EU Postpones AI Regulations for Critical Infrastructure

Specific requirements for high-risk AI in electricity, gas, heating, and water networks will not take effect until the end of 2027. However, basic AI rules are already mandatory today.

August 4, 2026

Source: E & M powernews

Most provisions of the EU AI Regulation have been in effect since August 2026. However, the specific obligations for high-risk systems in critical infrastructure will not take effect until the end of 2027.

TheEU AI Regulation has actuallybeen in effect since August 1, 2024. August 2, 2026, marks the general effective date for most of the provisions. This means that the regulation is applicable in large part—but only in large part. This is because the specific provisions for high-risk AI systems—which include AI systems for critical infrastructure—were deferred by the so-called “Digital Omnibus Regulation on AI” of July 8, 2026. They now take effect on December 2, 2027. The Digital Omnibus Regulation entered into force on July 27, 2026.

It applies to the systems listed in Annex III of the AI Regulation, which are classified by the EU as “high-risk AI.” These include “AI systems used as safety-critical components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heat, or electricity,” as stated in the EU document.

Thus, it is not solely a matter of whether the respective company is classified as a critical infrastructure operator. The decisive factor is whether the artificial intelligence performs a safety function. Systems that serve exclusively to provide user support, optimize performance, improve operational efficiency, automate processes, perform quality control, or enhance user-friendliness are not classified as “safety components.” However, systems “whose failure or malfunction would endanger health and safety are considered safety components.” AI used to ensure load distribution and grid stability, systems for switching operations, or systems for the physical security of critical facilities are therefore included.

General Rules Not Affected by the Delay

The resulting obligations for electricity, gas, and water network operators relate, among other things, to appropriate technical and organizational measures for operating the AI, sufficiently qualified personnel to supervise and monitor the use of AI, the reporting of serious incidents, and the documentation and archiving of measures.

Regardless of the postponement of the high-risk regulations, network operators must already comply with the general rules. These include, in particular, the bans on certain AI practices that have been in effect since February 2025 and the obligation to take measures to promote employees’ AI literacy. In addition, the transparency requirements of Article 50 have been in effect since August 2, 2026, for example, for certain chatbots or synthetically generated content.

In addition, NIS2, the CER Directive on the resilience of critical infrastructure, as well as energy law and technical safety requirements, remain in full force. The AI Regulation supplements these regulations with AI-specific requirements but does not replace them.

The postponement that has now taken place is intended to ensure that the requirements for high-risk AI can be implemented effectively and uniformly. Since standards, common specifications, and guidelines are still lacking, and national supervisory structures are in some cases not yet in place, there was a risk of legal uncertainty and disproportionately high implementation costs as of August 2, 2026. Therefore, the obligations for high-risk AI under Annex III will not take effect until December 2, 2027, and those for product-related systems under Annex I will not take effect until August 2, 2028.

Author: Fritz Wilhelm