Security monitoring by a SaaS company: cybersecurity alone is not a safety component
A software company supplies a SaaS platform that monitors network traffic at an operator of critical digital infrastructure and reports anomalous patterns to that customer's security team. Its developers see that use at such an operator may fall under point 2 of Annex III and wonder whether their own product therefore becomes a high-risk AI system.
The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map
Address and citation
This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.
- Identifier
praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur- Payload hash (sha256)
8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115
Citation line
Praxikon, "Security monitoring by a SaaS company: cybersecurity alone is not a safety component", praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115- Version
- 1.0.0
- Legal time (effective_at)
- 19 May 2026
- Knowledge time (known_at)
- 8 August 2026
- Closed on
- Not closed
- Topics
- examples
Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
What this object links to
Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.
The obligation this hangs off
1 of 1 shown
The object belongs to this obligation. The source line it hangs off sits there.
Source
Official fact on this object, with its locator.
Draft guidelines on the classification of high-risk AI systems
Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)
praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines
Open official source
Via
No condition or exception recorded on this object.
Consequence
ObligationAnnex III: high-risk AI
praxikon:eu:ai-act:obligation:annex-iii-high-risk
What this object is about
1 of 1 shown
The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.
Source
Official fact on this object, with its locator.
Draft guidelines on the classification of high-risk AI systems
Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)
praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines
Open official source
Via
No condition or exception recorded on this object.
Consequence
praxikon:eu:ai-act:actor:provider
What this object states
Official fact
Attributable to a named primary source, with a locator. Where they differ, the official source prevails.
The Commission draft guidelines of 19 May 2026 state that point 2 of Annex III lists AI systems intended to be used as safety components in the management and operation of, among other things, critical digital infrastructure, and that Recital 55 draws a clear distinction between a safety component and a cybersecurity component. To fall within point 2, an AI system must not be used solely for cybersecurity purposes; without a direct safety role it cannot be a safety component in critical infrastructure and therefore cannot be classified as high-risk under Article 6(2). As examples of systems used solely for cybersecurity and thus falling outside point 2, they list an AI honeypot that identifies and neutralises cyber threats in real time, technology that actively engages with potential attackers to learn new attack patterns, a system supporting the detection of unauthorised access, and a system that detects suspicious email addresses and identifies stolen data. They add that an AI system is classified as a safety component in critical infrastructure only where it is used by an entity identified as a critical entity by a Member State under the CER Directive, and that this interpretation does not require that status to be disclosed to a third-party provider. The document is a consultation version: non-binding and not yet final.
- Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source
Our interpretation
Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.
We read this passage as a line drawn function by function rather than customer by customer: the fact that your client operates critical digital infrastructure does not by itself turn your monitoring product into a safety component. What we cannot settle from the text is where mere flagging ends and a safety function begins, because the same guidelines also count monitoring and detecting situations that may directly lead to physical harm among the safety functions. The open question is therefore whether your SaaS platform stands apart from the systems that drive physical control, or in practice becomes part of them. So record, per product function, what the system performs and what it expressly leaves to the operator, because that distinction carries your entire classification and is hard to reconstruct after the fact.
- Locator: Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source
When this applies
No condition recorded on this object.
When this does not apply
No exception recorded on this object.
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Security monitoring by a SaaS company: cybersecurity alone is not a safety component", praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-05-19T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z, sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115, https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur (https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aexample%3Aexample-securitymonitoring-kritieke-digitale-infrastructuur&effective_at=2026-05-19&known_at=2026-08-08&lang=en, accessed 2026-08-25)
Short form
praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0 (sha256 8dd8de28)
BibTeX
@misc{praxikon-eu-ai-act-example-example-securitymonitoring-kritieke-digitale-infrastructuur-1-0-0,
author = {{Praxikon}},
title = {Security monitoring by a SaaS company: cybersecurity alone is not a safety component},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
note = {effective_at 2026-05-19T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115},
url = {https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur},
urldate = {2026-08-25},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur@1.0.0",
"type": "dataset",
"title": "Security monitoring by a SaaS company: cybersecurity alone is not a safety component",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur",
"URL": "https://www.praxikon.com/en/verkenner/example/example-securitymonitoring-kritieke-digitale-infrastructuur",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
8
]
]
},
"accessed": {
"date-parts": [
[
2026,
8,
25
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-05-19T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aexample%3Aexample-securitymonitoring-kritieke-digitale-infrastructuur&effective_at=2026-05-19&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
For agents and integrations
This page and the machine output come from the same object and the same two time axes.