Under the AI Act, critical infrastructure AI is high-risk only in narrow cases. The system must act as a safety component in digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. Draft Commission guidelines of 19 May 2026 add a third test: the operator must be designated as a critical entity.1,3 The duties apply from 2 December 2027.2

Summary

  1. Under the draft Commission guidelines, AI is high-risk in critical infrastructure only when it directly protects physical safety and its user is a designated critical entity. Forecasting, maintenance assistants and cybersecurity tools fall outside.
  2. Energy companies that use AI are twice as likely as the average firm to use it for ICT security: 39.4 against 19.8 percent in 2025. The AI Act excludes those tools from this category.
  3. In electricity and gas, 59.1 percent of firms that considered AI and held back cite unclear legal consequences, the highest share in the four sectors. Final guidelines are due by the end of 2026.

This briefing is for boards, CISOs and compliance leads at grid operators, utilities, water companies, telecom operators and road authorities. The energy and critical infrastructure sector page covers NIS2 and the wider rules. Every AI Act date is in the AI Act timeline.

Which critical infrastructure AI is high-risk under the AI Act?

Annex III point 2 lists AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating or electricity.1 Recital 55 explains why: a failure could endanger life and health at large scale and disrupt economic life.

A safety component protects people or property. The Digital Omnibus sharpened the definition in Article 3(14): a component fulfils a safety function when its intended purpose is to prevent or mitigate risks to health and safety.2

The draft guidelines name six safety functions

The Commission's draft reads the category narrowly.3 An AI system qualifies only if it directly protects the physical integrity of the infrastructure by doing one of six things:

  • detect situations that may directly cause physical harm or damage;
  • detect maintenance needs that, if missed, threaten physical integrity;
  • prevent harm, for example by blocking start-up after abnormal behaviour;
  • control or limit harm by adjusting how the infrastructure runs;
  • mitigate harm, for example by triggering a safe stop;
  • supervise another system that performs a safety function.

Systems that are "merely supportive, informational, organisational or optimisation-oriented" fall outside. The guidelines also weigh whether a redundant backup system already protects the infrastructure. Recital 55 of the Act itself excludes AI used solely for cybersecurity.

The critical entity test

The AI Act borrows its definition of critical infrastructure from the CER Directive.5 The draft guidelines read this to mean a system is high-risk only if the user has been identified as a critical entity by a Member State. Member States had to identify those entities by 17 July 2026 and notify them within one month.

The result: the same AI system can be high-risk at a national grid operator and not at a small municipal utility. Critical entities need not reveal their status to suppliers. The guidelines suggest they write AI Act compliance into tenders and contracts instead.

Which grid, water and telecom AI use cases are high-risk?

The draft guidelines give worked examples for each sector. The line is thin. Anomaly detection that supports decisions on load distribution, grid stability or shutdown is in scope. An outage warning to the control room is not, because it is one precaution among several and acts on nothing itself.

Sector AI system Why
Electricity Grid anomaly detection for stability or shutdown Supports critical grid decisions
Electricity Perimeter cameras, radar and drone control Protects physical integrity
Electricity Demand forecasting for grid optimisation Safety handled by other systems
Electricity Outage warnings to the control room One precaution; acts on nothing
Electricity Cybersecurity monitoring of grid networks Cybersecurity only
Electricity Photo checks of meter installations No safety function
Water Pressure sensing in drinking water networks Safety component in distribution
Water Sewage overflow prediction for drinking water Safety component in distribution
Gas Predictive maintenance on pipelines Safety systems stay independent
Heating Patrol robots in heating plants Detects only, cannot intervene
Road traffic Traffic lights adjusted to live traffic Limits physical harm
Road traffic Heavy-object detection on bridges and quays Prevents collapse
Road traffic Live translation, control room to drivers Supports safe operation
Road traffic Traffic flow analytics Insights only
Digital Fire alarm control in cloud data centres Prevents physical damage
Digital Maintenance manual assistant, trouble tickets Service quality only

High-risk if used by a critical entity Outside Annex III point 2

Source: European Commission, draft guidelines on the classification of high-risk AI systems, Annex III document, section 3.2, 19 May 2026; accessed 29 September 2026. Examples are from a draft and may change.

Two examples matter most for operators. An assistant that answers questions from technical manuals for network maintenance is named as outside the category. So is demand forecasting where core safety functions run separately. Live translation between a traffic control centre and drivers, by contrast, is listed as high-risk.

Some systems fall outside point 2 for other reasons. The road traffic case covers surface roads only, not waterways. AI in rail or civil aviation can be high-risk through the product legislation in Annex I. AI used as a safety component in nuclear energy production is excluded, as are oil and hydrogen.

How do energy, water and telecom companies use AI today?

Eurostat's 2025 enterprise survey asks AI users what they use it for.6 Two purposes matter here. ICT security is excluded from the high-risk category. Production processes is where safety components would sit.

Energy firms lead on AI for security

Of the sectors shown, electricity and gas firms that use AI are the most likely to apply it to ICT security.

Two in five energy companies that use AI apply it to ICT security, twice the average.

Share of enterprises using AI that use it for each purpose, EU-27, 2025, %

ICT security Production processes
0 10 20 30 40 50 19.8% 20.8% 39.4% 26.8% 34.1% 32.5% 25.5% 18.1% 21.4% 15.6% All sectors¹ Electricity and gas Telecoms Water supply and waste² Transport and storage

¹ EU-27, enterprises with 10 or more persons employed, excluding agriculture, forestry, fishing, mining and quarrying, and the financial sector. ² Water supply, sewerage, waste management and remediation (NACE section E). Telecoms is NACE division 61, electricity and gas is NACE division 35, transport and storage is NACE section H.

Source: Eurostat, Artificial intelligence by NACE Rev. 2 activity (isoc_eb_ain2), 2025 survey, updated 15 June 2026

Among AI users, 39.4 percent of electricity and gas firms and 34.1 percent of telecom firms apply AI to ICT security. The EU average is 19.8 percent. Under the AI Act, none of this is high-risk as a critical infrastructure safety component. NIS2 still governs it.

In all four infrastructure sectors, use in production processes trails use for security: 26.8 percent in energy, 18.1 percent in water and 15.6 percent in transport. Eurostat's purposes are not AI Act classes. Still, the data suggest that the systems caught by point 2 are a minority of what operators run today.

What must operators do if an AI system is high-risk?

The duties depend on the role. An operator that buys a high-risk system is a deployer. An operator that builds its own system and puts it into service under its own name is the provider.1 That applies to an in-house grid anomaly detector as much as to a vendor product.

Three procedural reliefs for point 2 systems

Providers follow conformity assessment based on internal control, without a notified body (Article 43(2)). The system is registered at national level, not in the public EU database (Article 49(5)). Deployers need no fundamental rights impact assessment (Article 27).

Deployer duties under Article 26

  • use the system according to the provider's instructions;
  • assign human oversight to staff with the competence, training and authority to act;
  • monitor operation and inform the provider of risks or serious incidents;
  • keep automatically generated logs for at least six months;
  • inform workers' representatives before use at the workplace.

Breaches of these duties can cost up to €15 million or 3 percent of worldwide annual turnover, whichever is higher (Article 99(4)). These duties apply from 2 December 2027. For operators in NIS2 scope, NIS2 already covers every AI system, high-risk or not.8 That means supplier assessment under Article 21 and an early warning within 24 hours of a significant incident under Article 23.

What holds infrastructure operators back from AI?

Eurostat also asks firms that considered AI but do not use it why they held back. The answers show where legal clarity would help.

Energy firms worry most about the law

In electricity and gas, data protection concerns outrank lack of expertise as a reason not to adopt AI.

Energy firms that held back on AI cite data protection and legal doubt more than the other sectors shown.

Share of enterprises that considered AI but do not use it, citing each reason, EU-27, 2025, %

Lack of expertise Data protection concerns Unclear legal consequences
0 20 40 60 80 70.3% 52.7% 53.6% 64.0% 65.6% 59.1% 62.6% 55.2% 48.7% 69.5% 52.5% 51.7% 69.1% 50.8% 51.0% All sectors¹ Electricity and gas Telecoms Water supply and waste² Transport and storage

¹ EU-27, enterprises with 10 or more persons employed, excluding agriculture, forestry, fishing, mining and quarrying, and the financial sector. ² Water supply, sewerage, waste management and remediation (NACE section E). Telecoms is NACE division 61, electricity and gas is NACE division 35, transport and storage is NACE section H.

Source: Eurostat, Artificial intelligence by NACE Rev. 2 activity (isoc_eb_ain2), 2025 survey, updated 15 June 2026

Across all sectors, lack of expertise is the main barrier at 70.3 percent. Electricity and gas is the exception. There, 65.6 percent cite data protection and 59.1 percent unclear legal consequences, both the highest of the four sectors shown.

The draft guidelines answer part of that doubt. The consultation closed on 23 July 2026 and final guidelines are due by the end of 2026.4 The Commission's energy roadmap of 3 June 2026 adds a European AI energy safety transformation group to monitor high-risk use cases, plus AI regulatory sandboxes for energy applications.7 It states that new AI models for the energy sector should be developed and managed in the EU. Horizon Europe puts about €75 million into AI for energy in 2026 and 2027.

What should operators do before December 2027?

  1. Confirm critical entity status. Check whether the national authority has notified the organisation under the CER Directive. In the Netherlands, the Wwke implements the CER Directive and has applied since 15 August 2026.9
  2. Classify every AI system. Record whether it performs one of the six safety functions, with the reasoning. Note any redundant safety system that does the same job.
  3. Fix procurement. Require AI Act high-risk compliance in tenders for any AI near physical operations, as the guidelines suggest.
  4. Plan provider duties for in-house builds. Technical documentation, logging and human oversight are easier to design in than to add later.
  5. Keep NIS2 in view. Assistants and forecasting tools escape the AI Act category but still count as suppliers and dependencies.

Lindstead maps each AI system to the AI Act risk class, NIS2 and national law through its AI governance and compliance work. Much of the AI operators want, such as a maintenance assistant, sits outside the high-risk category. It still handles sensitive asset data. AI deployment on infrastructure the operator controls keeps that data inside, and model selection checks origin and licence for the supplier file. The self-hosted LLM guide covers the technical options.

Frequently asked questions

  • No. Annex III point 2 covers only AI used as a safety component in critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. The draft Commission guidelines of 19 May 2026 add that the user must be an entity identified as critical under the CER Directive. Forecasting, optimisation, maintenance assistants and trouble-ticket tools fall outside.

  • From 2 December 2027. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the date from 2 August 2026. The prohibitions, AI literacy duty and transparency rules already apply.

  • Not under Annex III point 2. Recital 55 of the AI Act separates safety components from components used solely for cybersecurity. The draft guidelines give detection of unauthorised access and cybersecurity monitoring of grid networks as examples that fall outside. Such tools remain in scope of NIS2.

  • Not directly. The road traffic use case covers surface roads only. AI in rail systems or civil aviation can be high-risk through the product legislation in Annex I instead. AI used as a safety component in nuclear energy production falls outside point 2, although electricity components of a nuclear plant can be covered.

  • No. Article 27 exempts high-risk systems under Annex III point 2 from the fundamental rights impact assessment. These systems are also registered at national level rather than in the public EU database, under Article 49(5).

Sources

  1. Regulation (EU) 2024/1689 (AI Act), Articles 3(3), 3(14), 3(62), 6, 26, 27, 43(2), 49(5), 99(4), Annex III point 2 and recital 55, as amended. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026, in force 27 July 2026. eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744
  3. European Commission, Draft guidelines on the classification of high-risk AI systems, Annex III document, section 3.2, paragraphs 178 to 206, 19 May 2026. digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
  4. European Commission, Targeted consultation on the draft guidelines, deadline extended to 23 July 2026; final guidelines by the end of 2026. digital-strategy.ec.europa.eu/en/consultations/targeted-consultation-draft-guidelines-classification-high-risk-artificial-intelligence-systems
  5. Directive (EU) 2022/2557 on the resilience of critical entities (CER), Articles 2(4) and 6, 14 December 2022. eur-lex.europa.eu/eli/dir/2022/2557/oj/eng
  6. Eurostat, Artificial intelligence by NACE Rev. 2 activity (isoc_eb_ain2), updated 15 June 2026. ec.europa.eu/eurostat/databrowser/view/isoc_eb_ain2/default/table
  7. European Commission, Strategic Roadmap for Digitalisation and AI in the Energy Sector, COM(2026) 501, 3 June 2026. data.consilium.europa.eu/doc/document/ST-10101-2026-INIT/en/pdf
  8. Directive (EU) 2022/2555 (NIS2), Articles 21 and 23, 14 December 2022. eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
  9. Rijksoverheid, Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf vandaag van kracht, 15 August 2026. www.rijksoverheid.nl/actueel/nieuws/2026/08/15/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-vandaag-van-kracht

Method: legal points read from the AI Act as amended, the CER Directive and the draft Commission guidelines; Eurostat figures from the 2025 ICT usage in enterprises survey. All sources accessed 29 September 2026. This page is general information, not legal advice. Corrections: contact@lindstead.com.