Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

• If an AI system processes personal data, the GDPR continues to apply. • If the organisation falls under regimes such as NIS2 (and/or DORA for the financial sector), an AI-related incident affecting availability, integrity, or confidentiality may simultaneously trigger obliga - tions under those frameworks. Thus, the AI Act adds the AI-specific layer: integrity of model behaviour, protection against ML-specific attacks, and reporting of serious incidents associated with AI-related risks. Overall, the “cyber resilience” of AI systems in Greece will be assessed on three simultaneous levels: • infrastructure and operational security (classical cybersecurity); • personal data security (GDPR where applicable); and • security and resilience of the AI model and its behaviour (AI Act). Organisations that develop or use high-risk AI sys - tems therefore need a documented risk assessment that addresses ML-specific threats, technical defence measures, and incident-reporting procedures cover - ing all parallel regulatory obligations. AI-Related Cybersecurity Obligations in Greece AI-related cybersecurity requirements in Greece stem from a combination of national law and EU legislation. Primarily, the following are relevant. Law 4961/2022 – Emerging Technologies Law (AI, IoT, Blockchain) This national law established Greece’s earliest hori - zontal framework for AI governance. It includes obli - gations relating to responsible use, risk management, and data governance, applying across sectors. It also introduces risk-control requirements relevant to cybersecurity. EU AI Act (Regulation 2024/1689) Applicable directly in Greece, the AI Act imposes man - datory obligations on high-risk AI systems, including cybersecurity-specific requirements.

Under the EU AI Act, high-risk AI systems must include cybersecurity by design, encompassing: Robustness, accuracy, and resilience High-risk systems must be resilient to: • adversarial attacks; • data poisoning;

• model manipulation; • model extraction; and

• malicious inputs or “hallucination attacks”. Secure development life cycle requirements The AI Act requires:

• secure coding practices; • logging and monitoring;

• model traceability and version control; and • testing for robustness and security failures. Supply chain security AI operators must evaluate the security of: • datasets; • pre-trained models; • embedded components (libraries, frameworks); and • remote data-processing elements. Technical documentation and risk assessment Providers must maintain: • risk-management documentation; • logs that enable incident reconstruction; and • security-testing results. Under Greek Law 4961/2022, organisations using AI systems that affect employees or users must also: • maintain registers of AI systems; and • take measures to mitigate risks such as misuse, bias, and system vulnerabilities. Common requirements under both the EU AI Act and Greek Law 4961/2022 Dataset integrity and provenance High-risk AI systems must undergo validation of:

181 CHAMBERS.COM

Powered by