Skip to main content
STATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGETSTATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGET
AGICY.AI
StackTechnology OverviewRISC-V sovereign stackComputeBare-metal EU compute
FacilitiesData CentersWorldwide map & trackerVasilikos Campus42MW sovereign campus briefingSustainability100% renewable mission
HardwareHardware FleetVendor hub · phased COD roadmapTenstorrent GalaxyPhase 1 Blackhole fleet (pre-COD)AESOLAR AlpineEnergy stack · hail-class PV + BESSAMD HeliosPhase 2 open rack-scale (eval · pre-COD)CerebrasPhase 2 · wafer-scale eval (pre-COD)
Submit your Hardware for reviewPropose accelerators for the Vasilikos fleet
AIAI Web SearchNew!Sovereign AI search · AGICY & the webAI My MapsNew!Smart Maps · voice routing · agentsAgents Trading CryptoBeta · New!Live paper-trading arena · BTC · ETH · SUIAI Video SearchNew!Find AI videos · avatars · films · adsAdvertiseSearch ad program · how it works · board ranks
GatewayCopperwayEU-sovereign OpenAI-compatible gatewayTry PlaygroundNewLive Copperway demo · PII vaultSovereign Exchange5-year cross-org sovereign plan
ProductsReserve CapacityPre-construction LOI tiersMarketplaceCompute marketplaceGPUs Rent LiveLiveEU partner GPU now · until CODCompute VouchersSovereign compute creditsModel LeaderboardFrontier model rankingsPricingSubscription tiers
WorkloadsComputeBare-metal EU inference & trainingCopperway GatewayOpenAI-compatible EU APIVasilikos Campus42MW sovereign campus briefing
Trust & complianceTrust CenterSecurity portal · docs · statusEU AI ActRegulatory mapping & controlsAI Readiness AuditPublic-data readiness hub
PricingTiers
Capital & EducationInvestInstitutional data room & deal flowAcademyAI training programs
Individuals & Family OfficesLiving in EUNewClass B capital allocation · no visa framingInternationalNewPlan B · equity alternative to property
IntelligenceResearchPublications & portals
CompanyAboutBrand · HoldCo targetMissionCharter & sovereigntyTrust CenterSecurity portal · docs · status
Schedule Briefing
Sign In
NIS2 Directive Design Status
NIS2 DIRECTIVE REGULATORY COMPLIANCE

NIS2 Directive Design Status

Designed to meet Essential Entity infrastructure obligations when in scope, AGICY implements extreme cyber resilience protocols as design targets to protect the European Union's cognitive supply chain.

Last UpdatedFebruary 18, 2026
Document Version1.4.2
ClassificationCONFIDENTIAL / PUBLIC

1. Essential Entity Status

Under the NIS2 Directive (Directive (EU) 2022/2555), supercomputing facilities providing critical AI capabilities to governments, grid operators, and healthcare providers may be classified as "Essential Entities." AGICY is designing to embrace this classification and implement the directive's security and reporting mandates from Day 1 of operations — design status for a pre-construction programme, not a present-tense certification.

1.1 Scope of Classification

When operational, AGICY may fall under NIS2 Annex I, Sector 8 ("Digital Infrastructure") as a provider of cloud computing services, data centre services, and trust services. This would trigger the highest tier of obligations, including:

  • Mandatory risk management measures (Article 21).
  • Incident reporting to the competent authority within 24 hours (Article 23).
  • Supply chain security obligations (Article 21(2)(d)).
  • Board-level accountability for cybersecurity governance (Article 20).

2. Cyber Incident Reporting

AGICY plans a direct line to the Cypriot National CSIRT (Computer Security Incident Response Team). Our AGIOS operating system is designed for automated threat intelligence sharing. In the event of a sophisticated attack, early-warning data is intended to propagate to EU cybersecurity authorities.

2.1 Reporting Timeline

  • Within 24 hours: Early warning notification to the Cypriot CSIRT, including initial assessment of whether the incident was caused by unlawful or malicious action.
  • Within 72 hours: Incident notification with severity assessment, impact scope, and initial countermeasures.
  • Within 1 month: Final report including root cause analysis, cross-border impact, and measures applied.
Air-Gapped Sovereign Zones

"For high-sensitivity civilian government operations, AGICY offers physical air-gapping. Specific Tenstorrent Galaxy clusters can be completely severed from external internet access, accessible only via localized, biometric-secured terminals inside the Vasilikos facility."

3. Supply Chain Security

NIS2 mandates strict control over the supply chain. AGICY's design target is that no critical infrastructure components (silicon, networking gear, cooling controllers) contain unauthorized firmware. All hardware is planned to be audited up to the transistor level by independent European security firms prior to installation.

3.1 Hardware Provenance

  • Silicon: Tenstorrent Blackhole chips manufactured at Samsung Foundry (South Korea) and TSMC (Taiwan). Full Bill of Materials (BOM) audited by independent EU security laboratory.
  • Networking: 800 GbE Ethernet mesh using SwarmX protocol — no proprietary NVLink dependency. All firmware open for inspection.
  • Firmware: RISC-V open-source ISA — auditable down to the instruction set. No black-box proprietary microcode.

4. Risk Management Framework (Article 21)

AGICY plans the following technical and organisational measures as required by Article 21:

  • Policies on risk analysis and information system security.
  • Incident handling procedures with automated triage and escalation.
  • Business continuity and crisis management — including diesel backup, N+1 cooling, and geo-redundant control plane.
  • Supply chain security — including vendor vetting, firmware attestation, and hardware integrity monitoring.
  • Security in network and information systems acquisition, development, and maintenance.
  • Policies and procedures to assess the effectiveness of cybersecurity risk management measures.
  • Basic cyber hygiene practices and cybersecurity training for all staff.
  • Policies and procedures regarding the use of cryptography and encryption.
  • Human resources security, access control policies, and asset management.
  • Multi-factor authentication (MFA) and secured voice, video, and text communications.

5. Board-Level Accountability (Article 20)

AGICY's planned Board of Directors would be directly responsible for approving and overseeing the implementation of cybersecurity risk management measures. Board members would undergo mandatory cybersecurity training annually. The CISO would report directly to the Board, not through the CTO, ensuring independent oversight.

Continuous Compliance Monitoring

"NIS2 readiness is not a point-in-time audit. AGICY's planned Security Operations Centre is designed for 24/7/365 coverage with automated scoring against all 10 risk management domains defined in Article 21. Real-time dashboards are planned for the Board and auditors."

6. Cooperation with Authorities

AGICY plans cooperation protocols with:

  • The Cypriot Digital Security Authority (DSA) — designated competent authority under NIS2.
  • ENISA (EU Agency for Cybersecurity) — for cross-border coordination and threat intelligence sharing.
  • Europol EC3 — for incidents with criminal nexus.
  • CERT-EU — for incidents affecting EU institutional clients.

Download Official Policy Document

PDF Format · SHA-256 Verified · 1.4 MB

Secure Your Compliance

Pre-book Sovereign Compute compliant with all EU regulations.

Calculate SRA Allocation

§ FIN — Close of Document

Ready to build on sovereign infrastructure?

Schedule a confidential briefing with our team. NDA-protected, no commitment.

Schedule a briefing →
EU JURISDICTION · CYPRUSGDPR ART. 28 DPA-READY · BY DESIGNNIS2-ALIGNED · BY DESIGNEU AI ACT ART. 12 LOGGING SUPPORT · BY DESIGNRISC-V NATIVE · OPEN ISA

Design-alignment statements for a pre-construction facility — not certifications or attestations. Basis: compliance FAQ, § 08. Careers: we aim for 50-50 gender balance across hiring cohorts.

AGICY.AI

Advanced Governance & Intelligence Cyprus

The sovereign architecture for the Cyprus mind.
Humanitarian mandate: civilian public benefit only — healthcare, education, civil resilience. Civilian / humanitarian mandate only.
Office: 8 John Kennedy Street, Iris House, 7th floor, 3106 Limassol, Cyprus
+357 95 572 777 · 08:30 – 19:00 · agi@agicy.ai
VASILIKOS ENERGY CENTRE, LIMASSOL DISTRICT · PRE-CONSTRUCTION
34.7246°N · 33.2247°E
Principal campus: Cyprus Vasilikos (Phase 1). Parallel HoldCo path: sovereign compute project in Greece (TARGET / planning) — ~20 MW-class Tenstorrent / air-cooled inference positioning for EU diversification; separate CapEx, no offtake claimed.

The Ledger — monthly briefing
  • CopperwayEU-sovereign OpenAI-compatible gateway
  • Try PlaygroundNewLive Copperway demo · PII vault
  • Compression & PII vaultNewSovereign path controls in Playground
  • Sovereign Exchange5-year cross-org sovereign plan
  • ComputeBare-metal EU inference & training
  • UPDATED on GitHubAGICY AI desktop beta · source
  • Reserve CapacityPre-construction LOI tiers
  • MarketplaceCompute marketplace
  • AI Video SearchNewFind AI videos · avatars · films · ads
  • Sui Agent RailsPrivacy · Walrus · wallet connect
  • GPUs Rent LiveLiveEU partner GPU now · until COD
  • Compute VouchersSovereign compute credits
  • Model LeaderboardFrontier model rankings
  • PricingSubscription tiers
  • Research HubWave-1 publications index
  • Data CentersWorldwide map & tracker
  • Vasilikos Campus42MW sovereign campus briefing
  • Copperway vs gatewaysConcessive pricing & capability evidence
  • OpenRouter alternativesLiteLLM · Portkey · Copperway
  • EU alternative to OpenRouterCLOUD Act / sovereignty buyer guide
  • Copperway vs LLM gatewaysCapability evidence & SRA economics
  • GDPR-compliant AI hostingEU residency & processing path
  • Cerebras vs GroqInference speed & sovereign options
  • CLOUD Act riskUS parented API exposure
  • AI Act Digital OmnibusArticle 50 transparency duties
  • Sovereign cloud truthLabel vs residency — buyer checklist
  • EU AI ActRegulatory mapping & controls
  • AboutProject identity & status
  • GitHubAGICY AI public source · AGiOS-Ai-EU
  • MissionCharter & sovereignty
  • CareersCulture, benefits & hiring ethos
  • Open PositionsEngineering, research & operations roles
  • Ethics & CharterAnti-misconduct & responsible AI
  • Editorial & MethodologySources, claims, corrections
  • Trust CenterSecurity portal · docs · status
  • InvestInstitutional data room & deal flow
  • Living in EUIndividuals & FOs · Class B allocation
  • International investorsPlan B · Greece / Cyprus rails · Class B
  • Equity participation (legacy)CY & GR individual interest · counsel-gated
  • AcademyAI training programs
  • ContactBriefings & inquiries
  • Privacy PolicyGDPR · data processing
  • Terms of ServicePlatform usage terms
  • Cookie PolicyTracking & consent
  • SRA TermsReserve capacity agreement
  • Gateway Pricing DisclaimerCopperway pricing basis
© 2026 AGICY· PROJECT / BRAND OPERATOR · AGICY HOLDINGS LTD — NAME REGISTRATION APPLICATION COMPLETED · AWAITING APPROVAL · CORP DOCS TO FOLLOWDOC: AGICY.AI · REV 2.0 · SOVEREIGN LEDGER
AGICY