staffing a legal team through a period of sustained regulatory pressure.
And if you already know you need specialist capacity, we would be glad to help you find it. Get in touch with our team.
Get in touch
Facing a gap in your legal team? Browse available senior legal consultants on the Limine platform, or talk to us about bridging your vacancy while we search for your permanent hire.