EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · CRITICAL INFRASTRUCTURE · SAFETY-COMPONENT AI

WHEN AI CAN AFFECT WATER, POWER, TRAFFIC OR DIGITAL INFRASTRUCTURE,
FAILURE HAS TO BE GOVERNED BEFORE CONSEQUENCE.

Critical-infrastructure AI is not high-risk merely because it is important. The key question is whether the system functions as a safety component in the management or operation of critical infrastructure—or falls under another Article 6 high-risk route. Once consequence can propagate into physical systems, continuity, fallback, authority and evidence become operational requirements, not paperwork.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 6 and Annex III, Point 2

Annex III classifies AI intended as safety components in critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity as high-risk. The Regulation distinguishes these safety components from components used solely for cybersecurity and treats serious irreversible disruption of critical infrastructure as a serious incident.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE AI A SAFETY COMPONENT?

Annex III classifies AI intended to be used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity as high-risk.

02

IS THE COMPONENT ACTUALLY PROTECTING SAFETY OR PHYSICAL INTEGRITY?

The Regulation explains that safety components directly protect the physical integrity of critical infrastructure or the health and safety of persons and property. Components used solely for cybersecurity are not treated as safety components for this Annex III route.

03

WHAT HAPPENS IF THE AI FAILS OR DRIFTS?

For critical infrastructure, model error can become operational consequence. Preserve fallback modes, human override, safe-state logic, thresholds, alarms, maintenance evidence, incident records and the boundaries that prevent silent escalation.

04

CAN YOU PROVE THE SYSTEM STAYED INSIDE ITS APPROVED ENVELOPE?

Preserve intended purpose, deployment location, system and model version, sensor/data sources, authority, operating limits, human oversight, risk controls, serious-incident history, material changes and revalidation decisions.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Define the exact infrastructure function

Separate forecasting, optimisation, cybersecurity, maintenance prediction, dispatch, safety monitoring, shutdown protection and control. Not every AI system used by a critical-infrastructure operator is automatically high-risk.

02

Determine whether the AI is a safety component or another regulated product component

Test the Annex III critical-infrastructure route and, where relevant, Article 6(1) product-safety routes under Annex I legislation. Preserve which classification route actually supports the result.

03

Bind operational authority to evidence and safe-state controls

Connect risk management, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, alarms, fallback, override and maintenance evidence to the consequence-bearing function.

04

Revalidate after operational or technical change

A model update, new sensor source, changed threshold, network expansion, control-system integration, operating-policy change or new infrastructure dependency can invalidate the prior risk and evidence state.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Is all AI used in critical infrastructure high-risk?

No. Annex III specifically targets AI intended to be used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.

What counts as a safety component?

The Regulation describes safety components as systems used to directly protect the physical integrity of critical infrastructure or the health and safety of persons and property. Examples in the recitals include water-pressure monitoring and fire-alarm control systems in cloud-computing centres.

Is cybersecurity AI in critical infrastructure automatically high-risk?

Not under this Annex III safety-component route when the component is intended solely for cybersecurity purposes. Other legal or product routes may still apply, so the exact function must be classified.

What evidence matters most for critical infrastructure AI?

Preserve system identity and version, intended purpose, safety function, data and sensor provenance, authority, operating thresholds, human oversight, fallback and override logic, logs, incidents, maintenance, material changes, limitations and revalidation history.

What if a critical-infrastructure AI system causes a major disruption?

The Regulation defines a serious incident to include a serious and irreversible disruption of the management or operation of critical infrastructure. Providers of high-risk systems are subject to serious-incident reporting duties under the Act.

Does TA-14 certify a critical-infrastructure AI deployment as compliant?

No. TA-14 can preserve the classification basis, safety evidence, authority, operating limits, gaps, change history and revalidation state. It does not itself provide legal advice, conformity assessment, certification or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views