EU AI Act Annex III: which AI at a utility is really high-risk
The camera on the substation fence may be high-risk. The load forecast in grid planning, according to the Commission's draft, is not. Since 19 May 2026 there are two conditions and nine examples from electricity supply to sort by. None of it is final yet. It is still the most precise template a municipal utility has had for its AI inventory.
High-risk AI under Annex III point 2 of the EU AI Act is AI used as a safety component in the operation of electricity, gas or heat supply; under the European Commission's draft guidelines of 19 May 2026 this applies only if the AI directly protects the physical integrity of the installation and its operator has been identified by a Member State as a critical entity under the CER Directive. Obligations for such systems apply from 2 December 2027 under Regulation (EU) 2026/1744. For electricity the draft gives two high-risk examples, perimeter protection and anomaly detection that supports decisions on load distribution, grid stability or shutdowns, and seven counter-examples, among them load and consumption forecasts, imbalance forecasts under human supervision, early warnings to the grid control centre and cybersecurity-only AI. The consultation closed on 23 July 2026, and the Commission has announced the final version for the end of 2026. Still open is how to classify AI that switches on its own, such as automatic dimming under Section 14a of the German Energy Industry Act without an independent protection layer.
What the draft guidelines change
The draft replaces the rule of thumb "AI that intervenes is high-risk" with a test built on two conditions. The Commission published it on 19 May 2026 under Article 6(5) of the AI Act, which obliges it to issue guidelines with practical examples. The Annex III part alone runs to 148 pages. Critical infrastructure sits in section 3.2, electricity supply in 3.2.7.
Two caveats up front. It's a draft: the consultation ran until 23 July 2026 after a one-month extension, and the final text is due by the end of 2026. And it isn't binding. Paragraph 6 says so itself, only the Court of Justice can give an authoritative reading of the AI Act.
That doesn't make it irrelevant. In Germany the Bundesnetzagentur has been the market surveillance authority since 29 July 2026, and an authority that inspects will lean on what the Commission publishes as its reading. What the regulator is allowed to do is covered in our piece on KI-MIG and the Bundesnetzagentur as AI supervisor.
Our own assessment from early August, high-risk AI in energy infrastructure, still sorted by intervention: a load forecast that acts automatically was probably high-risk, a pure display was not. The draft asks a different question. Not whether the AI does something, but whether it protects something. The list of duties that follows a high-risk classification, and the grandfathering rules, stay in that earlier piece. This one is only about the question before them.
Two conditions, and both must hold
Under the draft, AI falls under Annex III point 2 only if it is a safety component and it is used by a critical entity under the CER Directive. If either condition fails, this route to high-risk is closed. Annex I can still apply, for example when the AI is part of a machine.
The first condition is about function. Paragraph 184 lists six: detecting dangerous situations, detecting a need for maintenance, preventing an installation from starting when behaviour looks abnormal, controlling and limiting what an installation does, mitigating consequences, for instance with a safe stop, and supervising another safety system. If an AI fits none of the six, you can stop looking.
Two more paragraphs shift the test. Paragraph 186 says to take into account whether a redundant or backup system already protects physical integrity directly. And paragraph 187, drawing on Recital 55, says AI used only for cybersecurity is never a safety component.
The second condition has nothing to do with technology. Paragraph 190 reads the AI Act's reference to the CER Directive to mean that only AI used by a critical entity identified by a Member State can be high-risk here. For electricity, paragraph 203 lists the categories: suppliers, distribution and transmission system operators, producers, nominated electricity market operators, and market participants in demand response, aggregation and storage.
Which leads to a result people find odd. The same software is high-risk at one utility and not at the next one down the road. What decides is the operator's legal status, not the code.
The examples from electricity supply
For electricity the draft names two systems inside Annex III point 2 and seven outside it. The list isn't exhaustive. It does hit the applications utilities actually run or put out to tender.
| AI system | Classification in the draft | Reason given, shortened |
|---|---|---|
| Perimeter protection with cameras, radar, drone control | High-risk | directly protects the physical integrity of the site |
| Anomaly detection in grid operation for monitoring and supporting decisions on load distribution, grid stability, shutdowns | High-risk | supports decisions on critical functions |
| Grid optimisation based on demand forecasts | Not high-risk | core safety functions are handled elsewhere |
| Cybersecurity monitoring of grid communication networks | Not high-risk | cybersecurity only, separate from OT |
| Quality assurance of meter installation from photos | Not high-risk | recommendation to a person, no safety function |
| Incident early warning to the grid control centre | Not high-risk | does not act itself, the control centre decides |
| Anomaly analysis as a basis for future improvements | Not high-risk | a person checks it, no direct safety function |
| Consumption forecasting as an assistant, local to transmission level | Not high-risk | recommendation without a safety function |
| Imbalance forecasts in 15-minute intervals, supervised by a person | Not high-risk | no direct link between system and harm |
The imbalance example tells you the most. The draft admits a faulty forecast can mislead dispatch, touch grid stability and even end in supply problems. It still doesn't classify it as high-risk. The chain is too long.
Gas and heat follow the same line. Predictive maintenance on a gas pipeline is out, because the existing safety systems keep running independently. So is a patrol robot in a heating plant, which only detects and never intervenes.
So what about the forecasting AI many grid operators are rolling out right now? AI load forecasting in the distribution grid that feeds numbers to planners and the control room sits clearly outside. Perimeter protection is the opposite case, and in Germany it is also a core topic of the KRITIS umbrella act, covered in our piece on counter-drone defence at energy facilities. Buy an AI camera for the fence and you may be buying a high-risk system.
Where the draft rubs against itself
Two of the examples sit so close together that a utility could file its control-room AI on either side and defend both.
On the high-risk side the draft places AI that detects anomalies in data patterns when operating electricity grids "for the purpose of monitoring and supporting decision-making in relation to critical functions, such as power load distribution, grid stability, or shutdown procedures". That is the wording of the draft of 19 May 2026.
A few lines further down, on the other side, is the early warning sent to the control centre. Of that one, the same document says: "It does not act on itself but rather only enriches the decision-making options in the grid control centre." And of anomaly detection whose output a human checks, it says it "exists to enrich the decision-making process. It lacks a direct safety function."
Does an anomaly alert that the shift supervisor reads before a switching operation support his decision? Or does it only enrich his options? The draft answers with the intended purpose the provider sets. In the control room the two look identical.
The line has a history. In its consultation response of July 2025, Eurelectric, the European electricity industry association, asked to limit the high-risk definition to AI systems "that directly impact safety components in electricity supply" and to exclude supportive or peripheral algorithms. The argument was cost: "In practice, compliance could force the shutdown of useful algorithms due to lack of resources." On substance, the Commission has largely followed.
It did add one lock the industry hadn't asked for. Under paragraph 75, split architectures are assessed as a whole, "to avoid circumvention of the high-risk classification rules by system design". A forecast, an optimiser and a switching command, each harmless on its own, can add up to one high-risk system. Agentic AI is named explicitly.
We won't resolve that tension here. It's in the text, and nobody knows in September 2026 whether the final version will smooth it out. What it means in practice: the purpose written into the contract and the vendor's manual becomes the classification document.
The grey zone: AI that switches by itself
The murkiest case is AI that doesn't warn but acts. The draft has no example of AI switching the power grid on its own.
The obvious scenario in a distribution grid: AI-supported grid state estimation under Section 14a spots an imminent overload at a secondary substation transformer and triggers, via the smart meter gateway, a dimming of controllable consumers under Section 14a of the Energy Industry Act, with no human releasing the command. What the Section 14a control box does technically is regulated. How the AI Act views the AI in front of it is not.
Such a system matches two of the six safety functions: controlling and limiting an installation, and mitigating consequences in a dangerous condition. An overloaded transformer is property damage. Paragraph 186 points the other way. If conventional grid protection with fuses and protection relays stays fully in service and independent of the AI, it is the protection that guards the asset, not the AI. The draft's gas example argues exactly this way.
That's a working hypothesis, nothing more. Two things we'd rely on. If you introduce AI with switching authority, document which independent protection layer remains and whether it holds without the AI. And a human sign-off doesn't automatically change the classification, as the anomaly example shows. It does when the human actually decides.
Provider or deployer when you buy AI in
With purchased AI the utility is usually the deployer and the vendor the provider. Most high-risk duties sit with the provider: risk management, technical documentation, conformity assessment. The deployer has to use the system according to its instructions, give human oversight to people with the competence and authority for it, monitor operation and keep the automatically generated logs for at least six months (Article 26).
The role can flip. Under Article 25 a deployer becomes a provider if it puts its own name on a high-risk system, modifies it substantially, or changes the purpose of a system so that it becomes high-risk. That happens more easily than it sounds. A utility buys anomaly detection for after-the-fact analysis, and grid operations later wires it into the control room as the basis for switching. Same code. Different purpose.
Paragraph 191 helps with procurement. A critical entity doesn't have to disclose its status to the vendor, it can simply require high-risk compliance in the tender, the contract or the technical specification. The draft expects some operators to do so even without formal status, for liability or governance reasons. For grid control system vendors that means the question will show up in a good share of utility tenders.
Aggregators are a special case. As market participants in aggregation and demand response they appear in the list of electricity entities themselves. If a utility works with an external platform that dispatches flexibility, the AI there can be high-risk at the platform operator even though nothing at the utility switches.
AI inventory and classification in five steps
No inventory, no classification. No classification, no procurement decision that holds until December 2027. The steps below describe how a utility can organise the work. They are no substitute for a legal review of an individual case.
From register to classification
-
Capture everything, including what is built in
Don't just count projects with "AI" in the name. Most models live inside purchased systems: the grid control system, forecasting software, asset management, video analytics at the fence, your flexibility partner's platform. Ask vendors in writing which functions rely on machine learning.
-
Write down purpose and effect
One line per system: who reads the output, who decides, what switches without a human?
-
Test for a safety function
Map each system to the six functions of paragraph 184 or record that it matches none. Note which independent protection layer runs alongside it. Cybersecurity-only AI gets the note "cybersecurity, not Annex III point 2" and moves into the ISMS.
-
Get critical entity status as an input
Whether your company is a critical entity isn't for grid or IT to decide. Management and legal set that, once Germany's ordinance under the KRITIS umbrella act is in place. Until then, keep both columns: with and without status.
-
Turn the result into procurement and operations
Attach the classification to the asset inventory you already built for NIS2, so it doesn't gather dust in a spreadsheet. For systems with a possible safety function, add the high-risk compliance question to tenders, as paragraph 191 allows. And decide who signs off when an existing system gets a new purpose, because that is exactly when the provider role can change under Article 25.
Our AI regulatory matrix gives an overview of duties by role and deadline. At a multi-utility in northern Germany we have supported the grid portfolio since 2024, around 40 initiatives including a Section 14a programme with five sub-projects. Which software decides what comes up in every one of them.
Critical entity status and NIS2 on the road to December 2027
In Germany the second condition hangs on an ordinance that hasn't been issued. The KRITIS umbrella act has applied since 17 March 2026. Which facilities count as critical is left to the KRITIS ordinance, whose draft the Federal Ministry of the Interior presented on 26 May 2026. It keeps 500,000 supplied residents as the reference threshold, and as of 21 September 2026 it was still going through the process. The CER Directive had given Member States until 17 July 2026 to identify their critical entities.
KRITIS umbrella act in force
Thresholds still missing, they come by ordinance.
Commission draft guidelines
Two conditions, consultation until 23 July, final version announced for the end of 2026.
Omnibus and KI-MIG in force
Regulation (EU) 2026/1744 moves the high-risk deadlines; two days later the Bundesnetzagentur becomes market surveillance authority and, under Section 20 KI-MIG, keeps a non-public register for Annex III point 2.
Annex III duties apply
AI under Annex I, embedded in regulated products, follows on 2 August 2028.
The transparency duties of Article 50 apply separately and have done since 2 August 2026, for a customer service chatbot, say. The details of the postponement are in our piece on high-risk deadlines after the Digital Omnibus.
And NIS2? Cybersecurity AI stays where it already is: in the information security management system under the German BSI Act and the Bundesnetzagentur's IT security catalogue. Recital 55 explicitly takes it out of Annex III point 2. How NIS2 and the KRITIS umbrella act fit together is explained in NIS2 and the KRITIS umbrella law 2026. For all other AI, don't run two inventories. One asset register with a column for the AI classification is enough.
Fourteen months to December 2027 sounds like plenty. But whoever buys control-room AI writes the requirements now, and nobody swaps a grid control system every year. The classification belongs in the tender, not in the acceptance test.
This article gives a general reading of the Commission's draft guidelines for typical roles at municipal utilities and grid operators. It is not legal advice and not a review of your individual case. Whether a system at your company is high-risk, and whether your company counts as a critical entity, is for your legal department or legal counsel to determine. Status: draft of 19 May 2026, final version pending.
Further Reading
Frequently Asked Questions
Annex III point 2 of the EU AI Act covers AI used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heat and electricity. Under the Commission's draft guidelines of 19 May 2026, the AI must directly protect the physical integrity of the installation, and its operator must be identified as a critical entity under the CER Directive.
Not according to the draft. The Commission lists grid optimisation based on demand forecasts and consumption forecasting as an assistant explicitly as examples outside Annex III point 2, because the safety functions are handled elsewhere. It can look different when the same forecast is part of a chain that switches without a human decision.
No. As of 26 September 2026 there is a draft. The consultation closed on 23 July 2026, and the Commission has announced the final version for the end of 2026. Even the final version is not binding under paragraph 6, only the Court of Justice of the European Union can interpret the AI Act authoritatively.
In Germany the KRITIS umbrella act governs this and has applied since 17 March 2026. Which facilities are critical is set by an ordinance. Its draft of 26 May 2026 uses 500,000 supplied residents as the reference value and was still in the process on 21 September 2026. Classifying your own company is a matter for management and the legal department.
No, if it is used only for cybersecurity. Recital 55 and paragraph 187 of the draft separate safety components from cybersecurity components. Such systems stay within NIS2, the German BSI Act and the IT security catalogue.
Most high-risk duties sit with the provider, usually the vendor. As deployer, the utility is responsible for use according to the instructions, human oversight, monitoring and keeping the logs. If it changes a system's purpose so that it becomes high-risk, it can become a provider itself under Article 25.