Point of viewAI in telecom

Governing AI in a network that cannot go down: the operator's guide after the AI Act delay

The EU has pushed high-risk AI obligations back to December 2027, but transparency rules already apply and autonomous networks are arriving faster than the rulebook. Operators need governance that works at network speed, with graded autonomy and a stop button that really stops.

9 min read By · Point of view
2 Dec 2027
new application date for EU AI Act obligations on stand-alone high-risk systems, including critical digital infrastructure2

Key takeaways

  • The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) moved stand-alone high-risk obligations to 2 December 2027 and product-embedded ones to 2 August 2028, but Article 50 transparency duties have applied since 2 August 202612.
  • Draft Commission guidelines treat network AI as high-risk only where it is a safety component used by an entity designated critical under the CER Directive; network optimisation, load prediction and trouble-ticket AI are cited as examples outside the category3.
  • The bigger governance risk for operators is operational, not legal: a single misconfigured network element triggered an automated response that disabled a national mobile network for at least 12 hours in 202412.
  • Operators should govern AI by autonomy level, with identity, permissions, testing and a tested kill switch for every agent that can change the network, aligned to NIST AI RMF and ISO/IEC 42001.

Telecom operators are unusual AI adopters. Much of their AI will not decide who gets a loan or a job; it will decide how traffic is routed, which cell sleeps at night and whether a configuration change is pushed to thousands of nodes. The harm model is less about individual unfairness and more about systemic failure: an outage that blocks emergency calls, a mis-scaled core that drops a city, a customer-facing agent that tells millions of people the wrong thing at once.

Governance frameworks written for banks and HR departments only partly fit that risk. This article sets out where the regulation stands as of autumn 2026, and what a governance model built for networks, rather than borrowed from other industries, looks like.

Where the EU AI Act stands

The Commission proposed amendments in November 2025 after implementation was judged to be off track; a political agreement followed in spring 20261. The resulting Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July2. Its core effect is to move obligations for stand-alone high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027, and those for AI embedded in regulated products to 2 August 202812.

The delay is narrower than many assume. Transparency obligations under Article 50 kept their original date of 2 August 2026: systems that interact with people must disclose that they are AI, and synthetic content must be marked in machine-readable form, with a four-month grace period to 2 December 2026 for generative systems already on the market12. For operators running AI agents in care, sales and collections, that duty is live today. Penalties remain significant: up to EUR 35m or 7% of worldwide turnover for prohibited practices, and up to EUR 15m or 3% for most other breaches6.

Exhibit 1

What applies when: the EU AI Act timeline for operators after the Omnibus

Key obligations and application dates relevant to telecom operators

ObligationRelevance to operatorsApplies from
Article 50 transparency (AI interaction disclosure, content marking)Customer care bots, voice agents, marketing content2 August 2026
Machine-readable marking for generative systems already on the marketExisting GenAI content tools2 December 2026 (grace period)
Annex III stand-alone high-risk systemsSafety components of critical digital infrastructure; creditworthiness of natural persons2 December 2027
High-risk AI embedded in regulated products (Annex I)Limited direct relevance for most operators2 August 2028

Note: Sources: [1], [2], [4]. Classification of individual systems depends on final Commission guidelines, still in draft at the time of writing.

Source: K&L Gates (Cyber Law Watch), “EU Digital Omnibus on AI enters into force” (2026)

Is network AI high-risk?

Annex III lists AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as high-risk, alongside systems that evaluate the creditworthiness of natural persons4. The second matters for postpaid credit vetting; the first is where most network questions sit. The Commission's draft classification guidelines, published for consultation on 19 May 2026, name public electronic communications networks and services as critical digital infrastructure but say such AI should be considered high-risk only where it is used by an entity identified as critical under the CER Directive3. They cite trouble-ticket management, network optimisation and network-load prediction as examples that should not be considered to have a direct safety function3.

The guidelines are not final, and operators are also in scope of NIS2, which applies to providers of public electronic communications networks and services and which member states had to transpose by 17 October 202415. The practical conclusion is that much network AI may fall outside the AI Act's high-risk regime while still sitting squarely inside cyber-resilience and operational-resilience obligations.

Autonomy is the real governance variable

The industry already has a vocabulary for this. 3GPP's levels of autonomous network run from manual operation to Level 5, where the entire autonomy workflow is accomplished without human intervention; at Level 4, all execution, awareness, analysis and decision tasks are automated and intent handling is partly automated11. More than 70 telcos and ecosystem partners have signed TM Forum's Autonomous Networks Manifesto, committing to Level 4 in key domains by 2025–202710.

Autonomy raises the stakes of every change. The US regulator's report on a nationwide mobile outage in February 2024 is instructive, even though no AI was involved. A new network element was misconfigured during a routine maintenance window; three minutes after it went live, it triggered an automated response that shut down all network connections. The outage lasted at least twelve hours, affected more than 125 million devices, blocked more than 92 million voice calls and prevented more than 25,000 calls to emergency centres12. The FCC cited a lack of peer review, inadequate testing and insufficient safeguards to ensure approval of core-network changes12. Replace the engineer with an agent that can push changes at machine speed, and those controls become existential.

Only approved network changes that are developed pursuant to internal procedures and industry best practices should be loaded onto the production network. It should not be possible to load changes that fail to meet those criteria.
Federal Communications Commission, Public Safety and Homeland Security Bureau12

The frameworks to build on

  • NIST AI RMF. Voluntary, released in January 2023, with a Generative AI Profile added in July 2024; in April 2026 NIST released a concept note for a profile on trustworthy AI in critical infrastructure covering IT, operational technology and industrial control systems7.
  • ISO/IEC 42001. Specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and is certifiable by third parties8.
  • ETSI EN 304 223. Adopted in December 2025, it sets baseline cyber-security requirements for AI models and systems across 13 principles and requires technical measures where human oversight is relied on as a risk control9.
  • GSMA Responsible AI Maturity Roadmap. Launched in September 2024 as the first industry-wide roadmap, with nineteen mobile operators committed to using it at launch13.

Article 14 of the AI Act gives the design principle for high-risk systems: people overseeing them must be able to intervene or interrupt the system through a 'stop' button or a similar procedure, and must be alert to automation bias5. Operators should apply that principle to every agent with write access to the network, whether or not the law requires it.

Exhibit 2

AI governance is lagging AI deployment

Selected findings from a 2025 cross-industry breach study, % of organisations (%)

Note: IBM/Ponemon study of 600 organisations; bases differ by bar (first bar: organisations whose AI was compromised; second: breached organisations).

Source: IBM Newsroom, “IBM report: 13% of organizations reported breaches of AI models or applications, 97% of which reported lacking proper AI access controls” (2025)

Cross-industry evidence shows why this matters. In IBM's 2025 breach study, 13% of organisations reported breaches of AI models or applications, and 97% of those lacked proper AI access controls14. In McKinsey's 2026 AI trust research, only about a third of organisations reported maturity of three or higher in strategy, governance and agentic AI governance, and nearly two-thirds cited security and risk concerns as the top barrier to scaling agentic AI16. Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027, citing costs, unclear value or inadequate risk controls17.

For executives

What this means for your operator

  1. Inventory every AI system and agent, tagging each with its Annex III exposure, Article 50 transparency duty, NIS2 relevance and autonomy level.
  2. Treat Article 50 as live now: audit every customer-facing bot and voice agent for disclosure, content marking and clean human handoff.
  3. Gate any agent that can change network configuration behind the same peer review, lab testing and approval controls as human engineers, enforced technically rather than by policy.
  4. Build and drill kill switches and automatic rollback for agentic changes, and measure time-to-stop as a resilience KPI.
  5. Anchor the programme in NIST AI RMF and an ISO/IEC 42001 management system so one control set serves the AI Act, NIS2 and board assurance.
Put it to work

How DaasLabs can help

AI governance and autonomy maturity assessment

Take the maturity assessment

Supervised AI agents with identities, permissions and audit trails

Meet the digital workforce

Governed, auditable data foundation with lineage

See compliance & data lineage

Reference architecture for guarded agentic operations

Explore the framework

Sources

  1. 1
  2. 2
    EU Digital Omnibus on AI enters into force (opens in a new tab) K&L Gates (Cyber Law Watch), 31 July 2026
  3. 3
  4. 4
  5. 5
    AI Act, Article 14: Human oversight (opens in a new tab) European Commission AI Act Service Desk, 2024
  6. 6
    AI Act, Article 99: Penalties (opens in a new tab) European Commission AI Act Service Desk, 2024
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
    February 22, 2024 nationwide mobile network outage: report and findings (opens in a new tab) Federal Communications Commission, Public Safety and Homeland Security Bureau, 22 July 2024
  13. 13
  14. 14
  15. 15
    NIS2 Directive (opens in a new tab) European Commission, 2026
  16. 16
  17. 17

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Where this fits in the story

From connectivity provider to intelligent, AI-native operator

This piece is chapter 5 of 6: the workforce. Supervised AI agents doing routine work end to end, inside guardrails people set and audit.

  1. 01 The pressure 2 insights
  2. 02 The value chain 3 insights
  3. 03 The foundation 2 insights
  4. 04 The proof 2 insights
  5. 05 The workforce 3 insights
  6. 06 The journey Tools
Stay informed

Get new telecom insights in your inbox

New perspectives on AI, data and transformation in telecom — a few times a month. Browse all insights.

AI
AI Analyst

I'm the DaasLabs AI Analyst for the telecom demo platform. I can help with:

  • Revenue assurance & CDR reconciliation
  • Fraud: SIM swap, SIM box, IRSF and Wangiri
  • Churn, customer and network analytics
  • Executive briefings across the accelerators

Answers are generated from the demo data.