Critical Infrastructure , Annex III Point 2 High-Risk AI
AI used as a safety component in the management or operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating and electricity is high-risk under Annex III Point 2. Safety-critical classification triggers intersection with sectoral regulation, including the NIS2 Directive, CER Directive, and sector-specific product safety law.
Scope, Definitions and Boundary with Prohibited Practices
Annex III Point 2 captures AI systems intended to be used as safety components in the management and operation of critical infrastructure. The scope covers critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. The key legal hook is the phrase "safety component", AI that, if it fails, could put the life and health of persons, property, or the environment at risk.
This is the point most frequently intersecting with other EU regulatory regimes. Operators of essential services under the NIS2 Directive (Directive (EU) 2022/2555) and critical entities under the CER Directive (Directive (EU) 2022/2557) may already be subject to cybersecurity and resilience obligations that overlap with Articles 9, 15 and 16 of the AI Act. Dual compliance is possible but must be deliberately mapped, the AI Act does not defer to sectoral law, it layers on top.
Example Systems Under Annex III Point 2
Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.
Example
Predictive grid load-balancing AI at a TSO
High-risk safety component, influences dispatch decisions that affect the electricity supply.
Example
Traffic signal timing optimisation on a motorway
High-risk if the AI output directly controls signalling with safety consequences.
Example
SCADA anomaly detection for water utility
High-risk where the detection output triggers operational response affecting supply.
Example
IT-only resource optimisation for a data centre (no safety control)
Arguably out of scope of Point 2, but may still trigger Point 5 (essential services) if it affects availability of public services.
Example
AI-managed rail track switching
High-risk, embedded AI in regulated products under Annex I may additionally trigger Annex I obligations with a 2027 deadline.
The Articles That Apply
High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.
| Article | Obligation | What It Means in Practice |
|---|---|---|
| Art. 9 | Risk Management System | Hazard analysis inherited from functional-safety practice (IEC 61508, ISO 26262) must be extended to cover AI-specific failure modes, data drift, adversarial robustness, explainability gaps. |
| Art. 10 | Data Governance | Operational data used for training must be representative of the deployment environment. Out-of-distribution handling must be specified and tested. |
| Art. 11, Annex IV | Technical Documentation | Full Annex IV technical documentation is mandatory. For critical infrastructure this typically runs to hundreds of pages and must integrate with existing safety cases. |
| Art. 12 | Logging | Automated logs must be retained for at least six months (longer if sectoral law requires). Logs must permit reconstruction of system operation, not merely events. |
| Art. 14 | Human Oversight | Human-in-the-loop or human-on-the-loop must be meaningfully implementable given the real-time constraints of infrastructure operation. This is often the hardest article to satisfy for high-automation environments. |
| Art. 15 | Accuracy, Robustness, Cybersecurity | Cybersecurity requirements are enforced together with NIS2, the two regimes share a common vocabulary but have distinct reporting obligations. |
| Art. 26 | Deployer Obligations | Where the deployer is a critical entity under the CER Directive, Article 26 duties stack with CER resilience obligations, they do not substitute. |
| Art. 49 | EU Database Registration | Even where the system is already registered under NIS2 or sectoral notification regimes, a distinct AI Act Annex III registration is required. |
Pitfalls to Avoid on Annex III Point 2
Recurrent patterns seen in pre-enforcement readiness assessments.
Treating NIS2 compliance as sufficient
NIS2 addresses cybersecurity and resilience of network and information systems, the AI Act addresses the behaviour of the AI system itself. The two overlap but neither is a substitute for the other.
Assuming 'safety component' means 'hardware'
A purely software AI module whose output influences a safety-critical decision is a safety component. Cloud-delivered inference services are not excluded.
Underestimating logging burden
Six months of full operational logs for a high-throughput infrastructure system can run to terabytes. Storage, retrieval, and tamper-evidence must all be specified.
Confusing Point 2 with Annex I
AI embedded in machinery, medical devices, vehicles etc. falls under Annex I and has a later 2 August 2027 deadline. Point 2 applies to AI managing the broader infrastructure, the classification rule is in Article 6.
Operationalise Point 2 Compliance
The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).
one-time · instant download
Get the Full Bundle →Also available: Checklist Pack $149 · White-Label $999/yr
Next Steps
Deadline Planning
15-week compliance work plan for the EU AI Act's phased timeline.
Week-by-Week Plan →