A transport operator's AI answers to four authorities at once
Rail, aviation, maritime, and road all face the same four desks. Each holds its own legal basis, its own document requests, and its own clock.
01NIS2
Your cybersecurity authority
24h early warning after becoming aware of a significant incident
02Sector
The safety agencies
Before use certification and safety-case approval precede operation
03GDPR
The data protection authority
72h personal data breach notification under Article 33
04AI Act
The market surveillance authority
2 Dec 2027 Annex III obligations apply
The desk
Who can knock, and with what
Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.
Desk 01NIS2
Your cybersecurity authority
The national competent authority designated under NIS2 in your member state, with its CSIRT receiving incident notifications.
Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2), with the transposition deadline passed on 17 October 2024. Transport is listed in Annex I as a sector of high criticality, and most rail, air, water, and road operators above the size threshold are essential entities. The Critical Entities Resilience Directive runs beside it for physical resilience in the same sectors, with critical entities designated per member state.
What they can ask for
The Article 21 risk-management measures, supply chain included: every AI vendor from maintenance platforms to LLM copilots and vision systems
Management body approvals and training records under Article 20
Documented failure modes and dependencies for AI-driven traffic management and routing systems
Incident notifications under Article 23 on the three-stage timeline
The clock
24h
early warning after becoming aware of a significant incident
72h
incident notification
1 month
final report
Desk 02Sector
The safety agencies
The European Union Agency for Railways, EASA, and the national maritime administrations, with technical support from EMSA.
Safety approval sits before use. ERA issues single safety certificates for railway undertakings, EASA holds type certification and continuing airworthiness for aviation, and maritime safety rests with national administrations supported by EMSA. An AI subsystem inside a safety case meets the existing certification bar before it operates, and the agencies publish assurance guidance for AI in safety-critical functions such as signalling, air traffic control, and navigation.
What they can ask for
The safety case, with the evidence behind every AI-enabled subsystem inside it
Pre-market certification documentation for safety-critical functions
Lifetime monitoring records for AI-enabled systems in service
The clock
Before use
certification and safety-case approval precede operation
Lifetime
monitoring obligations follow AI-enabled systems in service
Desk 03GDPR
The data protection authority
Your supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.
Worker and passenger data. Driver monitoring, fatigue detection, and biometric access control for depots and vessels all engage the GDPR and Article 88 on processing in the employment context. High-risk processing of this kind calls for a data protection impact assessment under Article 35, and in most member states, consultation with worker representatives.
What they can ask for
Data protection impact assessments under Article 35 for driver and crew monitoring
The lawful basis behind cabin cameras, fatigue detection, and biometric access control
Records of processing under Article 30
The clock
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act
The market surveillance authority
The market surveillance authority your member state designates under Regulation (EU) 2024/1689.
High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of road traffic, and rail, aviation, and maritime traffic management sit under sector safety regimes that regulators align with the Act in practice. Under the adopted Digital Omnibus, Annex III duties apply from 2 December 2027.
What they can ask for
The technical file, on request under Article 74
The conformity assessment behind the CE marking
Data governance and training data documentation for safety-component AI
Automatically generated logs and human oversight records
The clock
2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness
The record is the same at every desk
Each desk asks a different question on a different legal basis, but the evidence behind the answers overlaps almost entirely: the inventory of AI-enabled subsystems, safety-case artefacts, oversight logs, vendor records, and incident history. Modulos keeps that evidence as one governance graph, where a control written for signalling safety earns credit under NIS2 Article 21 and AI Act Annex III at the same time.
Transport makes this harder than most sectors. Networks are geographically distributed, operated by subcontractors, and built on OT systems with decade-long lifecycles. Governance holds only when obligations decompose into controls that the depot, the control centre, and the vendor can each execute and evidence. The authorities do not coordinate their requests; the record is ready for whichever desk asks first.
01 NIS202 Sector03 GDPR04 AI Act→One evidence record
Dates that matter
2 Aug 2026
General application of the EU AI Act and the start of GPAI enforcement
2 Dec 2027
Annex III duties for safety components in traffic management, per the adopted Digital Omnibus
The use-case docket
The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a predictive maintenance model with no AI Act gate still answers to desks one and two.
Emotion recognition in driver or crew cabins without safety justification
Article 5(1)(f) prohibits AI that infers emotions in the workplace outside medical or safety exceptions. Driver-state systems defended as safety measures must be tightly scoped to drowsiness and attention, not general affect inference.
Prohibited (Art. 5)
AI as a safety component of road traffic or rail control
Explicitly high-risk under Annex III Part 2. Requires conformity assessment, technical file, human oversight, and continuous monitoring.
High-risk (Annex III)
Autonomous and driver-assistance systems in fleet operations
Safety-critical ADAS and autonomy subsystems are high-risk under Article 6(1). Vehicles are Annex I Union harmonisation legislation and type approval is a third-party conformity assessment, so both cumulative conditions apply. UNECE type-approval requirements via UN Regulation 155, 156, and 157 run alongside.
High-risk (Annex III)
Predictive maintenance on rolling stock, aircraft, vessels
No AI Act gate triggered when advisory. Still feeds safety-critical decisions, so needs documented data quality, drift monitoring, and human override. Pulled into Annex III Part 2 high-risk if outputs become a safety component.
No AI Act gate
Driver fatigue and cabin monitoring (AI biometrics)
High-risk as a safety component of the vehicle under Article 6(1), where Annex I and third-party type approval both apply. Article 50(3) transparency stacks on top because biometric categorisation is involved. Outside a defendable safety purpose, Article 5(1)(f) would apply instead. GDPR lawful-basis analysis and works-council consultation still required.
High-risk (Annex III)Transparency (Art. 50)
Generative assistants for dispatch and control-room staff
Article 50 transparency applies: users must be told they interact with AI and synthetic content must be labelled. Chapter V GPAI duties sit on the model provider. Pulled into Annex III Part 2 high-risk if outputs become a safety component of traffic management.
Transparency (Art. 50)
Related regulations
Go deeper on the regimes that apply to this sector:
Yes. Transport is a sector of high criticality listed in Annex I of NIS2, covering air, rail, water, and road transport. Medium and large entities in these sectors are automatically essential or important entities. The transposition deadline for Member States was 17 October 2024.
Does the EU AI Act apply to transport management systems?
Yes. Annex III Part 2 of the EU AI Act classifies AI systems intended to be used as safety components in the management and operation of road traffic and the supply of water, gas, heating, and electricity as high risk. Rail and aviation traffic management systems fall under similar sector-specific safety regimes that regulators increasingly align with the AI Act.
How does NIS2 interact with sector safety regulators?
NIS2 sits alongside, not on top of, sector regulators like ERA, EASA, and EMSA. Cybersecurity and AI governance obligations under NIS2 are cumulative with existing safety certification. Most operators run an integrated assurance programme to avoid duplicate evidence across safety cases and cyber documentation.
What counts as an AI incident under NIS2?
NIS2 defines a significant incident as one that has caused or is capable of causing severe operational disruption or financial loss. This includes AI-specific incidents such as model drift causing wrong routing, adversarial attacks on perception systems, or catastrophic generative AI hallucinations in dispatch contexts. The 24-hour early-warning clock starts when the entity becomes aware of the incident.
Are driver monitoring and cabin cameras allowed under the EU AI Act?
AI systems inferring emotions in the workplace are prohibited under Article 5 of the EU AI Act, unless deployed for strictly medical or safety reasons. Fatigue detection can usually be defended as a safety measure but requires a documented justification, a GDPR lawful basis, data minimisation, and in most Member States, consultation with worker representatives.
How does Modulos help transportation operators?
Modulos models NIS2, CER, the EU AI Act, ISO/IEC 42001, and sector safety controls together. You inventory AI-enabled subsystems once, classify their risk, map the overlapping obligations, and run incident, training, and supplier workflows from the same place. Evidence is reusable, auditable, and board-ready.
See the governance graph on one of your subsystems
A demo walks through the four desks with a signalling or driver-monitoring use case. The quiz classifies your role and risk exposure in about three minutes.