The classic trap
Recital 55 draws a subtle line that critical infrastructure operators underestimate: an AI system does not need to be necessary for the system to function to fall into high-risk, it only needs to protect physical integrity or safety. As a result, AI modules considered as accessories (water pressure monitoring, fire detection in datacenters, AI for road traffic decision support) fall under Annex III even if the operator classified them as optimisation tools. Conversely, a purely cyber AI module (EDR, augmented SIEM) is NOT a safety component within the meaning of the AI Act, even if it protects the infrastructure. The CNPD remains competent for the personal data aspects, and the EU AI Office will supervise interpretation consistency at EU level.
The 'safety component' qualification test in 4 questions
- Does the system directly protect the physical integrity of the infrastructure or the health of persons? If yes, high-risk candidate.
- Is it necessary for the operational functioning of the infrastructure? If yes, it is NOT a safety component within the meaning of recital 55 (but may fall under another category).
- Is its sole purpose cybersecurity? If yes, explicit exclusion, outside Annex III point 2.
- Is the infrastructure listed in the Annex to Directive (EU) 2022/2557 or does it cover water / gas / electricity / heating / road traffic? If yes, scope confirmed.
The operational trap: a single product may contain multiple AI bricks, some high-risk and others not. The mapping must be done component by component, not by overall product. Luxembourg operators concerned (POST, Creos, SUDenergie, Encevo, LuxConnect, EBRC, road administrations) must document this qualification before the application date of high-risk obligations (August 2026).
How Luxgap automates this risk
Our Luxgap Critical Infrastructure AI Classifier definitively closes the high-risk qualification question for Luxembourg critical infrastructure operators. The tool automatically scans your application estate (SCADA, CMMS, Schneider EcoStruxure supervision, Siemens MindSphere, AVEVA System Platform, Azure IoT Hub) and detects each embedded AI brick or ML model, then applies the recital 55 qualification test brick by brick with opposable traceability.
- Automatically inventories AI components present in your industrial systems via native OPC-UA, Modbus TCP connectors and APIs of leading SCADA and CMMS vendors.
- Classifies each component against the recital 55 grid (safety component vs operational vs pure cybersecurity) with drafted justification and citation of the EU text.
- Generates the compliance matrix per component with applicable obligations (risk management article 9, data article 10, technical documentation article 11, logging article 12, transparency article 13, human oversight article 14, robustness article 15).
- Detects gaps between the qualification declared by your AI supplier and the actual qualification given the real use in your infrastructure.
- Alerts in real time as soon as a software update introduces a new unclassified AI brick into your supervision scope.
- Produces a timestamped and cryptographically signed PDF qualification dossier, opposable to the EU AI Office and the Luxembourg AI market surveillance authority during an inspection.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your industrial scope. Request a personalised quote and our teams will prepare a demonstration on your real estate, with a free blank audit within 48h to map your critical AI components before any engagement.