Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

• measures taken or proposed to address or mitigate adverse effects; • contact details of the DPO or relevant contact point; and • any additional relevant information (eg, forensic insights, containment measures, system logs). 6.2 Cybersecurity and AI Belgium’s AI-specific cybersecurity obligations are now primarily driven by the directly applicable EU Artificial Intelligence Act (AI Act), which imposes secu - rity by design and security by default requirements throughout the life cycle of AI systems. Under the AI Act, high-risk AI systems must be tech - nically resilient, protected against data poisoning, model evasion and other adversarial attacks, and sup - ported by secure logging, monitoring and post market surveillance mechanisms. Providers and deployers of high-risk AI systems must also address supply chain and model component risks, ensuring that upstream general purpose or foundational models are subject to appropriate due diligence, vulnerability testing and mitigation measures. The AI Act’s incident reporting framework requires notification of “serious incidents”, including systemic cybersecurity failures, while any personal data breach triggered by an AI security incident must also be noti - fied under Belgium’s GDPR regime. For entities already subject to NIS 2, the AI Act oper - ates alongside Belgium’s 24-hour early warning and 72-hour incident notification rules, creating a layered reporting landscape. Belgian regulators have empha - sised that AI-related obligations do not displace exist - ing cybersecurity or data protection duties; instead, the AI Act complements the GDPR’s security require - ments by imposing additional model-specific safe - guards and enhanced accountability for organisations developing or deploying AI systems. 6.3 Cybersecurity in the Healthcare Sector Cybersecurity requirements in Belgium’s healthcare sector stem from a combination of EU-level product regulations, horizontal cybersecurity legislation and sector-specific supervisory expectations. Healthcare providers, hospitals, medical device manufacturers

and operators of electronic health record (EHR) sys - tems must comply not only with the GDPR and NIS 2 Act but also with the security and safety require - ments embedded in the EU Medical Devices Regula - tion (MDR). Belgium’s Federal Agency for Medicines and Health Products (FAMHP) plays a central role in supervising device-related incidents, while the DPA oversees data protection and breach notification obli - gations. Healthcare Providers and Hospitals Hospitals and many other healthcare providers qualify as “essential” or “important” entities under the NIS 2 Act. As a result, they must implement proportionate technical and organisational cybersecurity measures, including: • risk assessments; • identity and access management; They must also comply with Belgium’s multi-stage incident reporting framework, which requires an early warning within 24 hours, a 72-hour incident notifica - tion, and a final report within one month. These expec - tations are reinforced by sector-specific guidance and broader national trends toward assurance-based supervision. Where incidents involve personal data such as patient records, healthcare providers must also comply with notification obligations under the GDPR. Medical Devices and Software as a Medical Device (SaMD) The EU Medical Device Regulation (MDR) imposes detailed cybersecurity obligations on manufacturers. Devices incorporating software – including SaMD and connected medical devices – must be “developed and manufactured in accordance with the state of the art”, including robust information security controls. Manu - facturers must define minimum IT network character - istics, hardware requirements and security controls, including protections against unauthorised access. • network segmentation; • continuous monitoring; • incident handling; and • business continuity planning.

49 CHAMBERS.COM

Powered by