AI in Critical Infrastructure and Energy
AI deployed in power grids, water systems, telecommunications networks, nuclear facilities, and oil and gas operations operates in environments where failure can have catastrophic, irreversible consequences. The EU AI Act classifies AI systems managing critical infrastructure as high-risk, requiring conformity assessments, human oversight, and robustness testing. Cyber resilience obligations under the EU's Digital Operational Resilience Act (DORA) and Cyber Resilience Act (CRA) impose additional requirements on digital systems in critical sectors.
Key board-level questions
- 1.Are our AI systems managing critical operations classified and governed as high-risk under applicable law?
- 2.What fail-safes and human override mechanisms exist for AI systems controlling physical infrastructure?
- 3.How do we test whether AI systems hold up against deliberate attacks and manipulation before they go live?
- 4.Are third-party AI vendors in our infrastructure supply chain subject to the same security and resilience standards as our own systems?
Regulatory frameworks
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Digital Operational Resilience Act
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover technology risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
OWASP Top 10 for Large Language Model Applications
OWASP's Top 10 for LLM Applications lists the most critical security risks in applications built on large language models. The current 2026 edition, published in August 2026, puts prompt injection, sensitive information disclosure, and excessive agency at the top. Development and security teams use it to prioritize safeguards.
