Industries · Transportation
Annex III duties for road-traffic safety AI apply from 2 December 2027A transport operator's AI answers to four authorities at once
Rail, aviation, maritime, and road all face the same four desks. Each holds its own legal basis, its own document requests, and its own clock.
What you need to know
- Four desks recur across the modes. Rail, aviation, maritime, and road operators answer to the NIS2 competent authority, the sector safety agencies (ERA, EASA, and the maritime administrations with EMSA), the data protection authority, and the AI Act market surveillance authority. Which of them reaches a given operator depends on mode, size, and member state.
- NIS2 already applies. Transport is an Annex I sector of high criticality, the transposition deadline passed on 17 October 2024. A significant incident starts a 24-hour early-warning clock with 72-hour and one-month follow-ups.
- Safety approval comes before use, and the AI Act follows. An AI subsystem inside a safety case meets the existing certification bar before it operates. Annex III Part 2 names road-traffic safety components as high risk, with duties applying from 2 December 2027.
- Crew monitoring sits next to a prohibition. Article 5(1)(f) bans emotion inference in the workplace outside medical or safety grounds. Fatigue and drowsiness detection sits outside the Act's definition of emotion recognition, but it still calls for a GDPR impact assessment where the risk is high, and worker consultation where national employment law requires it.
- One record backs every answer. The subsystem inventory, safety-case artefacts, oversight logs, vendor records, and incident history back the safety case, the Article 21 measures, and, for high-risk systems, the AI Act technical file once they live in one governance graph.
The use-case docket
The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a predictive maintenance model with no AI Act gate still answers to desks one and two.
Emotion recognition in driver or crew cabins without safety justification
Article 5(1)(f) prohibits AI that infers emotions in the workplace outside medical or safety exceptions. Driver-state systems defended as safety measures must be tightly scoped to drowsiness and attention. General affect inference stays inside the prohibition.
AI as a safety component of road traffic or rail control
Explicitly high-risk under Annex III Part 2. Requires conformity assessment, technical file, human oversight, and continuous monitoring.
Autonomous and driver-assistance systems in fleet operations
Safety-critical ADAS and autonomy subsystems are high-risk under Article 6(1). Vehicles are Annex I Union harmonisation legislation and type approval is a third-party conformity assessment, so both cumulative conditions apply. UNECE type-approval requirements via UN Regulation 155, 156, and 157 run alongside.
Predictive maintenance on rolling stock, aircraft, vessels
No AI Act gate triggered when advisory. Still feeds safety-critical decisions, so needs documented data quality, drift monitoring, and human override. Pulled into Annex III Part 2 high-risk if outputs become a safety component.
Driver fatigue and cabin monitoring (AI biometrics)
High-risk as a safety component of the vehicle under Article 6(1), where Annex I and third-party type approval both apply. Article 50(3) transparency stacks on top because biometric categorisation is involved. Outside a defendable safety purpose, Article 5(1)(f) would apply instead. GDPR lawful-basis analysis and works-council consultation still required.
Generative assistants for dispatch and control-room staff
Article 50 transparency applies: users must be told they interact with AI and synthetic content must be labelled. Chapter V GPAI duties sit on the model provider. Pulled into Annex III Part 2 high-risk if outputs become a safety component of traffic management.
Who can knock, and with what
The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.
01NIS2Your cybersecurity authority
The national competent authority designated under NIS2 in your member state, with its CSIRT receiving incident notifications.
Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2), with the transposition deadline passed on 17 October 2024. Transport is listed in Annex I as a sector of high criticality, and most rail, air, water, and road operators above the size threshold are essential entities. The Critical Entities Resilience Directive runs beside it for physical resilience in the same sectors, with critical entities designated per member state.
What they can ask for
- The Article 21 risk-management measures, supply chain included: every AI vendor from maintenance platforms to LLM copilots and vision systems
- Management body approvals and training records under Article 20
- Documented failure modes and dependencies for AI-driven traffic management and routing systems
- Incident notifications under Article 23 on the three-stage timeline
- 24h
- early warning after becoming aware of a significant incident
- 72h
- incident notification
- 1 month
- final report
02SectorThe safety agencies
The European Union Agency for Railways, EASA, and the national maritime administrations, with technical support from EMSA.
Safety approval sits before use. ERA issues single safety certificates for railway undertakings, EASA holds type certification and continuing airworthiness for aviation, and maritime safety rests with national administrations supported by EMSA. An AI subsystem inside a safety case meets the existing certification bar before it operates, and the agencies publish assurance guidance for AI in safety-critical functions such as signalling, air traffic control, and navigation.
What they can ask for
- The safety case, with the evidence behind every AI-enabled subsystem inside it
- Pre-market certification documentation for safety-critical functions
- Lifetime monitoring records for AI-enabled systems in service
- Before use
- certification and safety-case approval precede operation
- Lifetime
- monitoring obligations follow AI-enabled systems in service
03GDPRThe data protection authority
Your supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.
Worker and passenger data. Driver monitoring, fatigue detection, and biometric access control for depots and vessels all engage the GDPR and Article 88 on processing in the employment context. High-risk processing of this kind calls for a data protection impact assessment under Article 35, and in most member states, consultation with worker representatives.
What they can ask for
- Data protection impact assessments under Article 35 for driver and crew monitoring
- The lawful basis behind cabin cameras, fatigue detection, and biometric access control
- Records of processing under Article 30
- 72h
- personal data breach notification under Article 33
- 1 month
- response to a data subject request under Article 12(3)
04AI ActThe market surveillance authority
The market surveillance authority your member state designates under Regulation (EU) 2024/1689.
High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of road traffic, and rail, aviation, and maritime traffic management sit under sector safety regimes that regulators align with the Act in practice. Under the Digital Omnibus, now in force, Annex III duties apply from 2 December 2027.
What they can ask for
- The technical file, on request under Article 74
- The conformity assessment behind the CE marking
- Data governance and training data documentation for safety-component AI
- Automatically generated logs and human oversight records
- 2 Dec 2027
- Annex III obligations apply
- 15 days
- serious incident report under Article 73, from awareness
The regimes overlap where the controls live
For transport operators the framework library carries the EU AI Act, NIS2, the GDPR, and ISO/IEC 42001 on shared controls. A control written for signalling safety is reusable under NIS2 Article 21 and, for high-risk road-traffic systems, in the AI Act technical file, which matters in a sector built on subcontractors and decade-long OT lifecycles.
Framework library v1.0.32
Frequently asked questions
Is transportation in scope for NIS2?
Yes. Transport is a sector of high criticality listed in Annex I of NIS2, covering air, rail, water, and road transport. Medium and large entities in these sectors are automatically essential or important entities. The transposition deadline for Member States was 17 October 2024.
Does the EU AI Act apply to transport management systems?
Yes. Annex III Part 2 of the EU AI Act classifies AI systems intended to be used as safety components in the management and operation of road traffic and the supply of water, gas, heating, and electricity as high risk. Rail and aviation traffic management systems fall under similar sector-specific safety regimes that regulators increasingly align with the AI Act.
How does NIS2 interact with sector safety regulators?
NIS2 sits alongside sector regulators like ERA, EASA, and EMSA. Cybersecurity and AI governance obligations under NIS2 are cumulative with existing safety certification. Most operators run an integrated assurance programme to avoid duplicate evidence across safety cases and cyber documentation.
What counts as an AI incident under NIS2?
NIS2 defines a significant incident as one that has caused or is capable of causing severe operational disruption or financial loss. This includes AI-specific incidents such as model drift causing wrong routing, adversarial attacks on perception systems, or catastrophic generative AI hallucinations in dispatch contexts. The 24-hour early-warning clock starts when the entity becomes aware of the incident.
Are driver monitoring and cabin cameras allowed under the EU AI Act?
AI systems inferring emotions in the workplace are prohibited under Article 5 of the EU AI Act, unless deployed for strictly medical or safety reasons. Fatigue detection can usually be defended as a safety measure but requires a documented justification, a GDPR lawful basis, data minimisation, and in most Member States, consultation with worker representatives.
How does Modulos help transportation operators?
Modulos models NIS2, CER, the EU AI Act, ISO/IEC 42001, and sector safety controls together. You inventory AI-enabled subsystems once, classify their risk, map the overlapping obligations, and run incident, training, and supplier workflows from the same place. Evidence is reusable, auditable, and board-ready.
See the governance graph on one of your subsystems
Talk to an expert
A demo walks through the four desks with a signalling or driver-monitoring use case, on the governance graph your evidence would live in.
Request a demo →Keep exploring on your own
The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on each desk's legal basis.