Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries / Telecommunications

A telecom operator's AI answers to four authorities at once

Cybersecurity, telecom regulation, data protection, and market surveillance each arrive with their own legal basis and their own clock.

01NIS2

Your cybersecurity authority

24h early warning after becoming aware of a significant incident

02NRA

The national telecom regulator

Ongoing supervision of markets, spectrum, and quality of service

03GDPR

The data protection authority

72h personal data breach notification under Article 33

04AI Act

The market surveillance authority

2 Dec 2027 Annex III obligations apply

The desk

Who can knock, and with what

Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.

Desk 01NIS2

Your cybersecurity authority

The NIS2 competent authority in your member state, working with its CSIRT. Providers of public electronic communications networks and services sit in the digital infrastructure sector of Annex I as essential entities, and small and micro providers are in scope regardless of size under Article 2(2)(b).

Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2). NIS2 repealed EECC Articles 40 and 41 in October 2024, so telecom security supervision now runs through this desk. Article 21 sets the risk-management measures and Article 23 the reporting duties, with ENISA Technical Implementation Guidance (v1.0, June 2025) filling in the detail. Network and security AI sits inside the same measures.

What they can ask for

  • The Article 21 risk-management measures and the evidence behind them, network and security AI included
  • Incident reports on the 24-hour, 72-hour, and one-month timeline
  • Supply-chain security records covering cloud inference and model vendors
  • Management-body approval, oversight, and training records under Article 20

The clock

24h
early warning after becoming aware of a significant incident
72h
incident notification with an initial assessment
1 month
final report
Desk 02NRA

The national telecom regulator

The BEREC-coordinated national regulatory authority: BNetzA, ARCEP, or their peer in your member state. For UK operators, Ofcom holds the equivalent desk and opened a Call for Input on AI in telecoms in January 2026.

Spectrum, market analysis, and quality of service under the European Electronic Communications Code. BEREC's June 2023 report on AI solutions in telecommunications names six priority use cases, from network and capacity planning to fraud detection, and its 2025 work programme follows up on the impact of AI on internet openness and the environment. In several member states this desk also enforces ePrivacy rules over traffic and location data; in others that sits with the data protection authority.

What they can ask for

  • Traffic-management and quality-of-service records where AI steers or prioritises traffic
  • Spectrum-use evidence behind dynamic spectrum sharing
  • Responses to information requests on market analysis and network performance

The clock

Ongoing
supervision of markets, spectrum, and quality of service
Per request
information requests set their own deadlines
Desk 03GDPR

The data protection authority

Your lead supervisory authority under the GDPR. Subscriber, traffic, and location data are among the most sensitive categories it sees, and it does not wait for the AI Act.

GDPR, applicable since 25 May 2018, plus ePrivacy rules on traffic and location data where your member state assigns them here. EDPB Opinion 28/2024 (December 2024) addresses AI models directly: when anonymity claims are defensible, when legitimate interest works as a lawful basis, and what follows when training data was processed unlawfully. Churn, anti-fraud, customer-analytics, and generative customer-service models all sit inside this mandate.

What they can ask for

  • Data protection impact assessments under Article 35 for churn, analytics, and fraud models
  • Lawful-basis records for AI training and customer analytics, tested against Opinion 28/2024
  • The human review path behind automated fraud and SIM-swap decisions under Article 22

The clock

72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act

The market surveillance authority

The authority your member state designates under the AI Act. Telecom has no equivalent of the financial services rule that reuses the sector supervisor, so for most operators this is a new counterpart.

High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of critical digital infrastructure, which on the common interpretation reaches network automation, security, and resilience AI in public communications networks. Under the adopted Digital Omnibus, these duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • Data governance and training data documentation for network and security models
  • Automatically generated logs and human oversight records
  • The conformity assessment behind the CE marking

The clock

2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness

Every desk reads from the same record

The cybersecurity authority asks for the Article 21 measures behind network AI. The telecom regulator asks how AI steers traffic and quality of service. The data protection authority asks for lawful bases and DPIAs. The market surveillance authority asks for the technical file. The evidence behind those answers overlaps almost entirely: the AI inventory with safety-component classification, oversight logs, supplier records, and incident history. Modulos keeps that evidence as one governance graph, where a control written once earns credit across every framework it satisfies. The authorities do not coordinate their requests; the record is ready for whichever desk knocks first.

01 NIS202 NRA03 GDPR04 AI ActOne evidence record

Dates that matter

2 Aug 2026

General application of the EU AI Act and the start of GPAI enforcement

2 Dec 2027

Annex III duties for safety components of critical digital infrastructure, per the adopted Digital Omnibus

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a SIM-swap model with no AI Act gate still answers to desks two and three.

Untargeted scraping of subscriber facial images

Article 5(1)(e) prohibits systems built by untargeted scraping of facial images from the internet or CCTV to create facial recognition databases.

Prohibited (Art. 5)

AI as a safety component of critical digital infrastructure

On the common interpretation of Annex III Part 2, network-automation AI whose outputs significantly influence operational decisions is high risk.

High-risk (Annex III)

Behavioural fraud and SIM-swap detection

No AI Act gate in typical deployments. GDPR Article 22 and consumer protection still raise the bar.

No AI Act gate

Customer analytics and churn modelling

No gate in typical deployments. GDPR, ePrivacy, and EDPB Opinion 28/2024 still apply.

No AI Act gate

Generative AI customer service agents

Article 50: customers must be told they interact with AI. Chapter V duties sit upstream on the model provider.

Transparency (Art. 50)

Internal productivity and dev-tooling AI

No gate when outputs do not feed customer or network decisions. NIS2 supply-chain duties still apply where SaaS is involved.

No AI Act gate

Related regulations

Go deeper on the regimes that apply to this sector:

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Frequently asked questions

Are telecom operators in scope of NIS2?

Yes. Providers of public electronic communications networks and publicly available electronic communications services are listed as Annex I essential entities. Under Article 2(2)(b), small and micro providers are in scope regardless of size, because cybersecurity of public communications is considered critical in its own right. NIS2 repealed Articles 40 and 41 of the EECC in October 2024, so security obligations for telecoms now flow directly from NIS2.

Is telecom network AI automatically high risk under the EU AI Act?

Not automatically. Annex III Part 2 classifies AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as high risk. There is no binding EU guidance yet defining exactly which network-automation systems meet that threshold. The common interpretation is that AI significantly influencing operational decisions in a public communications network falls inside the definition, and most operators are scoping network automation, resilience, and security AI accordingly.

When do the high-risk AI Act obligations start for telecoms?

Annex III obligations were originally due on 2 August 2026. The Digital Omnibus, adopted by the Parliament and Council in June 2026, shifts that date to 2 December 2027. Prohibited practices and AI literacy apply since 2 February 2025, and GPAI obligations since 2 August 2025. The extra time is for execution, not a reason to pause inventory, classification, and evidence work.

What about BEREC and ENISA guidance?

BEREC published a report on AI solutions in telecommunications in June 2023 setting out six priority use cases, and its 2025 work programme follows up with a report on the impact of AI on internet openness and the environment. ENISA published Technical Implementation Guidance for NIS2 (v1.0, June 2025), operationalising Implementing Regulation (EU) 2024/2690 for digital infrastructure and ICT service management. Both feed directly into national supervisory expectations.

How does GDPR apply to telecom AI models?

EDPB Opinion 28/2024 (December 2024) addresses the GDPR treatment of AI models: when anonymity claims are defensible, when legitimate interest works as a lawful basis, and what happens when training data was processed unlawfully. It reaches churn, anti-fraud, customer-analytics, and generative customer-service models. The EDPB Guidelines on Article 5(3) ePrivacy (October 2024) also extend cookie-style rules to any technology accessing or storing information on user terminal equipment.

How does Modulos help telecom operators?

Modulos gives telecom operators a single governance graph where the EU AI Act, NIS2, ENISA guidance, GDPR, ISO/IEC 27001, and ISO/IEC 42001 share controls and evidence. You inventory AI-enabled network and customer systems, classify safety-component risk, run incident and supplier workflows, and generate technical documentation and board reporting without duplicating work across CISO, data protection, and AI teams.

See the governance graph on one of your network models

A demo walks through the four desks with a network automation or fraud use case. The quiz classifies your role and risk exposure in about three minutes.