● Annex III Point 2 · High-Risk

Critical Infrastructure , Annex III Point 2 High-Risk AI

AI used as a safety component in the management or operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating and electricity is high-risk under Annex III Point 2. Safety-critical classification triggers intersection with sectoral regulation, including the NIS2 Directive, CER Directive, and sector-specific product safety law.

Regulation EU 2024/1689 2 Dec 2027, Annex III (post-Omnibus) Article 6(2) + Annex III Point 2
What Annex III Point 2 Covers

Scope, Definitions and Boundary with Prohibited Practices

Annex III Point 2 captures AI systems intended to be used as safety components in the management and operation of critical infrastructure. The scope covers critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. The key legal hook is the phrase "safety component", AI that, if it fails, could put the life and health of persons, property, or the environment at risk.

This is the point most frequently intersecting with other EU regulatory regimes. Operators of essential services under the NIS2 Directive (Directive (EU) 2022/2555) and critical entities under the CER Directive (Directive (EU) 2022/2557) may already be subject to cybersecurity and resilience obligations that overlap with Articles 9, 15 and 16 of the AI Act. Dual compliance is possible but must be deliberately mapped, the AI Act does not defer to sectoral law, it layers on top.

Not legal advice. This page summarises the relevant Articles and Annex III provisions of Regulation (EU) 2024/1689 for orientation. Always consult qualified legal counsel before making compliance decisions.
In Scope / Out of Scope

Example Systems Under Annex III Point 2

Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.

Example

Predictive grid load-balancing AI at a TSO

High-risk safety component, influences dispatch decisions that affect the electricity supply.

Example

Traffic signal timing optimisation on a motorway

High-risk if the AI output directly controls signalling with safety consequences.

Example

SCADA anomaly detection for water utility

High-risk where the detection output triggers operational response affecting supply.

Example

IT-only resource optimisation for a data centre (no safety control)

Arguably out of scope of Point 2, but may still trigger Point 5 (essential services) if it affects availability of public services.

Example

AI-managed rail track switching

High-risk, embedded AI in regulated products under Annex I may additionally trigger Annex I obligations with a 2027 deadline.

Compliance Obligations

The Articles That Apply

High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.

ArticleObligationWhat It Means in Practice
Art. 9Risk Management SystemHazard analysis inherited from functional-safety practice (IEC 61508, ISO 26262) must be extended to cover AI-specific failure modes, data drift, adversarial robustness, explainability gaps.
Art. 10Data GovernanceOperational data used for training must be representative of the deployment environment. Out-of-distribution handling must be specified and tested.
Art. 11, Annex IVTechnical DocumentationFull Annex IV technical documentation is mandatory. For critical infrastructure this typically runs to hundreds of pages and must integrate with existing safety cases.
Art. 12LoggingAutomated logs must be retained for at least six months (longer if sectoral law requires). Logs must permit reconstruction of system operation, not merely events.
Art. 14Human OversightHuman-in-the-loop or human-on-the-loop must be meaningfully implementable given the real-time constraints of infrastructure operation. This is often the hardest article to satisfy for high-automation environments.
Art. 15Accuracy, Robustness, CybersecurityCybersecurity requirements are enforced together with NIS2, the two regimes share a common vocabulary but have distinct reporting obligations.
Art. 26Deployer ObligationsWhere the deployer is a critical entity under the CER Directive, Article 26 duties stack with CER resilience obligations, they do not substitute.
Art. 49EU Database RegistrationEven where the system is already registered under NIS2 or sectoral notification regimes, a distinct AI Act Annex III registration is required.
Common Failure Modes

Pitfalls to Avoid on Annex III Point 2

Recurrent patterns seen in pre-enforcement readiness assessments.

Pitfall

Treating NIS2 compliance as sufficient

NIS2 addresses cybersecurity and resilience of network and information systems, the AI Act addresses the behaviour of the AI system itself. The two overlap but neither is a substitute for the other.

Pitfall

Assuming 'safety component' means 'hardware'

A purely software AI module whose output influences a safety-critical decision is a safety component. Cloud-delivered inference services are not excluded.

Pitfall

Underestimating logging burden

Six months of full operational logs for a high-throughput infrastructure system can run to terabytes. Storage, retrieval, and tamper-evidence must all be specified.

Pitfall

Confusing Point 2 with Annex I

AI embedded in machinery, medical devices, vehicles etc. falls under Annex I and has a later 2 August 2027 deadline. Point 2 applies to AI managing the broader infrastructure, the classification rule is in Article 6.

Professional Documentation

Operationalise Point 2 Compliance

The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).

$499

one-time · instant download

Get the Full Bundle →

Also available: Checklist Pack $149  ·  White-Label $999/yr

Related Reading

Next Steps

Classify Your System

Interactive 3-question quiz to confirm Annex III scope.

Run Classifier →

All 8 Annex III Domains

Overview of every Annex III high-risk category.

Annex III Overview →

Deadline Planning

15-week compliance work plan for the EU AI Act's phased timeline.

Week-by-Week Plan →