EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Critical Infrastructure AI: Safety Components in Utilities, Traffic and Digital Networks

AI used as a safety component in water, gas, electricity, heating or road-traffic infrastructure is high-risk under Annex III(2). What infrastructure operators and vendors must document.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

High-risk

High-risk (Annex III, point 2)

When it applies

High-risk obligations apply from 2 December 2027.

Regulation (EU) 2024/1689, Annex III(2); Art. 6(1) and Annex I overlap with sectoral safety law; Art. 9 risk management

AI that acts as a safety component in the management or operation of critical infrastructure is high-risk under the EU AI Act. This covers digital infrastructure, road traffic, and the supply of water, gas, heating and electricity: predictive-maintenance models that decide when to isolate a section of grid, traffic-control systems that manage signal timing or incident response, and anomaly-detection systems that can trigger a physical safety action.

This page is for operators of utilities and transport networks, and for vendors selling AI-based monitoring, control or predictive-maintenance software into those sectors. The key question is not whether the AI is exciting or novel, but whether it functions as a safety component: something whose failure or malfunction directly endangers the health and safety of persons or property.

Classification

Why this classification applies

Annex III, point 2 lists AI systems “intended to be used as safety components in the management and operation of critical infrastructure”, specifically road traffic and the supply of water, gas, heating, and electricity, and, per the Digital Omnibus, digital infrastructure. A safety component is one whose failure or malfunction endangers people or property, even if it is not the primary function of the larger system.

A monitoring dashboard that only displays sensor readings to a human operator, with no automated control action, is a weaker candidate: it informs a decision rather than acting as a safety component itself. A system that can automatically shed load, reroute traffic, or shut a valve based on its own output is squarely in scope, because its malfunction has a direct physical safety consequence.

There is a second route into the high-risk regime here: if the AI is itself a safety component of a product already regulated under EU harmonisation legislation in Annex I (for example, machinery or certain energy equipment) and requires third-party conformity assessment under that legislation, Article 6(1) applies instead of, or alongside, Annex III(2), which changes the deadline to 2 August 2028 for that specific route.

Obligations

What you have to do

  • Risk management system covering both cybersecurity and physical-safety failure modes across the lifecycle (Art. 9).
  • Data governance for the sensor and operational data the system is trained and validated on, including edge cases like extreme weather or peak demand (Art. 10).
  • Technical documentation and automatic logging sufficient to reconstruct the basis of any automated safety action (Arts. 11, 12).
  • Accuracy, robustness and cybersecurity testing proportionate to the consequence of a wrong or delayed action, including resilience to sensor failure and adversarial interference (Art. 15).
  • Human oversight design that lets an operator understand, override and halt automated actions in real time (Art. 14).
  • Conformity assessment (internal control, or third-party where the Annex I / Art. 6(1) route applies), EU declaration of conformity, CE marking, EU database registration (Arts. 43, 47, 48, 49).
  • Post-market monitoring plan and serious-incident reporting integrated with existing sectoral incident-reporting duties under energy, telecoms or transport law (Arts. 72, 73).

Paperwork

Documents to have on file

Annex IV technical documentation
Risk management file covering safety and cybersecurity
Data governance and validation records
Human oversight and operator instructions
Accuracy/robustness/cybersecurity test reports
EU declaration of conformity and EU database registration
Post-market monitoring plan aligned with sectoral incident reporting

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Treating a predictive-maintenance model as “just analytics” because it only produces a recommendation, when operators near-universally act on the recommendation without independent verification.
  • Assuming sectoral certification (for example under energy or telecoms regulation) already covers the AI Act. It can satisfy parts of the conformity assessment, but the AI-specific duties, such as data governance and human oversight design, are usually not covered.
  • No tested fallback for sensor or model failure. A safety component needs a defined, tested degraded mode, not just a well-performing happy path.
  • Ignoring the digital-infrastructure category because the system feels like “IT” rather than “utilities”. Network-management AI for critical digital infrastructure is explicitly in scope.

FAQ

Frequently asked questions

Does this apply to building-management systems, like HVAC in an office block?

Only if the building is part of critical infrastructure in the Annex III(2) sense, generally not the case for an ordinary commercial building. Utility-scale heating or electricity supply infrastructure is the target, not an individual building’s internal systems.

We supply an AI dashboard for grid operators that only advises; a human always decides. Are we exempt?

Advisory-only tools are less clearly in scope, but the analysis turns on real-world reliance, not the interface label. If operators treat the recommendation as the decision in practice, document that reasoning carefully or plan for high-risk compliance.

What is the deadline if our system is also a machinery safety component under other EU law?

Where the Art. 6(1)/Annex I route applies because your product needs third-party conformity assessment under sectoral law, the AI Act obligations for that system apply from 2 August 2028 rather than 2 December 2027.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.

Related use cases

High-risk

Medical diagnosis & clinical decision support

Read →

Depends on use

Fraud detection & AML

Read →

Depends on use

Biometric identification & categorisation

Read →

Guide

EU AI Act compliance guide

Read →