Grid dispatch, water treatment, traffic control, rail signalling, air traffic operations and city-scale platforms are no longer piloting AI, they are running on it. In 2025 and 2026 the regulators of physical systems caught up: the EU fixed a hard high-risk deadline for critical-infrastructure AI, Korea put energy, water and transport under statutory high-impact duties, US grid authorities began writing mandatory rules for AI-scale loads, and autonomous transport moved from trial permits to commercial exemptions. AxiLayer AI and AxiSentinel™ give operators across the UAE and GCC, the European Union, the UK, North America and Asia-Pacific continuous, independent evidence that the AI now touching their control loops is still behaving as designed.
Infrastructure regulators spent a decade treating AI as an efficiency programme. Between late 2025 and mid-2026 they reclassified it as a safety component, in statute, in reliability standards and in permit conditions. Five developments define the new baseline.
AI has moved from dashboards into control loops. A mispriced loan is financial and reversible; a mis-dispatched feeder, a mistimed signal phase or a wrong coagulant dose is physical, immediate and sometimes irreversible. Yet most infrastructure operators cannot today produce an inventory of which models actually influence physical actuation, let alone evidence that each one is still inside its safety envelope. Every regime on this page, Annex III, Korea's high-impact duties, NERC's new standards, the ADS regulations, converges on exactly that evidence.
A single dispatch, traffic or treatment model deployed by a multinational operator can be simultaneously an Annex III safety component in the EU, a high-impact system under Korea's AI Framework Act, part of a SOCI-regulated asset in Australia and inside the perimeter of NERC's new computational-load standards in the US, while the entity running it answers to NIS2, the CER Directive and a national cyber agency. Each regime wants different evidence in a different format. This is the coverage map.
The Gulf is not merely regulating AI in infrastructure, it is building the world's largest sovereign AI-infrastructure programme while standing up the region's first AI trust certifications, and it expects suppliers to arrive with evidence.
The EU now regulates infrastructure AI from four directions at once: AI-specific classification, cyber resilience of the entity, physical resilience of the asset, and product security of every device with digital elements. The four regimes interlock by design.
Federal AI-specific policy softened in 2025, the sector regulators did not. Grid, pipeline, water and transport authorities all tightened through 2025 to 26, and the grid regulator now writes rules for AI's own electricity demand.
The UK regulates AI in infrastructure through cyber resilience law, transport statute and grid policy rather than an AI act, and its cyber agency has been the bluntest in the world about what AI does to critical-infrastructure risk.
Asia-Pacific hosts both the strictest AI-in-infrastructure statute in force anywhere and the most mature OT security regimes, a combination that makes per-market evidence packs unavoidable for regional operators.
Autonomy went from national experiments to global rulebooks in eighteen months, and every one of the new instruments demands the same thing: a safety case backed by continuous in-service monitoring.
Each use case below sits at a different distance from physical actuation, and that distance determines which regime bites, Annex III point 2 for safety components, NIS2 and SOCI for the entity, sector directives for the asset, and transport-specific instruments for anything that moves. AxiSentinel is configured per use case and per jurisdiction rather than shipped as one fixed pipeline.
Infrastructure AI cannot be assured from someone else's cloud. AxiSentinel's AXI-Node agent deploys inside your own environment, including fully air-gapped and OT-isolated networks, and produces the evidence every regime on this page now asks for: what is running, whether it is inside its envelope, and who signed off.
A continuously maintained register of every model and agent that reads from or writes to control systems, the first artefact Annex III classification, Korea's impact assessments and SOCI reviews all require.
Control-adjacent models monitored against their approved operating envelope, with drift and distribution-shift detection, and the practical answer to the EU's undefined "substantial modification" threshold for continuously retrained systems.
Documented, time-stamped proof that operator-in-the-loop review is real rather than rubber-stamped, the specific expectation in Korea's high-impact duties, Annex III Article 14 and every control-room deployment.
Evidence that fallback modes, manual override and disconnection paths exist, are tested and have been exercised, the difference between claiming a fail-safe and proving one.
Evidence collection and transfer through the .axibatch format for OT-isolated and air-gapped networks, no cloud dependency, no standing connection into the control network, consistent with the December 2025 OT-AI principles.
Detection of anomalous, spoofed or poisoned inputs to forecasting and control models, the attack class ENISA documented against AI supply chains in 2025.
Time-ordered incident artefacts sized for NIS2's 24-hour early warning and 72-hour notification, SOCI reporting windows and TSA's CISA-reporting directives.
One monitoring record, many formats: the same evidence base feeds an Annex III technical file, a NERC audit, a SOCI vulnerability assessment and a Korean impact assessment without re-instrumenting.
Continuous in-service monitoring aligned with ISO/PAS 8800's AI safety lifecycle and the UNECE ADS GTR, the evidence layer a robotaxi, rail or maritime autonomy safety case now has to cite.
Observability and guardrail monitoring for copilots and agents in SOCs and control rooms, hallucination, prompt-injection and scope-escape detection before an assistant's suggestion becomes an operator's action.
Tamper-evident, time-ordered records for regulators, insurers and boards, verifiable independently of AxiLayer AI, and durable across the multi-year timescales infrastructure regulation runs on.
Evidence mapped per market, EU Annex III and NIS2, US sector directives, UK CAF, Korea's K-Act, GCC frameworks, so one deployment serves every supervisor an operator answers to.
Utilities and transport operators buy slowly and stay for decades. The AI now running their physical systems is regulated by safety statute rather than fashion, the budgets sit inside regulated cost bases, and the deployment constraint, no cloud dependency inside the control network, excludes most of the competitive field by architecture. This is a segment where the moat is the deployment model.
An infrastructure AI review maps every model and agent that touches your physical operations against each regime that governs it, classification, evidence expectation, supervisor, deadline and gap, and shows what continuous monitoring looks like inside your own environment, including the networks that never touch the internet.