Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries · Utilities

Annex III duties for safety-component grid AI apply from 2 December 2027

A utility's AI answers to four authorities at once

Cybersecurity, market conduct, data protection, and AI safety each run on their own legal basis, their own document requests, and their own clock.

What you need to know

  1. Four desks can examine the same operational AI. The NIS2 cybersecurity authority, the energy regulator under REMIT and the network codes, the data protection authority, and the AI Act market surveillance authority your member state designates.
  2. The sector sits at NIS2's highest tier. Energy, drinking water, and waste water are Annex I sectors of high criticality; whether an operator counts as essential or important turns on entity type and size. The CER Directive adds physical-resilience duties for designated critical entities, and a significant incident starts a 24-hour early-warning clock.
  3. The energy regulator is already watching your models. Since the 2024 REMIT revision, algorithmic trading owes systems, risk controls, and notification to the national authority. A model that itself sets bid parameters with limited human intervention sits inside this mandate today, with no AI Act needed.
  4. Safety-component grid AI is heading for high risk. Annex III Part 2 reaches AI intended as a safety component in the supply of water, gas, heating, and electricity; forecasting and optimisation tools with no safety role stay outside. The duties apply from 2 December 2027.
  5. One record backs every answer. The AI inventory across IT and OT, data lineage, oversight logs, vendor records, and incident history feed the Article 21 measures, the REMIT file, and, for high-risk systems, the AI Act technical documentation once they live in one governance graph.
Owners: CISO, Head of Grid Operations, Head of Market Operations, DPORead the framework docs →
01

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and an outage model with no AI Act gate still answers to desks one and two.

Social scoring of customers for tariff access or service decisions

Article 5(1)(c) prohibits social scoring that leads to detrimental treatment unrelated to the data source or disproportionate to the behaviour. Ungoverned vulnerability scoring that gates supply can reach this threshold.

Prohibited (Art. 5)

AI safety components for electricity, gas, or water supply

Explicitly high risk under Annex III Part 2. Full conformity, documentation, monitoring, and human-oversight duties.

High-risk (Annex III)

Grid forecasting and balancing models

High risk under Annex III Part 2 when the output acts as a safety component. Even in advisory mode, drift or data poisoning has market and grid consequences.

High-risk (Annex III)

Smart metering vulnerability scoring

High risk under Annex III point 5 when it evaluates access to, or continued supply of, essential services. GDPR DPIAs and consumer protection law run alongside.

High-risk (Annex III)

Outage prediction and predictive maintenance

No gate while advisory, though change control and operator explainability still apply. Becomes Annex III Part 2 high risk if outputs act as a safety component.

No AI Act gate

Customer service generative AI assistants

Article 50: customers must be told they are interacting with AI. Chapter V GPAI duties sit on the model provider.

Transparency (Art. 50)
02

Who can knock, and with what

The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.

01NIS2Your cybersecurity authority

The national cybersecurity authority: the BSI, ANSSI, ACN, or their peer in your member state, with the national CSIRT taking your incident notifications.

Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2). Annex I lists energy, including electricity, gas, district heating and cooling, and hydrogen, alongside drinking water and waste water as sectors of high criticality, so most operators are essential entities. Article 21 sets the risk-management measures, supply chain security included, and Article 23 sets the reporting regime. The CER Directive runs in parallel for physical resilience: designated critical entities in the same sectors owe risk assessments and resilience plans.

What they can ask for

  • The Article 21 risk-management measures and their approval by the management body under Article 20
  • Supply chain security assessments covering SCADA vendors, cloud forecasting services, and AI suppliers
  • Incident notifications on the Article 23 timeline
  • Risk assessments and the resilience plan, where you are a designated critical entity under the CER Directive
24h
early warning after becoming aware of a significant incident
72h
incident notification with an initial assessment
1 month
final report
02EnergyThe energy regulator

The national regulatory authority for energy: the Bundesnetzagentur, the CRE, ARERA, or their peer, with ACER monitoring wholesale market data at EU level.

Market conduct and network operation. REMIT prohibits insider trading and market manipulation in wholesale energy markets, and ACER screens trading data across the EU; since the 2024 revision, market participants trading algorithmically owe systems, risk controls, and notification to the national authority. The same regulator enforces network codes on data exchange and balancing and oversees the smart-meter rollout. A model that itself sets bid parameters with limited human intervention sits inside this mandate today, with no AI Act needed.

What they can ask for

  • Order and trade records behind algorithmic and AI-assisted bidding, under REMIT
  • Notification and risk-control evidence for algorithmic trading under the revised REMIT
  • Data-exchange and balancing conduct under the network codes
  • Smart-meter rollout plans and progress reporting
Ongoing
supervision runs continuously on reported trade and market data, with no filing calendar to prepare for
03GDPRThe data protection authority

Your supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.

Smart-meter consumption data is personal data. Half-hourly readings reveal occupancy, routines, and appliance use, which is why profiling household consumption for tariff segmentation or vulnerability scoring calls for a data protection impact assessment under Article 35. Solely automated decisions with legal or similarly significant effects, disconnection included, engage Article 22. Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher.

What they can ask for

  • Data protection impact assessments under Article 35 for smart-meter profiling
  • Records of processing under Article 30
  • The lawful basis and retention schedule for consumption data
  • The human review path behind automated disconnection and tariff decisions
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
04AI ActThe market surveillance authority

The market surveillance authority your member state designates under the AI Act. For most utilities this is a new desk rather than an existing supervisor holding a second mandate.

High-risk AI under Regulation (EU) 2024/1689. Annex III Part 2 names AI used as a safety component in the management and operation of critical digital infrastructure and in the supply of water, gas, heating, and electricity. Grid forecasting, balancing, and outage-management models sit inside the clause when their outputs act as safety components. Under the Digital Omnibus, now in force, these duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • Data governance and training data documentation
  • Automatically generated logs and human oversight records
  • The conformity assessment behind the CE marking
2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness
EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189CCPA ADMTNYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

The utilities stack in the framework library is the EU AI Act, NIS2, the GDPR, and ISO/IEC 42001, mapped onto shared controls. A NIS2 Article 21 control is reusable in the AI Act technical file where a system is high risk, one incident intake can route both Article 23 and Article 73 reports on their separate triggers and clocks, and every desk above reads from that shared record.

454 / 958controls in the library serve more than one framework
49controls shared by at least two of these four frameworks

Framework library v1.0.32

03

Frequently asked questions

Are utilities automatically essential entities under NIS2?

Energy (electricity, oil, gas, district heating and cooling, hydrogen), drinking water, and waste water are sectors of high criticality under NIS2 Annex I. Large entities in these sectors are essential entities and medium-sized ones are important entities. Member states can also bring smaller operators into scope where they are sole or critical providers.

Is grid forecasting AI high risk under the EU AI Act?

Yes, when used as a safety component. Annex III Part 2 classifies AI systems used as safety components in the management and operation of critical digital infrastructure and the supply of water, gas, heating, and electricity as high risk. Most grid-facing forecasting and balancing models fall inside that definition.

How does NIS2 interact with ISO/IEC 27001 and 42001?

ISO/IEC 27001 and 42001 are the most practical way to demonstrate the Article 21 risk-management measures. They are not a legal substitute for NIS2 compliance, but they give operators a certifiable baseline, and regulators increasingly treat them as evidence of good-faith implementation, especially for AI-specific governance.

What about smart metering and customer analytics?

Smart-meter data and derived analytics bring the GDPR, consumer protection, and energy-poverty rules into scope. Inferring household vulnerability or tariff suitability can engage special-category data and the automated-decision rules in Article 22. These use cases need DPIAs, explainability, and human review paths alongside cybersecurity controls.

Does NIS2 apply to cloud and SaaS AI vendors used by utilities?

Yes, indirectly. Article 21 treats supply chain security as a mandatory risk-management topic, so the utility is responsible for assessing, contracting, and monitoring its ICT suppliers, AI providers included. Some cloud providers may additionally be designated critical ICT third-party providers under DORA or under national NIS2 schemes.

How does Modulos help utilities run AI governance?

Modulos gives utilities a single governance graph where NIS2, the CER Directive, the EU AI Act, ISO/IEC 42001, and national energy rules share controls and evidence. You inventory AI-enabled OT and IT systems, classify their risk, run resilience and incident workflows, and produce the management body evidence Article 20 requires, without duplicating work across CISO, AI, and market-operations teams.

See the governance graph on one of your operational models

Talk to an expert

A demo walks through the four desks with a forecasting or smart-metering use case, on the governance graph your evidence would live in.

Request a demo

Keep exploring on your own

The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on each desk's legal basis.