[{"data":1,"prerenderedAt":294},["ShallowReactive",2],{"uc-reg-nis2":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"nis2","NIS2 Directive","European Union","europe","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",false,true,[14,55,76,96,114,143,157,168,189,215,229,245,264,279],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":22,"patterns":25,"audience":30,"autonomy":31,"adoptionStage":32,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":35,"bestGrade":41,"headline":42,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":54},"autonomous-network-operations","Agentic AI for autonomous, intent based network operations","Autonomous network operations","AI agents that run closed loops over a telecom network: they take an intent from the operator (for example a latency or availability target for a service), observe the network, diagnose deviations and execute corrective actions across radio, transport and core, within guardrails set by engineers and with human approval for major changes.","published",[21],"telecommunications",[23,24],"network-operations","it-and-engineering",[26,27,28,29],"agentic-workflow","anomaly-detection","prediction-and-scoring","classification-and-routing","back-office","supervised-agent","emerging","network",6,[36,37,38,39,40],"Deutsche Telekom","du","KDDI","stc Group","Telstra","B",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"processing-time-reduction","Cycle time reduction","percent",1,0,"reported",95,"at-least","organization","2026-09-26","context-dependent","Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk; Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. Loops that only optimise performance or capacity are usually not safety components, but a loop that protects physical integrity or life safety services can be, so operators should assess each closed loop and document the outcome.",{"slug":56,"title":57,"shortTitle":58,"definition":59,"status":19,"industries":60,"functions":61,"patterns":64,"audience":68,"autonomy":31,"adoptionStage":32,"segment":69,"evidenceCount":70,"publicEvidenceCount":46,"organizations":71,"bestGrade":41,"headline":73,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":75},"network-outage-communication-agent","AI agent for network outage detection and customer communication","Outage communication","An AI agent that turns network alarms into a clear picture of which customers are affected by an outage and why, tells them proactively by message, app or phone with a cause and an estimated fix time, answers their questions during the incident, and updates them until service is restored.",[21],[62,23,63],"customer-service","field-service",[27,29,65,66,67],"content-generation","conversational-agent","voice-agent","customer-facing","front-office",2,[72],"Comcast",null,"2026-09-27","The customer facing agent is limited risk with an Article 50 duty to disclose AI. AI used as a safety component in the management and operation of critical digital infrastructure is high risk under Annex III point 2, so the classification depends on whether the detection part acts on the network or only informs people.",{"slug":77,"title":78,"shortTitle":79,"definition":80,"status":19,"industries":81,"functions":83,"patterns":86,"audience":30,"autonomy":87,"adoptionStage":88,"segment":89,"evidenceCount":70,"publicEvidenceCount":70,"organizations":90,"bestGrade":93,"headline":73,"lastVerified":94,"indexable":12,"euAiActTier":53,"euAiActBasis":95},"smart-meter-analytics","AI analytics for smart meter and AMI data","Smart meter analytics","AI that turns the flood of readings from smart electricity, gas and water meters into usable information: it monitors meter and network health at scale, estimates which appliances drive a household's usage from the meter signal alone, flags unusual consumption, and targets efficiency and electrification programmes at the customers who will benefit most, instead of a utility treating every meter and every customer the same way.",[82],"energy-and-utilities",[84,85],"operations","analytics-and-reporting",[27,28],"assist","early-adopters","metering-and-billing",[91,92],"Consolidated Edison (Con Edison)","Southern California Gas Company (SoCalGas)","C","2026-09-28","Annex III point 2 covers AI systems intended to be used as a safety component in the management and operation of critical digital infrastructure and the supply of water, gas, heating or electricity. Meter health prioritisation and usage disaggregation for programme targeting are not intended as safety components, so they stay outside that scope regardless of whether a person reviews the output. The tier would instead be high risk if the same kind of analytics were intended as a safety component in network operation or supply, for example directly controlling grid or metering protection systems; a human in the loop is then an Article 14 obligation for that high risk system, not a way to fall outside the category.",{"slug":97,"title":98,"shortTitle":99,"definition":100,"status":19,"industries":101,"functions":102,"patterns":103,"audience":106,"autonomy":107,"adoptionStage":88,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":108,"bestGrade":41,"headline":112,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":113},"network-fault-triage-copilot","AI copilot for network operations centre fault triage","NOC fault triage copilot","AI in the network operations centre (NOC) that correlates alarms and performance data from radio, transport, core and fixed networks into a small number of probable faults, ranks them by customer impact, proposes the likely root cause and fix from runbooks, vendor documentation and past tickets, and routes the ticket to the right team, while an engineer decides what to change.",[21],[23,84],[27,29,104,105,26],"rag-knowledge-assistant","summarization","employee-facing","copilot",[109,36,38,110,40,111],"Bell Canada","Orange","Vodafone",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"The main test is Annex III point 2, which lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk. A copilot that prepares diagnoses for engineers who decide every change is normally not such a safety component, and is then minimal risk. The tier rises when the system is designed to protect the safe operation of the network, for example by acting on it automatically to prevent or contain outages. Article 6(3) can exempt an Annex III system that only performs a preparatory task to an assessment and poses no significant risk of harm, provided the provider documents that assessment and registers the system.",{"slug":115,"title":116,"shortTitle":117,"definition":118,"status":19,"industries":119,"functions":124,"patterns":126,"audience":106,"autonomy":107,"adoptionStage":88,"evidenceCount":34,"publicEvidenceCount":127,"organizations":128,"bestGrade":41,"headline":134,"lastVerified":74,"indexable":12,"euAiActTier":141,"euAiActBasis":142},"aiops-incident-triage","AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[120,121,122,21,123],"cross-industry","banking","technology","payments",[24,84,125],"risk-management",[27,29,105,104,26],5,[129,130,131,132,133],"Google","Meta","Microsoft","Mizuho Financial Group","TD Bank",{"kpi":135,"label":136,"unit":45,"n":137,"nUpTo":47,"kind":138,"value":139,"qualifier":140,"claimant":73,"organization":73,"vendorReported":11},"accuracy","Accuracy",3,"median",90,"exact","minimal","An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.",{"slug":144,"title":145,"shortTitle":146,"definition":147,"status":19,"industries":148,"functions":149,"patterns":150,"audience":106,"autonomy":31,"adoptionStage":88,"segment":33,"evidenceCount":127,"publicEvidenceCount":127,"organizations":152,"bestGrade":41,"headline":155,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":156},"network-planning-and-capacity-optimization","AI for mobile network planning and capacity optimization","Network planning and capacity","Machine learning that forecasts where and when a mobile network will run out of capacity, recommends where to add cells, spectrum or hardware, and continuously tunes radio parameters so existing capacity carries more traffic, with planners approving investments and major changes.",[21],[23,85],[28,151,27,26],"recommendation-and-personalization",[36,153,39,154,111],"NTT DOCOMO","Telefónica España",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"Forecasting demand, ranking congested cells and recommending investments is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property and that are not necessary for the system to function. Closed loop parameter optimisation on the live radio network is high risk only when it serves in that role, for example a loop whose purpose is to protect emergency call availability, so each automated loop should be assessed against point 2 and the outcome documented. Loops that only optimise performance or capacity are usually not safety components.",{"slug":158,"title":159,"shortTitle":160,"definition":161,"status":19,"industries":162,"functions":163,"patterns":164,"audience":30,"autonomy":31,"adoptionStage":88,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":165,"bestGrade":41,"headline":73,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":167},"predictive-network-maintenance","AI for predictive network maintenance in telecom","Predictive network maintenance","Machine learning that spots the early signs of network failure, such as degrading cells, faulty customer equipment, ageing hardware or planned digging near fibre, and triggers a preventive fix, a remote reset or a targeted intervention before customers lose service.",[21],[23,63,84],[27,28,26],[38,110,154,40,166,111],"Verizon","Scoring failure risk and planning maintenance is normally minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall within that infrastructure. Recital 55 limits safety components to systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. An operator whose automated actions meet that test must treat the system as high risk.",{"slug":169,"title":170,"shortTitle":171,"definition":172,"status":19,"industries":173,"functions":174,"patterns":175,"audience":30,"autonomy":176,"adoptionStage":88,"segment":33,"evidenceCount":127,"publicEvidenceCount":127,"organizations":177,"bestGrade":41,"headline":183,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":188},"ran-energy-optimization","AI for radio access network energy optimization","RAN energy optimization","Machine learning that predicts traffic per cell and puts radio carriers, cells and hardware components into sleep modes when demand is low, then wakes them before users notice, so a mobile network uses less electricity without losing coverage or quality.",[21],[23],[28],"autonomous",[178,179,180,181,182],"BT Group","Indosat Ooredoo Hutchison","O2 Telefónica Germany","Safaricom","Telefónica",{"kpi":184,"label":185,"unit":45,"n":47,"nUpTo":46,"kind":48,"value":186,"qualifier":187,"claimant":51,"organization":182,"vendorReported":11},"energy-savings","Energy savings",8,"up-to","Optimizing energy use is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall under that infrastructure. Recital 55 limits safety components to systems that directly protect the infrastructure or the health and safety of persons, so an optimizer is not high risk by default, but a design in which it could affect emergency service availability should be assessed against point 2.",{"slug":190,"title":191,"shortTitle":192,"definition":193,"status":19,"industries":194,"functions":198,"patterns":200,"audience":106,"autonomy":31,"adoptionStage":88,"evidenceCount":201,"publicEvidenceCount":201,"organizations":202,"bestGrade":41,"headline":210,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":214},"security-alert-triage-and-investigation","AI for security alert triage and investigation in the SOC","Security alert triage","An AI agent in the security operations centre that picks up each new alert or user reported phishing email, gathers the evidence from the SIEM, endpoint, identity and threat intelligence tools, gives a verdict with its reasoning and a draft incident summary, and closes clear false positives while an analyst approves every containment action.",[120,195,122,196,197],"healthcare","government","professional-services",[199,24],"security-operations",[26,29,105,104],7,[203,204,205,206,207,208,209],"Avanade","Federal Housing Finance Agency","Human Managed","SEP2","St. Luke's University Health Network","TÜV SÜD","U.S. Immigration and Customs Enforcement",{"kpi":211,"label":212,"unit":45,"n":137,"nUpTo":47,"kind":138,"value":213,"qualifier":140,"claimant":73,"organization":73,"vendorReported":11},"productivity-gain","Productivity gain",60,"Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.",{"slug":216,"title":217,"shortTitle":218,"definition":219,"status":19,"industries":220,"functions":221,"patterns":222,"audience":106,"autonomy":107,"adoptionStage":88,"evidenceCount":224,"publicEvidenceCount":224,"organizations":225,"bestGrade":41,"headline":73,"lastVerified":74,"indexable":12,"euAiActTier":141,"euAiActBasis":228},"software-vulnerability-remediation","AI for software vulnerability triage and remediation","Vulnerability remediation","AI that takes security findings from scanners, fuzzers and bug reports, filters out duplicates and false positives, reproduces and ranks the real ones, and drafts a code fix with a test for each, which a developer reviews and merges through the normal change process.",[120,122,195],[199,24],[223,26,29],"code-generation",4,[129,226,227],"Labelbox","PatientPoint","Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.",{"slug":230,"title":231,"shortTitle":232,"definition":233,"status":19,"industries":234,"functions":235,"patterns":237,"audience":30,"autonomy":31,"adoptionStage":88,"segment":238,"evidenceCount":224,"publicEvidenceCount":224,"organizations":239,"bestGrade":41,"headline":240,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":244},"telecom-fraud-detection","AI for telecom fraud detection (SIM swap, IRSF and Wangiri)","Telecom fraud detection","AI that protects the operator's own network, revenue and numbers from fraud: it watches call, messaging, roaming and account activity to detect SIM swap and port out takeovers, international revenue share fraud (IRSF) and Wangiri one ring scams, blocks or flags them in real time, and shares risk signals with banks and other businesses that rely on the phone number for security. Scam calls aimed at subscribers are handled by call blocking.",[21],[236,23,199],"fraud-prevention",[27,28,29],"customer-protection",[40,111],{"kpi":241,"label":242,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":243,"qualifier":140,"claimant":51,"organization":111,"vendorReported":11},"detection-rate-improvement","Detection improvement",30,"Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.",{"slug":246,"title":247,"shortTitle":248,"definition":249,"status":19,"industries":250,"functions":252,"patterns":255,"audience":106,"autonomy":107,"adoptionStage":88,"segment":257,"evidenceCount":224,"publicEvidenceCount":224,"organizations":258,"bestGrade":41,"headline":73,"lastVerified":74,"indexable":12,"euAiActTier":141,"euAiActBasis":263},"vendor-due-diligence","AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[120,121,251,196,123],"insurance",[253,125,254],"procurement","regulatory-compliance",[256,104,26,105],"document-processing","second-line",[259,260,261,262],"U.S. Department of Justice","Internal Revenue Service","U.S. Department of Agriculture","U.S. Trade and Development Agency","Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.",{"slug":265,"title":266,"shortTitle":267,"definition":268,"status":19,"industries":269,"functions":271,"patterns":272,"audience":106,"autonomy":87,"adoptionStage":88,"segment":274,"evidenceCount":70,"publicEvidenceCount":70,"organizations":275,"bestGrade":41,"headline":73,"lastVerified":94,"indexable":12,"euAiActTier":53,"euAiActBasis":278},"freight-rail-rolling-stock-predictive-maintenance","AI predictive maintenance for freight rail rolling stock","Rail rolling stock predictive maintenance","Machine vision and machine learning that inspect freight railcar wheels, bearings and other running gear as trains pass wayside sensors and camera portals at track speed, learn what a healthy wheel or a healthy reading looks like, and flag the ones that need attention before a crack, an overheating bearing or a worn wheel causes a service failure or a derailment.",[270],"logistics-and-transportation",[84,63],[273,27,28],"computer-vision","mechanical-and-safety",[276,277],"BNSF Railway","Norfolk Southern","A system that flags a wheel or railcar for a qualified inspector to confirm is advisory and usually minimal risk. Under Article 6(1) it is high risk when both conditions hold: the same detection logic is built into a safety component of rolling stock or track equipment (or is itself such a product) covered by Directive (EU) 2016/797 on the interoperability of the rail system, which sits in Annex I Section B, for example if a flag were wired to trigger an automatic stop or speed restriction without a human check, and that directive requires a third party conformity assessment of the product. Under Article 2(2), as amended by Regulation (EU) 2026/1744, a high risk system of that kind is not subject to the full AI Act: only Article 6(1), Article 60a and Articles 102 to 112 apply directly, and Articles 57, 58 and 59 apply only so far as the high risk requirements have been integrated into the interoperability directive. The substantive high risk requirements reach the system through that directive instead, which Article 106 of the AI Act amends to require rail delegated and implementing acts to take those requirements into account.",{"slug":280,"title":281,"shortTitle":282,"definition":283,"status":19,"industries":284,"functions":286,"patterns":287,"audience":106,"autonomy":87,"adoptionStage":88,"segment":288,"evidenceCount":137,"publicEvidenceCount":137,"organizations":289,"bestGrade":41,"headline":73,"lastVerified":74,"indexable":12,"euAiActTier":53,"euAiActBasis":293},"industrial-asset-predictive-maintenance","AI predictive maintenance for industrial and energy assets","Industrial predictive maintenance","Machine learning that learns the normal behaviour of industrial and energy equipment from sensor and process data, flags early signs of degradation weeks or months before a failure, and turns them into prioritised maintenance work, so plants and utilities plan repairs instead of reacting to breakdowns.",[82,285],"manufacturing",[84,63],[27,28],"asset-management",[290,291,292],"Duke Energy","Georgia-Pacific","Shell","A system that advises engineers on the condition of equipment is usually minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; if predictive maintenance acts on protection or control in a utility network, it can become high risk. Article 6(1) can also apply when the AI is a safety component of machinery or another product covered by Annex I legislation and that product must undergo a third party conformity assessment.",1790598319564]