EU AI Act

When is AI in critical infrastructure high-risk under the EU AI Act, and how does it fit with NIS2?

AI as a safety component in critical digital infrastructure, road traffic, or water, gas, heating or electricity supply is high-risk under Annex III point 2 from 2 Dec 2027. It is registered at national level and excluded from the fundamental rights impact assessment. NIS2 duties apply to the operator alongside.

The EU AI Act treats AI that keeps critical infrastructure safe as high-risk. Annex III, point 2 covers AI used as a safety component in digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. The area gets two exemptions other high-risk areas do not: no fundamental rights impact assessment, and registration at national level instead of the EU database. The operators are often NIS2 entities too, so two regimes apply at once.

Point 2Annex III area
2 Dec 2027High-risk rules apply
NationalRegistration
No FRIAExcluded

Quotations are from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026, and from Directive (EU) 2022/2555 (NIS2), on 2 October 2026. This is not legal advice.

Which critical infrastructure AI is high-risk?

Annex III, point 2 reads: "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity." The key words are "safety components". In our reading, an AI system that optimizes billing or forecasts demand for planning is not a safety component; one that controls flow, balances load to keep the grid stable, or manages traffic signals may be.

The July 2026 amendment rewrote the definition in Article 3(14): a safety component is "a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property", and it fulfils a safety function "where its intended purpose is to prevent or mitigate risks to health and safety of persons or property". Our Annex III guide covers the Article 6(3) test that can take a listed system out of high-risk status.

What is different about this area?

Two exemptions. Article 27(1) excludes "high-risk AI systems intended to be used in the area listed in point 2 of Annex III" from the fundamental rights impact assessment. And Article 49(5) says these systems "shall be registered at national level", while Article 49(1) and (3) exclude point 2 from registration in the EU database. Everything else in the high-risk regime applies: the provider requirements and Article 16 obligations, and the deployer duties in Article 26, from 2 December 2027.

NIS2 Article 21 checklist

Article 21(2) measure,What NIS2 says (summary),Our policy or control,Owner,Evidence kept,Last reviewed,Approved by management body (Art. 20(1)),Notes
(a),Policies on risk analysis and information system security,,,,,,
(b),Incident handling,,,,,,
(c),"Business continuity, such as backup management and disaster recovery, and crisis management",,,,,,
(d),"Supply chain security, including security aspects of relationships with direct suppliers and service providers",,,,,,
(e),"Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure",,,,,,
(f),Policies and procedures to assess the effectiveness of cybersecurity risk-management measures,,,,,,
(g),Basic cyber hygiene practices and cybersecurity training,,,,,,
(h),"Policies and procedures on cryptography and, where appropriate, encryption",,,,,,
(i),"Human resources security, access control policies and asset management",,,,,,
(j),"Multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems, where appropriate",,,,,,
Article 20(2),Management body members follow training,,,,,,
Article 23(4)(a),Early warning within 24 hours of becoming aware of a significant incident,,,,,,
Article 23(4)(b),Incident notification within 72 hours,,,,,,
Article 23(4)(d),Final report within one month of the incident notification,,,,,,
"Directive (EU) 2022/2555, read 2 October 2026. NIS2 reaches you through national law, which may add to this list. Template from credentialpress.com/guides/nis2-management-body-duties. Not legal advice.",,,,,,,

How does it fit with NIS2?

Energy, transport, water and digital infrastructure operators are often essential or important entities under NIS2, which has applied through national law since October 2024. NIS2 requires the management body to approve and oversee ten minimum cybersecurity measures and to follow training, and requires an early warning within 24 hours of becoming aware of a significant incident. The AI Act adds, for a high-risk AI safety component, human oversight, logging, monitoring and serious incident reporting under its own Article 73. Our NIS2 guide for management bodies and AI Act incident reporting guide set out the two sets of clocks.

Who is the provider and who is the deployer?

An operator that buys a control system with an AI safety component is usually the deployer, and the vendor is the provider. An operator that develops its own AI safety component, or substantially modifies a bought one, can become the provider under Article 25. Our guides to provider obligations and deployer obligations cover each side.

What should an operator do this year?

List the AI used in operations and mark which perform a safety function under the amended definition. For those, ask the vendor whether it treats the system as high-risk, plan national registration, and map the AI Act's oversight, logging and incident duties onto your NIS2 program. For the people running both, the CISSP study guide covers the security side and the AI Governance Framework handbook the AI Act, written to the 2024 text. Credential Press is independent of the EU institutions.

Frequently asked questions

Is AI in critical infrastructure high-risk under the EU AI Act?

When it is a safety component. Annex III, point 2 lists AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.

What counts as a safety component?

Article 3(14), as amended in July 2026, defines it as a component that fulfils a safety function, or whose failure or malfunctioning endangers the health and safety of persons or property; a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property.

Do critical infrastructure operators need a FRIA?

No. Article 27(1) excludes high-risk systems in the area of Annex III, point 2 from the fundamental rights impact assessment.

Where are critical infrastructure AI systems registered?

At national level. Article 49(5) says high-risk AI systems referred to in Annex III, point 2 shall be registered at national level, and they are excluded from the EU database registration in Article 49(1) and (3).

How does this fit with NIS2?

They stack. NIS2 requires essential and important entities to take ten minimum cybersecurity measures and report significant incidents within 24 hours, and the AI Act adds provider and deployer duties for high-risk AI safety components from 2 December 2027.

EU AI Act: test yourself in five minutes

Which books help infrastructure security and AI teams?

Cover of AI Governance Framework

AI Governance Framework

Building one that survives the EU AI Act. 22 chapters, 384 pages.

Cover of CISSP Exam Guide

CISSP Exam Guide

Certified Information Systems Security Professional. 14 chapters, 396 pages.

Sources

Every quotation above was read on 2 October 2026 through the EU Publications Office.

Credential Press is independent of the European Commission. This is not legal advice.