A telecom operator's AI answers to four authorities at once
Cybersecurity, telecom regulation, data protection, and market surveillance each arrive with their own legal basis and their own clock.
01NIS2
Your cybersecurity authority
24h early warning after becoming aware of a significant incident
02NRA
The national telecom regulator
Ongoing supervision of markets, spectrum, and quality of service
03GDPR
The data protection authority
72h personal data breach notification under Article 33
04AI Act
The market surveillance authority
2 Dec 2027 Annex III obligations apply
The desk
Who can knock, and with what
Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.
Desk 01NIS2
Your cybersecurity authority
The NIS2 competent authority in your member state, working with its CSIRT. Providers of public electronic communications networks and services sit in the digital infrastructure sector of Annex I as essential entities, and small and micro providers are in scope regardless of size under Article 2(2)(b).
Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2). NIS2 repealed EECC Articles 40 and 41 in October 2024, so telecom security supervision now runs through this desk. Article 21 sets the risk-management measures and Article 23 the reporting duties, with ENISA Technical Implementation Guidance (v1.0, June 2025) filling in the detail. Network and security AI sits inside the same measures.
What they can ask for
The Article 21 risk-management measures and the evidence behind them, network and security AI included
Incident reports on the 24-hour, 72-hour, and one-month timeline
Supply-chain security records covering cloud inference and model vendors
Management-body approval, oversight, and training records under Article 20
The clock
24h
early warning after becoming aware of a significant incident
72h
incident notification with an initial assessment
1 month
final report
Desk 02NRA
The national telecom regulator
The BEREC-coordinated national regulatory authority: BNetzA, ARCEP, or their peer in your member state. For UK operators, Ofcom holds the equivalent desk and opened a Call for Input on AI in telecoms in January 2026.
Spectrum, market analysis, and quality of service under the European Electronic Communications Code. BEREC's June 2023 report on AI solutions in telecommunications names six priority use cases, from network and capacity planning to fraud detection, and its 2025 work programme follows up on the impact of AI on internet openness and the environment. In several member states this desk also enforces ePrivacy rules over traffic and location data; in others that sits with the data protection authority.
What they can ask for
Traffic-management and quality-of-service records where AI steers or prioritises traffic
Responses to information requests on market analysis and network performance
The clock
Ongoing
supervision of markets, spectrum, and quality of service
Per request
information requests set their own deadlines
Desk 03GDPR
The data protection authority
Your lead supervisory authority under the GDPR. Subscriber, traffic, and location data are among the most sensitive categories it sees, and it does not wait for the AI Act.
GDPR, applicable since 25 May 2018, plus ePrivacy rules on traffic and location data where your member state assigns them here. EDPB Opinion 28/2024 (December 2024) addresses AI models directly: when anonymity claims are defensible, when legitimate interest works as a lawful basis, and what follows when training data was processed unlawfully. Churn, anti-fraud, customer-analytics, and generative customer-service models all sit inside this mandate.
What they can ask for
Data protection impact assessments under Article 35 for churn, analytics, and fraud models
Lawful-basis records for AI training and customer analytics, tested against Opinion 28/2024
The human review path behind automated fraud and SIM-swap decisions under Article 22
The clock
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act
The market surveillance authority
The authority your member state designates under the AI Act. Telecom has no equivalent of the financial services rule that reuses the sector supervisor, so for most operators this is a new counterpart.
High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of critical digital infrastructure, which on the common interpretation reaches network automation, security, and resilience AI in public communications networks. Under the adopted Digital Omnibus, these duties apply from 2 December 2027.
What they can ask for
The technical file, on request under Article 74
Data governance and training data documentation for network and security models
Automatically generated logs and human oversight records
The conformity assessment behind the CE marking
The clock
2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness
Every desk reads from the same record
The cybersecurity authority asks for the Article 21 measures behind network AI. The telecom regulator asks how AI steers traffic and quality of service. The data protection authority asks for lawful bases and DPIAs. The market surveillance authority asks for the technical file. The evidence behind those answers overlaps almost entirely: the AI inventory with safety-component classification, oversight logs, supplier records, and incident history. Modulos keeps that evidence as one governance graph, where a control written once earns credit across every framework it satisfies. The authorities do not coordinate their requests; the record is ready for whichever desk knocks first.
01 NIS202 NRA03 GDPR04 AI Act→One evidence record
Dates that matter
2 Aug 2026
General application of the EU AI Act and the start of GPAI enforcement
2 Dec 2027
Annex III duties for safety components of critical digital infrastructure, per the adopted Digital Omnibus
The use-case docket
The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a SIM-swap model with no AI Act gate still answers to desks two and three.
Untargeted scraping of subscriber facial images
Article 5(1)(e) prohibits systems built by untargeted scraping of facial images from the internet or CCTV to create facial recognition databases.
Prohibited (Art. 5)
AI as a safety component of critical digital infrastructure
On the common interpretation of Annex III Part 2, network-automation AI whose outputs significantly influence operational decisions is high risk.
High-risk (Annex III)
Behavioural fraud and SIM-swap detection
No AI Act gate in typical deployments. GDPR Article 22 and consumer protection still raise the bar.
No AI Act gate
Customer analytics and churn modelling
No gate in typical deployments. GDPR, ePrivacy, and EDPB Opinion 28/2024 still apply.
No AI Act gate
Generative AI customer service agents
Article 50: customers must be told they interact with AI. Chapter V duties sit upstream on the model provider.
Transparency (Art. 50)
Internal productivity and dev-tooling AI
No gate when outputs do not feed customer or network decisions. NIS2 supply-chain duties still apply where SaaS is involved.
No AI Act gate
Related regulations
Go deeper on the regimes that apply to this sector:
Yes. Providers of public electronic communications networks and publicly available electronic communications services are listed as Annex I essential entities. Under Article 2(2)(b), small and micro providers are in scope regardless of size, because cybersecurity of public communications is considered critical in its own right. NIS2 repealed Articles 40 and 41 of the EECC in October 2024, so security obligations for telecoms now flow directly from NIS2.
Is telecom network AI automatically high risk under the EU AI Act?
Not automatically. Annex III Part 2 classifies AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as high risk. There is no binding EU guidance yet defining exactly which network-automation systems meet that threshold. The common interpretation is that AI significantly influencing operational decisions in a public communications network falls inside the definition, and most operators are scoping network automation, resilience, and security AI accordingly.
When do the high-risk AI Act obligations start for telecoms?
Annex III obligations were originally due on 2 August 2026. The Digital Omnibus, adopted by the Parliament and Council in June 2026, shifts that date to 2 December 2027. Prohibited practices and AI literacy apply since 2 February 2025, and GPAI obligations since 2 August 2025. The extra time is for execution, not a reason to pause inventory, classification, and evidence work.
What about BEREC and ENISA guidance?
BEREC published a report on AI solutions in telecommunications in June 2023 setting out six priority use cases, and its 2025 work programme follows up with a report on the impact of AI on internet openness and the environment. ENISA published Technical Implementation Guidance for NIS2 (v1.0, June 2025), operationalising Implementing Regulation (EU) 2024/2690 for digital infrastructure and ICT service management. Both feed directly into national supervisory expectations.
How does GDPR apply to telecom AI models?
EDPB Opinion 28/2024 (December 2024) addresses the GDPR treatment of AI models: when anonymity claims are defensible, when legitimate interest works as a lawful basis, and what happens when training data was processed unlawfully. It reaches churn, anti-fraud, customer-analytics, and generative customer-service models. The EDPB Guidelines on Article 5(3) ePrivacy (October 2024) also extend cookie-style rules to any technology accessing or storing information on user terminal equipment.
How does Modulos help telecom operators?
Modulos gives telecom operators a single governance graph where the EU AI Act, NIS2, ENISA guidance, GDPR, ISO/IEC 27001, and ISO/IEC 42001 share controls and evidence. You inventory AI-enabled network and customer systems, classify safety-component risk, run incident and supplier workflows, and generate technical documentation and board reporting without duplicating work across CISO, data protection, and AI teams.
See the governance graph on one of your network models
A demo walks through the four desks with a network automation or fraud use case. The quiz classifies your role and risk exposure in about three minutes.