Regulation
NIS2 Directive and AI use cases
Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.
Read the source text (European Union)Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- Agentic AI for autonomous, intent based network operations
Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk; Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. Loops that only optimise performance or capacity are usually not safety components, but a loop that protects physical integrity or life safety services can be, so operators should assess each closed loop and document the outcome.
- AI agent for network outage detection and customer communication
The customer facing agent is limited risk with an Article 50 duty to disclose AI. AI used as a safety component in the management and operation of critical digital infrastructure is high risk under Annex III point 2, so the classification depends on whether the detection part acts on the network or only informs people.
- AI analytics for smart meter and AMI data
Annex III point 2 covers AI systems intended to be used as a safety component in the management and operation of critical digital infrastructure and the supply of water, gas, heating or electricity. Meter health prioritisation and usage disaggregation for programme targeting are not intended as safety components, so they stay outside that scope regardless of whether a person reviews the output. The tier would instead be high risk if the same kind of analytics were intended as a safety component in network operation or supply, for example directly controlling grid or metering protection systems; a human in the loop is then an Article 14 obligation for that high risk system, not a way to fall outside the category.
- AI copilot for network operations centre fault triage
The main test is Annex III point 2, which lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk. A copilot that prepares diagnoses for engineers who decide every change is normally not such a safety component, and is then minimal risk. The tier rises when the system is designed to protect the safe operation of the network, for example by acting on it automatically to prevent or contain outages. Article 6(3) can exempt an Annex III system that only performs a preparatory task to an assessment and poses no significant risk of harm, provided the provider documents that assessment and registers the system.
- AI for mobile network planning and capacity optimization
Forecasting demand, ranking congested cells and recommending investments is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property and that are not necessary for the system to function. Closed loop parameter optimisation on the live radio network is high risk only when it serves in that role, for example a loop whose purpose is to protect emergency call availability, so each automated loop should be assessed against point 2 and the outcome documented. Loops that only optimise performance or capacity are usually not safety components.
- AI for predictive network maintenance in telecom
Scoring failure risk and planning maintenance is normally minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall within that infrastructure. Recital 55 limits safety components to systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. An operator whose automated actions meet that test must treat the system as high risk.
- AI for radio access network energy optimization
Optimizing energy use is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall under that infrastructure. Recital 55 limits safety components to systems that directly protect the infrastructure or the health and safety of persons, so an optimizer is not high risk by default, but a design in which it could affect emergency service availability should be assessed against point 2.
- AI for security alert triage and investigation in the SOC
Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.
- AI for telecom fraud detection (SIM swap, IRSF and Wangiri)
Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.
- AI predictive maintenance for freight rail rolling stock
A system that flags a wheel or railcar for a qualified inspector to confirm is advisory and usually minimal risk. Under Article 6(1) it is high risk when both conditions hold: the same detection logic is built into a safety component of rolling stock or track equipment (or is itself such a product) covered by Directive (EU) 2016/797 on the interoperability of the rail system, which sits in Annex I Section B, for example if a flag were wired to trigger an automatic stop or speed restriction without a human check, and that directive requires a third party conformity assessment of the product. Under Article 2(2), as amended by Regulation (EU) 2026/1744, a high risk system of that kind is not subject to the full AI Act: only Article 6(1), Article 60a and Articles 102 to 112 apply directly, and Articles 57, 58 and 59 apply only so far as the high risk requirements have been integrated into the interoperability directive. The substantive high risk requirements reach the system through that directive instead, which Article 106 of the AI Act amends to require rail delegated and implementing acts to take those requirements into account.
- AI predictive maintenance for industrial and energy assets
A system that advises engineers on the condition of equipment is usually minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; if predictive maintenance acts on protection or control in a utility network, it can become high risk. Article 6(1) can also apply when the AI is a safety component of machinery or another product covered by Annex I legislation and that product must undergo a third party conformity assessment.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI for IT incident triage and root cause analysis (AIOps)
An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.
- AI for software vulnerability triage and remediation
Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.
- AI for third party and vendor risk due diligence
Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.