{
  "node_id": "eu-ai-act-high-risk-critical-infrastructure",
  "title": "EU AI Act - High-Risk AI in Critical Infrastructure Safety Components (Annex III Point 2)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 2 designates as high-risk AI systems intended to be used as safety components in the management and operation of critical infrastructure, covering: (2a) AI used as safety components in road traffic management and in the operation of road traffic, including traffic management centres and autonomous and connected vehicle AI systems; (2b) AI used as safety components in the supply of water, gas, heating, or electricity - including AI systems controlling distribution networks, flow management, or grid balancing; the critical infrastructure category is defined by the concept of 'safety component' - a component whose failure would put at risk the health or safety of persons or property; this requirement aligns with the NIS2 Directive (Directive 2022/2555) definition of critical infrastructure operators and creates a direct regulatory interface between EU AI Act Annex III Point 2 and NIS2 essential service obligations; AI systems used in critical infrastructure that are not safety components - for example AI used in administrative functions or non-safety optimisation - do not qualify as high-risk under Annex III Point 2; the high-risk classification triggers full Chapter III compliance including Article 15 robustness and cybersecurity requirements that overlap with NIS2 Article 21 cybersecurity risk management obligations, creating a dual compliance framework for critical infrastructure AI operators.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-critical-infrastructure.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-9-risk-management-system",
    "eu-ai-act-article-14-human-oversight",
    "eu-ai-act-article-15-robustness",
    "eu-ai-act-article-26-deployer-obligations",
    "eu-ai-act-annex-iii-high-risk-ai-systems",
    "eu-nis2-essential-important-entities-obligations"
  ],
  "primary_citations_count": 5
}