Industries
Annex III duties across the sectors apply from 2 December 2027The AI Act lands differently in every sector
The EU AI Act sets the horizontal baseline. Your sector decides which Annex III category applies, which regulators can knock, and which rules stack on top.
Pick your sector
Each row carries the sector's stakes, the desks that can knock, and the nearest dated obligation. The page behind it holds the mandates, document requests, and clocks.
Financial services
Annex III Part 5 makes credit scoring and insurance pricing high risk under the EU AI Act. DORA, ECB model risk guidance, and ISO/IEC 42001 layer underneath.
The clock
2 Dec 2027
Annex III duties for credit scoring and insurance pricing
Transportation
Annex III Part 2 classifies AI safety components in road traffic as high risk; rail, air, and maritime AI runs through sector safety regimes. NIS2 and the CER Directive sit behind for resilience.
The clock
2 Dec 2027
Annex III duties for road-traffic safety AI
Utilities
Safety-component AI in the supply of electricity, gas, water, and heating is Annex III high risk. NIS2 adds cyber duties for a sector of high criticality and the CER Directive adds physical resilience.
The clock
2 Dec 2027
Annex III duties for safety-component grid AI
Mobility
Article 6(1) ties the EU AI Act to UN-R 155, 156, 157 and the General Safety Regulation. Safety-component ADAS, automated driving, and mandated driver monitoring are high risk.
The clock
2 Aug 2028
Article 6(1) high-risk track for vehicle AI
Telecommunications
Annex III Part 2 reaches network AI as a safety component of critical digital infrastructure. BEREC, ENISA, and NIS2 add sector-specific obligations.
The clock
2 Dec 2027
Annex III duties for safety-component network AI
Defense & national security
Article 2(3) carves out exclusively military AI, but Recital 24 pulls dual-use and civilian lines back in. NATO PRUs and ISO/IEC 42001 cover the rest.
The clock
2 Dec 2027
Annex III duties for in-scope civilian AI
The regime matrix, for reference
Which rules govern AI in each sector
| Sector | EU AI Act | NIS2 | DORA | GDPR | ISO/IEC 42001 | Sector regimes |
|---|---|---|---|---|---|---|
| Financial Services | ●Annex III 5(b), 5(c) | DORA lex specialis | ● | ●Art. 22 | ● | ×ECB model risk guide |
| Transportation | ●Annex III Part 2 | ●essential entity | × | ○ | ● | ×CER · ERA, EASA, EMSA |
| Utilities | ●Annex III Part 2 | ●essential entity | × | ○smart metering | ● | ×CER · ACER |
| Mobility | ●Art. 6(1) product track | × | × | ○cabin biometrics | ● | ×UN-R 155/156/157 · GSR |
| Telecommunications | ●Annex III Part 2 | ●essential entity | × | ●plus ePrivacy | ● | ×BEREC · ENISA |
| Defense & National Security | Art. 2(3) carve-out, dual-use in scope | × | × | × | ● | ×NATO · DoDD 3000.09 · CMMC 2.0 |
● primary driver · ○ applies · × not a focus for this sector. For orientation only.
Why one programme works in every sector
The EU AI Act sets the horizontal baseline, but every regulated sector adds its own layer. A bank running an AI underwriting model reconciles the AI Act high-risk regime with DORA, ECB model risk expectations, and GDPR. A rail operator runs the same AI Act obligations against NIS2, the CER Directive, and safety rules from the European Union Agency for Railways. A mobility OEM runs UN Regulation 155, 156, and 157 alongside the AI Act and ISO/PAS 8800.
The cost of running AI governance as separate per-framework programmes is duplicate work. Each team ends up maintaining its own spreadsheet of controls, its own incident playbook, its own evidence store. Modulos is built on a single governance graph, so a control written once for ISO/IEC 42001 is reused wherever the EU AI Act, DORA, NIS2, or sector guidance shares it. Everything traces back to the original requirement.
The sector pages describe the regulatory pressure, the AI use cases most likely to be classified high-risk, and the governance pattern that works in that sector. They are starting points for AI governance strategy, board briefings, and vendor conversations. For decisions about a specific system, bring in counsel.
See your sector on the governance graph
Talk to an expert
A demo starts from your sector's desks and use cases, on the governance graph your evidence would live in.
Request a demo →Keep exploring on your own
The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on the regimes in the matrix.