EU AI Act: High-Risk AI in Energy Infrastructure
The sharpest duties of the EU AI Act arrive later than planned, but they arrive. For utilities this is not good news with an asterisk, it is a deadline with liability. Anyone using AI in grid control, dispatch or fault location has to know by 2 December 2027 whether that system is a safety component in the meaning of the law.
The Digital Omnibus moved the duties for stand-alone high-risk AI under Annex III of the EU AI Act from 2 August 2026 to 2 December 2027. Annex III point 2 classifies AI as high-risk when it works as a safety component in the supply of water, gas, heating or electricity. For utilities that means grid control, real-time dispatch, automated fault location and load forecasting with intervention can fall under the duty, while billing and marketing do not. From the cut-off, the AI Act requires risk management, data governance, human oversight, a conformity assessment and registration in the EU database, with penalties up to 15 million euros or 3 percent of global annual turnover. The framework adds to NIS2 and the EnWG security catalogues, it does not replace them.
What the Digital Omnibus actually moved
Start with the plain version. 2 August 2026 is off the table. For high-risk AI under Annex III the date is now 2 December 2027. That sounds like breathing room. It is not.
The European Commission proposed the Digital Omnibus on 19 November 2025, Parliament and Council agreed the text, and publication in the Official Journal is still pending. What moved is the day the duties bite. The duties themselves are unchanged. Confuse the two and you plan the deadline wrong.
The reason for the delay is unspectacular. The harmonised standards and support tools that make practical implementation possible were not ready in time. The deadline follows the standards, not the other way around. If you want the horizontal chronology, the general EU AI Act high-risk deadlines cover it. This piece is about the energy sector.
Sixteen more months are not a pause. Making a grid control system conformant takes longer than the extension suggests.
Why the extension is not a restWhen energy AI counts as high-risk
The decisive sentence sits in Annex III point 2, and it names the energy sector by name. High-risk is AI used as a safety component in the management and operation of critical infrastructure, or in the supply of water, gas, heating or electricity. No sub-clause. No room to argue about the industry. The only question is what counts as a safety component in your organisation.
Translated to supply, the test reads: can the failure of the AI endanger the safety or availability of the electricity, gas or heating supply. The second question follows: does the AI manage, prioritise or secure the infrastructure in a way where a failure hits that safety. Two times yes means Annex III.
A single system can become high-risk by two routes at once. If the AI sits inside a machine under the Machinery Regulation or in pressure equipment, Annex I applies on top. Both classifications carry their own duties, and one does not settle the other.
Concrete systems: what is covered and what is not
Now it gets practical. The dividing line does not run between departments, it runs between an effect on security of supply and everything else. A few examples so the classification does not become guesswork.
| AI system or function | Classification |
|---|---|
| Grid control and real-time dispatch | likely high-risk, steers supply directly |
| Automated fault location with disconnection (FLISR) | likely high-risk, switches without a human |
| Load forecasting with automatic intervention | likely high-risk, acts on the controls |
| Billing, tariff recommendation, marketing | probably not high-risk, no effect on supply |
| Cybersecurity-only AI | expressly excluded, protection rather than control |
A load forecast that only shows a human a chart and switches nothing stays outside. The same forecast that automatically charges a storage unit or curtails generation becomes a safety component. The difference is the intervention, not the model.
The borderline case belongs in the documentation, not waved away. For critical infrastructure, under-classification is the more expensive risk, because it leaves the conformity missing entirely when it counts.
The Article 6(3) filter
Not every AI that falls under Annex III is automatically high-risk. Article 6(3) carves out an exemption, and the Digital Omnibus sharpened it. For utilities this is the lever to narrow the number of genuinely affected systems honestly, without talking the duty away.
A system is not high-risk despite Annex III if it poses no significant risk to health, safety or fundamental rights, for instance because it performs a narrow procedural task or only prepares a human decision. For embedded AI the rule reads: if it merely optimises or supports a regulated product without its failure creating safety risks, the exemption applies.
One hard limit remains. As soon as the system profiles a natural person, the exemption is forfeited. It stays high-risk no matter how narrow the task. And whoever uses the exemption has to document the assessment before the system goes to market. The reasoning is part of the evidence, not a free-form note.
Which duties apply from 2 December 2027
Once a system is classified high-risk, the list of duties is long and concrete. It is also the reason sixteen months are tight. Making a grid control system conformant is not a form, it is a project with data work, documentation and external assessment.
Add the technical documentation under Annex IV, the built-in logging under Article 12, and demonstrated accuracy, robustness and cybersecurity at the level the infrastructure demands. At the end sit a conformity assessment, registration in the EU database for high-risk AI, and clear instructions for use for the deployers. That is a lot, and it sensibly does not start in November 2027.
AI Act meets NIS2 and EnWG
Here is the point many utilities underrate. The AI Act does not replace NIS2 or the EnWG security catalogues. It sits on top. The same grid control system then carries two sets of duties that overlap but do not coincide.
NIS2 and the KRITIS umbrella law govern the cybersecurity and resilience of operations through the BSI Act, in force since 6 December 2025. The security catalogues under Section 5c EnWG, successor to Section 11(1a) and (1b), set a security level for grid control. The AI Act additionally governs the quality, verifiability and oversight of the AI system itself.
Cybersecurity appears in both frameworks, with a different focus. NIS2 protects operations, the AI Act demands robustness as a property of the model. One set of evidence does not automatically satisfy the other.
In practice: if you already built an asset inventory and a risk management system for NIS2, you can build on it, but you have to classify and document the AI systems separately. The same mindset is familiar to anyone who worked on OT security under IEC 62443. Duplicate work is avoided only by planning both frameworks together rather than one after the other.
Legacy systems and substantial modification
Good news with fine print. AI already in use before 2 December 2027 is not initially covered by the new duties. But the grandfathering ends faster than it sounds, and public bodies face their own deadline anyway.
A high-risk system placed on the market before the cut-off stays free of the Annex III duties as long as it undergoes no substantial modification. Substantial means a change that shifts the system noticeably in design or purpose after the cut-off. A major model update or a new control function can void the grandfathering and trigger the full duty.
Public bodies face a separate deadline: high-risk systems already in use must be compliant by 2 August 2030. Many municipal utilities are public-law entities and therefore directly affected.
The grandfathering is therefore no rest, it is a reason to check every planned change to a high-risk AI for its trigger effect first. That changes how decisions about updates are made.
What utilities should do now
The build-up to the end of 2027 works best in steps, and it starts not with technology but with visibility. Without a register of the AI in use, not a single duty can be met. The good news: anyone already steering AI tools in-house deliberately, for instance when building a sovereign AI stack, has done part of the work already.
Five steps to the deadline
-
Build an AI inventory
Record every AI system, in-house and at vendors, that touches grid control, generation, metering or automation. Without this list every further assessment is patchwork. It takes a few days and decides everything after it.
-
Classify conservatively
Check each system against Annex III point 2 and the Article 6(3) filter. When in doubt, classify higher and document the reasoning, especially for systems that can switch. The classification stays with the utility.
-
Review vendor contracts
Clarify who demonstrates conformity, the AI vendor or you as the operator. Unassigned responsibility is the most common gap, and it surfaces in the audit, when it gets expensive.
-
Name an owner
Assign responsibility for AI conformity to a role that connects IT, grid operations and legal. The AI Act is not a pure IT task, and no one fills the gap that sits between three departments.
-
Plan alongside NIS2
Use the asset inventory and risk management from the NIS2 rollout as the base and add the AI-specific documentation. Two separate projects cost double, one shared project saves half.
What is assessed in the end is systems and their effect, not a single model. The model you run today may be replaced in two years. The classification and the duty to demonstrate stay. That is exactly why it pays to start now, and not once the standards are final.
Further Reading
Frequently Asked Questions
For stand-alone high-risk AI under Annex III the deadline is 2 December 2027. The Digital Omnibus moved it from the original 2 August 2026. For AI embedded as a safety component in a regulated product (Annex I), the deadline is 2 August 2028. High-risk systems already in use by public bodies must comply by 2 August 2030.
High-risk is AI that works as a safety component in the supply of electricity, gas or heating and whose failure could endanger the safety or availability of supply. That covers grid control, real-time dispatch, automated fault location with disconnection, and load forecasting with automatic intervention. AI for billing, tariff recommendations or marketing is not covered, and AI used solely for cybersecurity is expressly excluded.
The test is functional. A system is a safety component if its failure could cause physical damage to the infrastructure or harm to people. Annex III point 2 names the supply of water, gas, heating and electricity explicitly. What matters is whether the AI manages, prioritises or secures the infrastructure in a way where a failure hits safety or availability.
The AI Act requires a lifecycle risk management system (Article 9), data governance (Article 10), logging (Article 12), human oversight with the ability to intervene (Article 14), technical documentation under Annex IV, a conformity assessment, and registration in the EU database for high-risk AI. Penalties reach up to 15 million euros or 3 percent of global annual turnover.
No. The AI Act sits on top. NIS2 and the German BSI Act, in force since 6 December 2025, govern the cybersecurity and resilience of operations, and the security catalogues under Section 5c EnWG set the security level for grid control. The AI Act additionally governs the quality, verifiability and oversight of the AI system itself. One set of evidence does not automatically satisfy the other, so it pays to plan both frameworks together.
A high-risk system placed on the market before the cut-off is initially free of the Annex III duties as long as it undergoes no substantial modification. A major model update or a new control function can void that grandfathering. Public bodies face the 2 August 2030 deadline regardless, and many municipal utilities are directly affected as public-law entities.