Research

The School carries out applied research with the purpose of developing economically, legally, and socially-sound regulation and policy, using a multidisciplinary approach.

The EU emissions trading system and support for aviation

The EU aviation climate action framework is entering a new phase in which delivery and implementation matter as much as the overall design of...

Authors
Steven  Truxal Marie Raude JJMP
Technical Report
Managing market tightness in the EU ETS on the path to net-zero : design options and trade-offs in price-based supply adjustments
Discover more
Policy Brief
Financing High-Speed rail
Discover more

Executive Education

We offer different types of training: Online, Residential, Blended and Tailor-made courses in all levels of knowledge.

Policy Events

A wide range of events for open discussion and knowledge exchange. In Florence, Brussels, worldwide and online.

More

Discover more initiatives, broader research, and featured reports.

Lights on Women

The Lights on Women initiative promotes, trains and advocates for women in energy, climate and sustainability, boosting their visibility, representation and careers.

Discover more
Topic of the Month - AI and electricity

The AI Act in the electricity sector

This is the fourth and last instalment of the Topic of the Month: AI and the EU Electricity System

Artificial intelligence (AI) can support the development of new tools to improve the functioning of the electricity system, increasing its efficiency and reliability. Regulation (EU) 2024/1689, known as the AI Act, was adopted as a horizontal legal framework applicable across multiple sectors, including energy. In this instalment, we investigate the relevance of the AI Act for the electricity sector. To do so, we first delve into the definition of AI systems and elucidate the AI Act’s risk-based approach. Second, we focus on the AI systems to be used as safety components in the electricity critical infrastructure. Third, we examine the Commission’s draft guidelines on the classification of high-risk AI systems, with practical examples. We close by referring to the relationship between the AI Act and the legislative proposal amending the Electricity Market Regulation.

The AI system definition and the risk-based approach

The AI Act lays down harmonised rules for placing on the market, putting into service, and using AI systems in the Union.[1] It establishes a dense and complex regulatory framework consisting of multiple layers of norms, ranging from binding and semi-binding rules to non-binding recommendations, guidelines and standards.

According to Article 3(1) of the AI Act:

‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.’

In July 2025, the European Commission adopted guidelines to clarify the main elements of this definition.[2] Interestingly, when the guidelines dive deep into the type of outputs that can influence physical or virtual environments, and in particular ‘predictions’, they confirmed the relevance of the AI Act for the electricity sector by mentioning – as an example – AI systems that are ‘designed to estimate energy consumption by analysing data from smart meters, weather forecasts and behavioural patterns of consumers’.[3]

A defining feature of the AI Act is its risk-based approach. Under this approach, different degrees of safeguards applied to AI systems are tailored according to the intensity and scope of the risks they can generate.[4] As a result, the AI Act prohibits certain unacceptable AI practices (Chapter II), establishes requirements for high-risk systems and obligations on the operators responsible for them (Chapter III), and imposes transparency obligations for providers and deployers of certain AI systems (Chapter IV).

The Commission’s guidelines on the definition of AI systems provide two fundamental caveats. First, such a definition should not be applied mechanically: each system must be assessed based on its specific characteristics. For this reason, the guidelines do not provide an exhaustive list of all potential AI systems. Second, only certain AI systems are subject to regulatory obligations and oversight under the AI Act because of its risk-based approach. In this regard, the guidelines explicitly state that ‘[t]he vast majority of systems, even if they qualify as AI systems within the meaning of Article 3(1) AI Act, will not be subject to any regulatory requirements under the AI Act’.[5]

High-risk AI systems: scope and implications

Regarding the regulation of the electricity sector in general, the crucial question is whether a technology or innovation system qualifies as a ‘high-risk AI system’. For high-risk AI systems, in fact, the AI Act establishes rules on (i) requirements related, for instance, to risk management, data governance, technical documentation, and record keeping; (ii) obligations on providers concerning, for instance, quality management system and cooperation with competent authorities; (iii) notification duties; and (iv) specific procedures related to standards, conformity assessment, certificates, registration.[6]

Under Article 6(2) and Annex III (point (2)) of the AI Act, AI systems are classified as ‘high risk’ when they are intended to be used as safety components in the management and operation of critical infrastructures, including electricity infrastructure. By definition, ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.[7]

Stakeholders and researchers have been investigating the scope and implications of the safety components’ definition, often claiming that it is excessively narrow, with the risk of leaving some promising AI use cases, such as demand-side management, exempt from the obligations and requirements for high-risk AI systems. Uncertainty on the scope of high-risk AI systems in the electricity sector[8] – which is thus left to a case-by-case interpretation – is not the only challenging regulatory aspect.[9] Even for those systems falling within that category, it is important to highlight that the AI Act only includes the abovementioned (ex ante) disclosure obligations, and not also (ex post) liability rules. After the withdrawal of the proposal for a Directive on adapting non-contractual civil liability rules to AI, the compromise solution was to amend the Product Liability Directive, which regulates the no-fault-based liability regime for manufacturers of defective products, and now explicitly includes software and AI within its scope. However, for harms not covered by the Product Liability Directive – such as damages caused to the electricity network due to a malfunction of the AI system, which was supposed to improve the grid functioning – claimants shall rely on the safeguards established by the (not-harmonised) national liability frameworks.

Practical examples of high-risk AI systems in the electricity critical infrastructure

Almost two years after the adoption of the AI Act, the European Commission drafted guidelines on the classification of high-risk AI systems under Article 6 of the AI Act, providing practical examples to illustrate how such systems should be assessed across different areas and use cases.[10]

These guidelines rely on the definition of ‘critical infrastructure’ contained in the Critical Entities Resilience (CER) Directive (EU) 2022/2557 and the related Delegated Regulation (EU) 2023/2450. The latter identifies a non-exhaustive list of essential services in the electricity sector, which includes supply of electricity, operation, maintenance and development of an electricity distribution or transmission system, generation of electricity, nominated electricity market operator service, demand response, aggregation and energy storage. On this basis, the Commission has clarified in the guidelines that an AI system used in the management and operation of supply of electricity should be considered high-risk if intended to be used by an electricity entity (i.e. electricity supply undertaking, distribution or transmission operator, electricity producer, nominated electricity market operator or electricity market participant) that has been identified by a Member State as a critical entity under the CER Directive.

Examples on the high-risk category include:

  • AI systems used for the surveillance and protection of a physical perimeter (such as camera systems, radar systems and drone control systems used to directly protect the physical integrity of the infrastructure); and
  • AI systems used for the detection of anomalies in data patterns when operating electricity grids for the purpose of monitoring and supporting decision-making in relation to critical functions (such as power load distribution, grid stability, or shutdown procedures).

By contrast, many commonly discussed energy-sector AI systems are not considered high-risk because they lack a direct safety function or constitute mere decision-supporting tools. They are summarised in the table below.

The AI Act and the Commission’s proposal amending the Electricity Market Regulation

On 17 July 2026, the European Commission published a proposal for amending the EU Electricity Market Regulation (EMR), following the recently published Strategic Roadmap for Digitalisation and Artificial Intelligence (AI) in the Energy Sector. Among other things, the legislative proposal introduces rules to foster the digitalisation of electricity grids in the EU and facilitate the exchange and reuse of grid data. In particular, the Commission proposes a long provision under Article 18a(5), obliging TSOs and DSOs, through a coordinated arrangement jointly facilitated by ENTSO-E and the EU DSO Entity, to establish a voluntary electricity grid data exchange framework. The framework should enable ‘the lawful, secure and controlled reuse of data for research and innovation public-interest purposes of developing, testing, integration and deployment of advanced technologies for grid operation and optimisation’, including, in practice, AI systems. It is worth pointing out that the AI Act does not directly restrict or grant access to energy data as such, because it is inherently framed as a product-safety legislation, which does not govern data re-use, nor does it establish specific rights for researchers, operators, or regulators to obtain energy data for the purpose of training AI models. At the same time, the AI Act includes obligations for AI systems – especially those categorised as high-risk – that would generally help ensure a safe, trustworthy, and transparent regulatory environment. In this sense, the provisions on data exchange framework introduced by the legal proposal operate upstream of the AI Act: they contribute to creating the trusted data environment needed for the development, testing and validation of innovative digital and AI-based solutions for grid operation and optimisation, while leaving the applicable obligations for AI systems themselves to the AI Act.[11]

Acknowledgements

The Florence School of Regulation gratefully acknowledges the financial support of the European Commission (DG ENER) for conducting the research that led to this blogpost. Views expressed in this blogpost reflect the opinion of individual author(s) and do not necessarily reflect the views of the European Commission.

[1] AI Act, Art. 1(2)(a).

[2] Commission Guidelines are not legally binding but relevant for any judicial interpretation of the AI Act provisions.

[3] Commission Guidelines, point (55).

[4] AI Act, Recital (26).

[5] Commission Guidelines, point (63).

[6] See, respectively, Section 2, 3, 4, and 5 of the AI Act, Chapter III.

[7] AI Act, Art. 3(14).

[8] European Commission. Joint Research Centre and others, How AI Is Shaping EU Electricity Grids (Publications Office of the European Union 2025) 6 <https://doi.org/10.2760/7152988>.

[9] This instalment was written before Regulation (EU) 2026/1744 (‘Digital Omnibus on AI’) entered into force on 27 July 2026. The amendments made to the AI Act – including the new definition of ‘safety components’ – are therefore not discussed.

[10] Stakeholders’ consultation closed on 23 July 2026. The final guidelines are expected by the end of 2026.

[11] See also Recital (68) of the AI Act, acknowledging that ‘the facilitation of data sharing between businesses and with government in the public interest will be instrumental to provide trustful, accountable and non-discriminatory access to high-quality data for the training, validation and testing of AI systems’.

Don’t miss any update on this topic

Sign up for free and access the latest publications and insights

Sign up
Back to top