Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries / Transportation

A transport operator's AI answers to four authorities at once

Rail, aviation, maritime, and road all face the same four desks. Each holds its own legal basis, its own document requests, and its own clock.

01NIS2

Your cybersecurity authority

24h early warning after becoming aware of a significant incident

02Sector

The safety agencies

Before use certification and safety-case approval precede operation

03GDPR

The data protection authority

72h personal data breach notification under Article 33

04AI Act

The market surveillance authority

2 Dec 2027 Annex III obligations apply

The desk

Who can knock, and with what

Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.

Desk 01NIS2

Your cybersecurity authority

The national competent authority designated under NIS2 in your member state, with its CSIRT receiving incident notifications.

Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2), with the transposition deadline passed on 17 October 2024. Transport is listed in Annex I as a sector of high criticality, and most rail, air, water, and road operators above the size threshold are essential entities. The Critical Entities Resilience Directive runs beside it for physical resilience in the same sectors, with critical entities designated per member state.

What they can ask for

  • The Article 21 risk-management measures, supply chain included: every AI vendor from maintenance platforms to LLM copilots and vision systems
  • Management body approvals and training records under Article 20
  • Documented failure modes and dependencies for AI-driven traffic management and routing systems
  • Incident notifications under Article 23 on the three-stage timeline

The clock

24h
early warning after becoming aware of a significant incident
72h
incident notification
1 month
final report
Desk 02Sector

The safety agencies

The European Union Agency for Railways, EASA, and the national maritime administrations, with technical support from EMSA.

Safety approval sits before use. ERA issues single safety certificates for railway undertakings, EASA holds type certification and continuing airworthiness for aviation, and maritime safety rests with national administrations supported by EMSA. An AI subsystem inside a safety case meets the existing certification bar before it operates, and the agencies publish assurance guidance for AI in safety-critical functions such as signalling, air traffic control, and navigation.

What they can ask for

  • The safety case, with the evidence behind every AI-enabled subsystem inside it
  • Pre-market certification documentation for safety-critical functions
  • Lifetime monitoring records for AI-enabled systems in service

The clock

Before use
certification and safety-case approval precede operation
Lifetime
monitoring obligations follow AI-enabled systems in service
Desk 03GDPR

The data protection authority

Your supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.

Worker and passenger data. Driver monitoring, fatigue detection, and biometric access control for depots and vessels all engage the GDPR and Article 88 on processing in the employment context. High-risk processing of this kind calls for a data protection impact assessment under Article 35, and in most member states, consultation with worker representatives.

What they can ask for

  • Data protection impact assessments under Article 35 for driver and crew monitoring
  • The lawful basis behind cabin cameras, fatigue detection, and biometric access control
  • Records of processing under Article 30

The clock

72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act

The market surveillance authority

The market surveillance authority your member state designates under Regulation (EU) 2024/1689.

High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of road traffic, and rail, aviation, and maritime traffic management sit under sector safety regimes that regulators align with the Act in practice. Under the adopted Digital Omnibus, Annex III duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • The conformity assessment behind the CE marking
  • Data governance and training data documentation for safety-component AI
  • Automatically generated logs and human oversight records

The clock

2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness

The record is the same at every desk

Each desk asks a different question on a different legal basis, but the evidence behind the answers overlaps almost entirely: the inventory of AI-enabled subsystems, safety-case artefacts, oversight logs, vendor records, and incident history. Modulos keeps that evidence as one governance graph, where a control written for signalling safety earns credit under NIS2 Article 21 and AI Act Annex III at the same time.

Transport makes this harder than most sectors. Networks are geographically distributed, operated by subcontractors, and built on OT systems with decade-long lifecycles. Governance holds only when obligations decompose into controls that the depot, the control centre, and the vendor can each execute and evidence. The authorities do not coordinate their requests; the record is ready for whichever desk asks first.

01 NIS202 Sector03 GDPR04 AI ActOne evidence record

Dates that matter

2 Aug 2026

General application of the EU AI Act and the start of GPAI enforcement

2 Dec 2027

Annex III duties for safety components in traffic management, per the adopted Digital Omnibus

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a predictive maintenance model with no AI Act gate still answers to desks one and two.

Emotion recognition in driver or crew cabins without safety justification

Article 5(1)(f) prohibits AI that infers emotions in the workplace outside medical or safety exceptions. Driver-state systems defended as safety measures must be tightly scoped to drowsiness and attention, not general affect inference.

Prohibited (Art. 5)

AI as a safety component of road traffic or rail control

Explicitly high-risk under Annex III Part 2. Requires conformity assessment, technical file, human oversight, and continuous monitoring.

High-risk (Annex III)

Autonomous and driver-assistance systems in fleet operations

Safety-critical ADAS and autonomy subsystems are high-risk under Article 6(1). Vehicles are Annex I Union harmonisation legislation and type approval is a third-party conformity assessment, so both cumulative conditions apply. UNECE type-approval requirements via UN Regulation 155, 156, and 157 run alongside.

High-risk (Annex III)

Predictive maintenance on rolling stock, aircraft, vessels

No AI Act gate triggered when advisory. Still feeds safety-critical decisions, so needs documented data quality, drift monitoring, and human override. Pulled into Annex III Part 2 high-risk if outputs become a safety component.

No AI Act gate

Driver fatigue and cabin monitoring (AI biometrics)

High-risk as a safety component of the vehicle under Article 6(1), where Annex I and third-party type approval both apply. Article 50(3) transparency stacks on top because biometric categorisation is involved. Outside a defendable safety purpose, Article 5(1)(f) would apply instead. GDPR lawful-basis analysis and works-council consultation still required.

High-risk (Annex III)Transparency (Art. 50)

Generative assistants for dispatch and control-room staff

Article 50 transparency applies: users must be told they interact with AI and synthetic content must be labelled. Chapter V GPAI duties sit on the model provider. Pulled into Annex III Part 2 high-risk if outputs become a safety component of traffic management.

Transparency (Art. 50)

Related regulations

Go deeper on the regimes that apply to this sector:

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Frequently asked questions

Is transportation in scope for NIS2?

Yes. Transport is a sector of high criticality listed in Annex I of NIS2, covering air, rail, water, and road transport. Medium and large entities in these sectors are automatically essential or important entities. The transposition deadline for Member States was 17 October 2024.

Does the EU AI Act apply to transport management systems?

Yes. Annex III Part 2 of the EU AI Act classifies AI systems intended to be used as safety components in the management and operation of road traffic and the supply of water, gas, heating, and electricity as high risk. Rail and aviation traffic management systems fall under similar sector-specific safety regimes that regulators increasingly align with the AI Act.

How does NIS2 interact with sector safety regulators?

NIS2 sits alongside, not on top of, sector regulators like ERA, EASA, and EMSA. Cybersecurity and AI governance obligations under NIS2 are cumulative with existing safety certification. Most operators run an integrated assurance programme to avoid duplicate evidence across safety cases and cyber documentation.

What counts as an AI incident under NIS2?

NIS2 defines a significant incident as one that has caused or is capable of causing severe operational disruption or financial loss. This includes AI-specific incidents such as model drift causing wrong routing, adversarial attacks on perception systems, or catastrophic generative AI hallucinations in dispatch contexts. The 24-hour early-warning clock starts when the entity becomes aware of the incident.

Are driver monitoring and cabin cameras allowed under the EU AI Act?

AI systems inferring emotions in the workplace are prohibited under Article 5 of the EU AI Act, unless deployed for strictly medical or safety reasons. Fatigue detection can usually be defended as a safety measure but requires a documented justification, a GDPR lawful basis, data minimisation, and in most Member States, consultation with worker representatives.

How does Modulos help transportation operators?

Modulos models NIS2, CER, the EU AI Act, ISO/IEC 42001, and sector safety controls together. You inventory AI-enabled subsystems once, classify their risk, map the overlapping obligations, and run incident, training, and supplier workflows from the same place. Evidence is reusable, auditable, and board-ready.

See the governance graph on one of your subsystems

A demo walks through the four desks with a signalling or driver-monitoring use case. The quiz classifies your role and risk exposure in about three minutes.