23. July 2026 By Stephen Lorenzen
Future-proof AI in the energy sector – what the EU AI Act now requires and what matters afterwards
The EU AI Act was actually due to come into full effect in August 2026. However, with the Digital Omnibus, the EU has postponed the obligations for high-risk systems: to December 2027 for autonomous systems under Annex III – which also include safety components of critical infrastructure such as the electricity supply – and to August 2028 for AI embedded in products. Anyone who interprets this as a green light is drawing the wrong conclusion. This is because the substantive requirements remain unchanged: risk management, technical documentation, logging and human oversight are still on the cards – just later. And certain obligations have long since come into force, such as demonstrating AI competence within the organisation. For energy suppliers, the AI Act is therefore not a one-off deadline, but an ongoing task. This article shows what AI architectures look like that meet regulatory requirements and will still be viable in two years’ time.
Why a deadline is the wrong target
Many energy suppliers treat the AI Act like a traditional compliance project: stock-taking, classification, documentation, approval – done. This logic falls short – the postponement of the deadline demonstrates precisely this: deadlines change, but the task remains. Furthermore, AI systems are not static applications. Models are retrained, data sources change, and providers update foundation models. Each of these changes can trigger a reassessment – from a business, technical and regulatory perspective.
In practical terms, this happens quickly: if a forecasting model for grid management is retrained, questions regarding the duty to provide evidence arise immediately. Who assesses the change? Where is it documented which model version was used when a decision was made? And what is presented during the audit? Organisations without a well-established response to this experience every model change as a special case.
The crucial question is therefore not: ‘How do I become compliant by the deadline?’ but rather: ‘How do I build AI systems that remain compliant in the long term – without every model change triggering a new project?’
Future-proof AI architectures for OT and IT landscapes
Regulatory requirements can be documented retrospectively – or built into the architecture from the outset. The second approach is the more cost-effective one. Three design principles have proven their worth:
Model versioning as a standard feature. Every production model requires a complete history: training data, parameters, test results, approvals. This is the only way to demonstrate which model made which decision, when and at what version – a core requirement for high-risk systems.
Explainability-by-design rather than post-hoc explanation. Explainability cannot be retrofitted if the model was designed as a black box. Those who consider early on which decisions must be explainable to operational management, auditors or regulatory authorities will select model classes and interfaces differently.
Audit logging as an architectural feature. Logging is not a secondary obligation under the AI Act, but an operational prerequisite. In established OT landscapes, this means integrating control systems, historians and AI components in such a way that events are consistently traceable without compromising real-time capability.
Not all of this is mandatory for every system. However, those who establish these principles as standard need not worry when faced with the classification question – high-risk or not. The architecture supports both answers.
Continuous AI Governance as an operational model
Once implemented, continuous operation begins – and this requires an operational model, not a project organisation. This includes clearly defined roles (subject matter experts for each AI system, a governance body with decision-making authority, and interfaces with data protection and information security) and recurring processes: model monitoring, a regulated approach to model changes – including triggers for re-evaluations – and an incident process for AI system malfunctions.
In practice, maturity levels range from ad hoc, project-driven documentation to a governance framework that functions as an active operational process with monitoring and clear escalation pathways. Honestly assessing one’s position on this scale is the first step – it reveals whether the organisation can keep pace with continuous operation or whether every model change turns into a fire-fighting exercise. Technical support for this can be provided by platforms such as the adesso AI Hub, which creates transparency regarding the use of AI within the organisation and provides governance structures, including audit trails, in line with the EU AI Regulation.
From concept to implementation
For energy suppliers and network operators, a three-stage approach has proven successful: first, honestly assess the maturity level – for example, across the dimensions of drivers, enablement, operationalisation and governance; then prioritise architectural and governance gaps; and finally, integrate the implementation into the existing IT and OT landscape, rather than setting up parallel structures.
The fact that this approach does not have to be a multi-year project is demonstrated by Energieversorgung Mittelrhein (evm): working together with adesso, a viable AI strategy – complete with a roadmap, backlog and initial flagship projects – was developed within six months, based on a company-wide assessment of its own maturity level.
adesso supports energy suppliers on this journey with sector-specific expertise in generation, grid operations and sales: from the AI Maturity Check through the development of an AI strategy with a use-case roadmap to architecture consultancy and integration into established SAP and OT landscapes. The aim is to treat governance not as a hindrance, but as a prerequisite for operating AI in a sustainable and scalable manner.
Conclusion
The Digital Omnibus has bought time, but has not waived any requirements. For the energy sector, the AI Act is not a sprint towards a deadline, but a transition to a new normal. Those who invest now in future-proof architectures and establish governance as an operational model rather than a project will not only meet regulatory requirements – they will lay the foundations for scaling AI in grid control, maintenance and customer processes with confidence. When done right, compliance is a prerequisite for innovation, not its nemesis.
Find out how adesso supports energy suppliers with AI strategy, architecture and governance on our energy sector page.