AI in Critical Infrastructure and Energy
AI deployed in power grids, water systems, telecommunications networks, nuclear facilities, and oil and gas operations operates in environments where failure can have catastrophic, irreversible consequences. The EU AI Act classifies AI systems managing critical infrastructure as high-risk, requiring conformity assessments, human oversight, and robustness testing. Cyber resilience obligations under DORA and the CRA impose additional requirements on digital systems in critical sectors.
Key board-level questions
- 1.Are our AI systems managing critical operations classified and governed as high-risk under applicable law?
- 2.What fail-safes and human override mechanisms exist for AI systems controlling physical infrastructure?
- 3.How do we test AI systems for adversarial robustness and cybersecurity vulnerabilities before operational deployment?
- 4.Are third-party AI vendors in our infrastructure supply chain subject to the same security and resilience standards as our own systems?
Regulatory frameworks
EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)
This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to establish workforce literacy measures. It also describes enforceable prohibitions on unacceptable-risk practices. Organizations must cease prohibited practices and demonstrate adequate staff competency by that date.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Digital Operational Resilience Act
DORA, Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover ICT risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
NIST Artificial Intelligence Risk Management Framework Playbook
The voluntary NIST AI RMF Playbook provides implementation guidance, suggested actions, and example outputs across AI use cases. It supports GOVERN, MAP, MEASURE, and MANAGE throughout the system lifecycle.
OWASP Top 10 for Large Language Model Applications
OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.
