Skip to content
EU AI Regulation DecodedKnowledge Platform

Critical infrastructure: is it high-risk under the EU AI Act?

AI used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating and electricity.

Annex III domain 2 of 8Route Article 6(2)Status Under editorial review

Classification test

Falling in this domain is necessary but not sufficient. Under Article 6(2) the system is high-risk only if it also performs one of the specific functions the domain's text lists. Only safety components are in scope — general operational AI without a safety-critical function may fall outside.

Example systems

If it is high-risk, these obligations apply

All high-risk (Annex III) obligations → · How to classify under Article 6 →

Legal source

Annex III AIA

FAQ

Is critical infrastructure AI high-risk under the EU AI Act?
It is high-risk under Article 6(2) if it matches the Annex III critical infrastructure domain and performs a listed function. Only safety components are in scope — general operational AI without a safety-critical function may fall outside.

What must I do if it is high-risk?
Run a risk-management system, govern your data, keep the Annex IV technical file, evidence accuracy/robustness/cybersecurity, complete conformity assessment and register in the EU database.

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.