Skip to main content
Praxikon
Back to the explorer
ExampleGuidancev1.0.0

Security monitoring by a SaaS company: cybersecurity alone is not a safety component

A software company supplies a SaaS platform that monitors network traffic at an operator of critical digital infrastructure and reports anomalous patterns to that customer's security team. Its developers see that use at such an operator may fall under point 2 of Annex III and wonder whether their own product therefore becomes a high-risk AI system.

The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map

Address and citation

This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.

Identifier
praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur
Payload hash (sha256)
8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115

Citation line

Praxikon, "Security monitoring by a SaaS company: cybersecurity alone is not a safety component", praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115
Version
1.0.0
Legal time (effective_at)
19 May 2026
Knowledge time (known_at)
8 August 2026
Closed on
Not closed
Topics
examples

Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

What this object links to

Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.

The obligation this hangs off

1 of 1 shown

The object belongs to this obligation. The source line it hangs off sits there.

  1. Source

    Official fact on this object, with its locator.

    • Draft guidelines on the classification of high-risk AI systems

      Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)

      praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object is about

1 of 1 shown

The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.

  1. Source

    Official fact on this object, with its locator.

    • Draft guidelines on the classification of high-risk AI systems

      Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)

      praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object states

Official fact

Attributable to a named primary source, with a locator. Where they differ, the official source prevails.

  • The Commission draft guidelines of 19 May 2026 state that point 2 of Annex III lists AI systems intended to be used as safety components in the management and operation of, among other things, critical digital infrastructure, and that Recital 55 draws a clear distinction between a safety component and a cybersecurity component. To fall within point 2, an AI system must not be used solely for cybersecurity purposes; without a direct safety role it cannot be a safety component in critical infrastructure and therefore cannot be classified as high-risk under Article 6(2). As examples of systems used solely for cybersecurity and thus falling outside point 2, they list an AI honeypot that identifies and neutralises cyber threats in real time, technology that actively engages with potential attackers to learn new attack patterns, a system supporting the detection of unauthorised access, and a system that detects suspicious email addresses and identifies stolen data. They add that an AI system is classified as a safety component in critical infrastructure only where it is used by an entity identified as a critical entity by a Member State under the CER Directive, and that this interpretation does not require that status to be disclosed to a third-party provider. The document is a consultation version: non-binding and not yet final.

    • Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source

Our interpretation

Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.

  • We read this passage as a line drawn function by function rather than customer by customer: the fact that your client operates critical digital infrastructure does not by itself turn your monitoring product into a safety component. What we cannot settle from the text is where mere flagging ends and a safety function begins, because the same guidelines also count monitoring and detecting situations that may directly lead to physical harm among the safety functions. The open question is therefore whether your SaaS platform stands apart from the systems that drive physical control, or in practice becomes part of them. So record, per product function, what the system performs and what it expressly leaves to the operator, because that distinction carries your entire classification and is hard to reconstruct after the fact.

    • Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source

When this applies

No condition recorded on this object.

When this does not apply

No exception recorded on this object.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Security monitoring by a SaaS company: cybersecurity alone is not a safety component",
praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-05-19T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115,
https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur
(https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aexample%3Aexample-securitymonitoring-kritieke-digitale-infrastructuur&effective_at=2026-05-19&known_at=2026-08-08&lang=en, accessed 2026-08-25)

Short form

praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0 (sha256 8dd8de28)

BibTeX

@misc{praxikon-eu-ai-act-example-example-securitymonitoring-kritieke-digitale-infrastructuur-1-0-0,
  author       = {{Praxikon}},
  title        = {Security monitoring by a SaaS company: cybersecurity alone is not a safety component},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-05-19T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115},
  url          = {https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur},
  urldate      = {2026-08-25},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0",
    "type": "dataset",
    "title": "Security monitoring by a SaaS company: cybersecurity alone is not a safety component",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur",
    "URL": "https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          25
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-05-19T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aexample%3Aexample-securitymonitoring-kritieke-digitale-infrastructuur&effective_at=2026-05-19&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

For agents and integrations

This page and the machine output come from the same object and the same two time axes.