Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries / Utilities

A utility's AI answers to four authorities at once

Cybersecurity, market conduct, data protection, and AI safety each run on their own legal basis, their own document requests, and their own clock.

01NIS2

Your cybersecurity authority

24h early warning after becoming aware of a significant incident

02Energy

The energy regulator

Ongoing supervision runs continuously on reported trade and market data, not on a filing calendar

03GDPR

The data protection authority

72h personal data breach notification under Article 33

04AI Act

The market surveillance authority

2 Dec 2027 Annex III obligations apply

The desk

Who can knock, and with what

Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.

Desk 01NIS2

Your cybersecurity authority

The national cybersecurity authority: the BSI, ANSSI, ACN, or their peer in your member state, with the national CSIRT taking your incident notifications.

Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2). Annex I lists energy, including electricity, gas, district heating and cooling, and hydrogen, alongside drinking water and waste water as sectors of high criticality, so most operators are essential entities. Article 21 sets the risk-management measures, supply chain security included, and Article 23 sets the reporting regime. The CER Directive runs in parallel for physical resilience: designated critical entities in the same sectors owe risk assessments and resilience plans.

What they can ask for

  • The Article 21 risk-management measures and their approval by the management body under Article 20
  • Supply chain security assessments covering SCADA vendors, cloud forecasting services, and AI suppliers
  • Incident notifications on the Article 23 timeline
  • Risk assessments and the resilience plan, where you are a designated critical entity under the CER Directive

The clock

24h
early warning after becoming aware of a significant incident
72h
incident notification with an initial assessment
1 month
final report
Desk 02Energy

The energy regulator

The national regulatory authority for energy: the Bundesnetzagentur, the CRE, ARERA, or their peer, with ACER monitoring wholesale market data at EU level.

Market conduct and network operation. REMIT prohibits insider trading and market manipulation in wholesale energy markets, and ACER screens trading data across the EU; since the 2024 revision, market participants trading algorithmically owe systems, risk controls, and notification to the national authority. The same regulator enforces network codes on data exchange and balancing and oversees the smart-meter rollout. A forecasting model that moves a bidding position sits inside this mandate today, with no AI Act needed.

What they can ask for

  • Order and trade records behind algorithmic and AI-assisted bidding, under REMIT
  • Notification and risk-control evidence for algorithmic trading under the revised REMIT
  • Data-exchange and balancing conduct under the network codes
  • Smart-meter rollout plans and progress reporting

The clock

Ongoing
supervision runs continuously on reported trade and market data, not on a filing calendar
Desk 03GDPR

The data protection authority

Your supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.

Smart-meter consumption data is personal data. Half-hourly readings reveal occupancy, routines, and appliance use, which is why profiling household consumption for tariff segmentation or vulnerability scoring calls for a data protection impact assessment under Article 35. Solely automated decisions with legal or similarly significant effects, disconnection included, engage Article 22. Article 83(5) caps fines at 4% of worldwide annual turnover.

What they can ask for

  • Data protection impact assessments under Article 35 for smart-meter profiling
  • Records of processing under Article 30
  • The lawful basis and retention schedule for consumption data
  • The human review path behind automated disconnection and tariff decisions

The clock

72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act

The market surveillance authority

The market surveillance authority your member state designates under the AI Act. For most utilities this is a new desk rather than an existing supervisor holding a second mandate.

High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of critical digital infrastructure and in the supply of water, gas, heating, and electricity. Grid forecasting, balancing, and outage-management models sit inside the clause when their outputs act as safety components. Under the adopted Digital Omnibus, these duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • Data governance and training data documentation
  • Automatically generated logs and human oversight records
  • The conformity assessment behind the CE marking

The clock

2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness

Every desk reads from the same record

Desk one asks about supply chain security, desk two about bidding conduct, desk three about profiling, desk four about safety components. Behind all four sit the same artefacts: the AI inventory across IT and OT, data lineage, oversight logs, vendor records, and incident history. Modulos keeps that evidence as one governance graph, where a control written once earns credit across every framework it satisfies. A NIS2 Article 21 control feeds the AI Act technical file, and a single incident process serves Article 23 and Article 73. The authorities do not coordinate their requests; the record is ready for whichever desk asks first.

01 NIS202 Energy03 GDPR04 AI ActOne evidence record

Dates that matter

2 Aug 2026

General application of the EU AI Act and the start of GPAI enforcement

2 Dec 2027

Annex III duties for safety components in water, gas, heating, and electricity supply, per the adopted Digital Omnibus

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and an outage model with no AI Act gate still answers to desks one and two.

Social scoring of customers for tariff access or service decisions

Article 5(1)(c) prohibits social scoring that leads to detrimental treatment unrelated to the data source or disproportionate to the behaviour. Ungoverned vulnerability scoring that gates supply can reach this threshold.

Prohibited (Art. 5)

AI safety components for electricity, gas, or water supply

Explicitly high risk under Annex III Part 2. Full conformity, documentation, monitoring, and human-oversight duties.

High-risk (Annex III)

Grid forecasting and balancing models

High risk under Annex III Part 2 when the output acts as a safety component. Even in advisory mode, drift or data poisoning has market and grid consequences.

High-risk (Annex III)

Smart metering vulnerability scoring

High risk under Annex III point 5 when it evaluates access to, or continued supply of, essential services. GDPR DPIAs and consumer protection law run alongside.

High-risk (Annex III)

Outage prediction and predictive maintenance

No gate while advisory, though change control and operator explainability still apply. Becomes Annex III Part 2 high risk if outputs act as a safety component.

No AI Act gate

Customer service generative AI assistants

Article 50: customers must be told they are interacting with AI. Chapter V GPAI duties sit on the model provider.

Transparency (Art. 50)

Related regulations

Go deeper on the regimes that apply to this sector:

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Frequently asked questions

Are utilities automatically essential entities under NIS2?

Energy (electricity, oil, gas, district heating and cooling, hydrogen), drinking water, and waste water are sectors of high criticality under NIS2 Annex I. Large entities in these sectors are essential entities and medium-sized ones are important entities. Member states can also bring smaller operators into scope where they are sole or critical providers.

Is grid forecasting AI high risk under the EU AI Act?

Yes, when used as a safety component. Annex III Part 2 classifies AI systems used as safety components in the management and operation of critical digital infrastructure and the supply of water, gas, heating, and electricity as high risk. Most grid-facing forecasting and balancing models fall inside that definition.

How does NIS2 interact with ISO/IEC 27001 and 42001?

ISO/IEC 27001 and 42001 are the most practical way to demonstrate the Article 21 risk-management measures. They are not a legal substitute for NIS2 compliance, but they give operators a certifiable baseline, and regulators increasingly treat them as evidence of good-faith implementation, especially for AI-specific governance.

What about smart metering and customer analytics?

Smart-meter data and derived analytics bring the GDPR, consumer protection, and energy-poverty rules into scope. Inferring household vulnerability or tariff suitability can engage special-category data and the automated-decision rules in Article 22. These use cases need DPIAs, explainability, and human review paths alongside cybersecurity controls.

Does NIS2 apply to cloud and SaaS AI vendors used by utilities?

Yes, indirectly. Article 21 treats supply chain security as a mandatory risk-management topic, so the utility is responsible for assessing, contracting, and monitoring its ICT suppliers, AI providers included. Some cloud providers may additionally be designated critical ICT third-party providers under DORA or under national NIS2 schemes.

How does Modulos help utilities run AI governance?

Modulos gives utilities a single governance graph where NIS2, the CER Directive, the EU AI Act, ISO/IEC 42001, and national energy rules share controls and evidence. You inventory AI-enabled OT and IT systems, classify their risk, run resilience and incident workflows, and produce the management body evidence Article 20 requires, without duplicating work across CISO, AI, and market-operations teams.

See the governance graph on one of your operational models

A demo walks through the four desks with a forecasting or smart-metering use case. The quiz classifies your role and risk exposure in about three minutes.