Telecom operators are unusual AI adopters. Much of their AI will not decide who gets a loan or a job; it will decide how traffic is routed, which cell sleeps at night and whether a configuration change is pushed to thousands of nodes. The harm model is less about individual unfairness and more about systemic failure: an outage that blocks emergency calls, a mis-scaled core that drops a city, a customer-facing agent that tells millions of people the wrong thing at once.
Governance frameworks written for banks and HR departments only partly fit that risk. This article sets out where the regulation stands as of autumn 2026, and what a governance model built for networks, rather than borrowed from other industries, looks like.
Where the EU AI Act stands
The Commission proposed amendments in November 2025 after implementation was judged to be off track; a political agreement followed in spring 20261. The resulting Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July2. Its core effect is to move obligations for stand-alone high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027, and those for AI embedded in regulated products to 2 August 202812.
The delay is narrower than many assume. Transparency obligations under Article 50 kept their original date of 2 August 2026: systems that interact with people must disclose that they are AI, and synthetic content must be marked in machine-readable form, with a four-month grace period to 2 December 2026 for generative systems already on the market12. For operators running AI agents in care, sales and collections, that duty is live today. Penalties remain significant: up to EUR 35m or 7% of worldwide turnover for prohibited practices, and up to EUR 15m or 3% for most other breaches6.
What applies when: the EU AI Act timeline for operators after the Omnibus
Key obligations and application dates relevant to telecom operators
| Obligation | Relevance to operators | Applies from |
|---|---|---|
| Article 50 transparency (AI interaction disclosure, content marking) | Customer care bots, voice agents, marketing content | 2 August 2026 |
| Machine-readable marking for generative systems already on the market | Existing GenAI content tools | 2 December 2026 (grace period) |
| Annex III stand-alone high-risk systems | Safety components of critical digital infrastructure; creditworthiness of natural persons | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I) | Limited direct relevance for most operators | 2 August 2028 |
Note: Sources: [1], [2], [4]. Classification of individual systems depends on final Commission guidelines, still in draft at the time of writing.
Source: K&L Gates (Cyber Law Watch), “EU Digital Omnibus on AI enters into force” (2026)
Is network AI high-risk?
Annex III lists AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as high-risk, alongside systems that evaluate the creditworthiness of natural persons4. The second matters for postpaid credit vetting; the first is where most network questions sit. The Commission's draft classification guidelines, published for consultation on 19 May 2026, name public electronic communications networks and services as critical digital infrastructure but say such AI should be considered high-risk only where it is used by an entity identified as critical under the CER Directive3. They cite trouble-ticket management, network optimisation and network-load prediction as examples that should not be considered to have a direct safety function3.
The guidelines are not final, and operators are also in scope of NIS2, which applies to providers of public electronic communications networks and services and which member states had to transpose by 17 October 202415. The practical conclusion is that much network AI may fall outside the AI Act's high-risk regime while still sitting squarely inside cyber-resilience and operational-resilience obligations.
Autonomy is the real governance variable
The industry already has a vocabulary for this. 3GPP's levels of autonomous network run from manual operation to Level 5, where the entire autonomy workflow is accomplished without human intervention; at Level 4, all execution, awareness, analysis and decision tasks are automated and intent handling is partly automated11. More than 70 telcos and ecosystem partners have signed TM Forum's Autonomous Networks Manifesto, committing to Level 4 in key domains by 2025–202710.
Autonomy raises the stakes of every change. The US regulator's report on a nationwide mobile outage in February 2024 is instructive, even though no AI was involved. A new network element was misconfigured during a routine maintenance window; three minutes after it went live, it triggered an automated response that shut down all network connections. The outage lasted at least twelve hours, affected more than 125 million devices, blocked more than 92 million voice calls and prevented more than 25,000 calls to emergency centres12. The FCC cited a lack of peer review, inadequate testing and insufficient safeguards to ensure approval of core-network changes12. Replace the engineer with an agent that can push changes at machine speed, and those controls become existential.
Only approved network changes that are developed pursuant to internal procedures and industry best practices should be loaded onto the production network. It should not be possible to load changes that fail to meet those criteria.
The frameworks to build on
- NIST AI RMF. Voluntary, released in January 2023, with a Generative AI Profile added in July 2024; in April 2026 NIST released a concept note for a profile on trustworthy AI in critical infrastructure covering IT, operational technology and industrial control systems7.
- ISO/IEC 42001. Specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and is certifiable by third parties8.
- ETSI EN 304 223. Adopted in December 2025, it sets baseline cyber-security requirements for AI models and systems across 13 principles and requires technical measures where human oversight is relied on as a risk control9.
- GSMA Responsible AI Maturity Roadmap. Launched in September 2024 as the first industry-wide roadmap, with nineteen mobile operators committed to using it at launch13.
Article 14 of the AI Act gives the design principle for high-risk systems: people overseeing them must be able to intervene or interrupt the system through a 'stop' button or a similar procedure, and must be alert to automation bias5. Operators should apply that principle to every agent with write access to the network, whether or not the law requires it.
AI governance is lagging AI deployment
Selected findings from a 2025 cross-industry breach study, % of organisations (%)
Note: IBM/Ponemon study of 600 organisations; bases differ by bar (first bar: organisations whose AI was compromised; second: breached organisations).
Cross-industry evidence shows why this matters. In IBM's 2025 breach study, 13% of organisations reported breaches of AI models or applications, and 97% of those lacked proper AI access controls14. In McKinsey's 2026 AI trust research, only about a third of organisations reported maturity of three or higher in strategy, governance and agentic AI governance, and nearly two-thirds cited security and risk concerns as the top barrier to scaling agentic AI16. Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027, citing costs, unclear value or inadequate risk controls17.