Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries

Annex III duties across the sectors apply from 2 December 2027

The AI Act lands differently in every sector

The EU AI Act sets the horizontal baseline. Your sector decides which Annex III category applies, which regulators can knock, and which rules stack on top.

01

Pick your sector

Each row carries the sector's stakes, the desks that can knock, and the nearest dated obligation. The page behind it holds the mandates, document requests, and clocks.

Financial services

Annex III Part 5 makes credit scoring and insurance pricing high risk under the EU AI Act. DORA, ECB model risk guidance, and ISO/IEC 42001 layer underneath.

DORASSMGDPRAI Act

The clock

2 Dec 2027

Annex III duties for credit scoring and insurance pricing

Transportation

Annex III Part 2 classifies AI safety components in road traffic as high risk; rail, air, and maritime AI runs through sector safety regimes. NIS2 and the CER Directive sit behind for resilience.

NIS2SectorGDPRAI Act

The clock

2 Dec 2027

Annex III duties for road-traffic safety AI

Utilities

Safety-component AI in the supply of electricity, gas, water, and heating is Annex III high risk. NIS2 adds cyber duties for a sector of high criticality and the CER Directive adds physical resilience.

NIS2EnergyGDPRAI Act

The clock

2 Dec 2027

Annex III duties for safety-component grid AI

Mobility

Article 6(1) ties the EU AI Act to UN-R 155, 156, 157 and the General Safety Regulation. Safety-component ADAS, automated driving, and mandated driver monitoring are high risk.

Type approvalAI ActGDPR

The clock

2 Aug 2028

Article 6(1) high-risk track for vehicle AI

Telecommunications

Annex III Part 2 reaches network AI as a safety component of critical digital infrastructure. BEREC, ENISA, and NIS2 add sector-specific obligations.

NIS2NRAGDPRAI Act

The clock

2 Dec 2027

Annex III duties for safety-component network AI

Defense & national security

Article 2(3) carves out exclusively military AI, but Recital 24 pulls dual-use and civilian lines back in. NATO PRUs and ISO/IEC 42001 cover the rest.

Dual-useProcurementAI Act

The clock

2 Dec 2027

Annex III duties for in-scope civilian AI

02

The regime matrix, for reference

Which rules govern AI in each sector
SectorEU AI ActNIS2DORAGDPRISO/IEC 42001Sector regimes
Financial ServicesAnnex III 5(b), 5(c)DORA lex specialisArt. 22×ECB model risk guide
TransportationAnnex III Part 2essential entity××CER · ERA, EASA, EMSA
UtilitiesAnnex III Part 2essential entity×smart metering×CER · ACER
MobilityArt. 6(1) product track××cabin biometrics×UN-R 155/156/157 · GSR
TelecommunicationsAnnex III Part 2essential entity×plus ePrivacy×BEREC · ENISA
Defense & National SecurityArt. 2(3) carve-out, dual-use in scope××××NATO · DoDD 3000.09 · CMMC 2.0

● primary driver · ○ applies · × not a focus for this sector. For orientation only.

03

Why one programme works in every sector

The EU AI Act sets the horizontal baseline, but every regulated sector adds its own layer. A bank running an AI underwriting model reconciles the AI Act high-risk regime with DORA, ECB model risk expectations, and GDPR. A rail operator runs the same AI Act obligations against NIS2, the CER Directive, and safety rules from the European Union Agency for Railways. A mobility OEM runs UN Regulation 155, 156, and 157 alongside the AI Act and ISO/PAS 8800.

The cost of running AI governance as separate per-framework programmes is duplicate work. Each team ends up maintaining its own spreadsheet of controls, its own incident playbook, its own evidence store. Modulos is built on a single governance graph, so a control written once for ISO/IEC 42001 is reused wherever the EU AI Act, DORA, NIS2, or sector guidance shares it. Everything traces back to the original requirement.

The sector pages describe the regulatory pressure, the AI use cases most likely to be classified high-risk, and the governance pattern that works in that sector. They are starting points for AI governance strategy, board briefings, and vendor conversations. For decisions about a specific system, bring in counsel.

See your sector on the governance graph

Talk to an expert

A demo starts from your sector's desks and use cases, on the governance graph your evidence would live in.

Request a demo

Keep exploring on your own

The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on the regimes in the matrix.