The article argues that Article 20 of the EU’s NIS2 Directive puts personal legal accountability directly on CEOs and board members, not just IT teams – approving cybersecurity measures, overseeing their implementation, and being liable for failures are now explicit board duties, and “I wasn’t briefed” is no longer a valid defense. This is landing at a moment when AI is actively lowering the bar for attackers: the piece cites a self-propagating AI worm demonstrated by University of Toronto researchers and an AI-driven ransomware operation (“Jade Puffer”) that no longer requires a skilled human operator, both signs that breaches can now unfold in hours rather than weeks.

Several EU countries have already turned this into concrete financial exposure. Portugal caps individual board-member fines at €125,000 per serious infraction, Germany's BSIG law makes personal liability non-waivable (meaning a company legally cannot shield or indemnify its own executives), and Belgium has set formal self-assessment and certification deadlines for essential entities in 2026 and 2027. The European Commission has also layered on an AI Action Plan meant to push member states toward using AI defensively while tightening NIS2 enforcement - so the regulatory pressure and the AI threat are both accelerating at once.