C‑DRONE
Aerial view of Paris and the Eiffel Tower at sunset

C-DRONE GUIDE · 30 AUGUST 2026

AI and Professional Drones: What the EU AI Act Changes for Inspection Reports

More and more drone inspection reports — electrical substations, drinking-water networks, engineering structures, industrial roofing — now rely on an automatic detection module that pre-flags anomalies before an expert reviews them. Since 2 August 2026, most of the EU's Artificial Intelligence Act has entered into application, and a technical manager or a public buyer at a local authority is entitled to ask whether the tool their contractor uses is covered, and on what basis. The answer comes in three parts : what already applies, what an adjustment text adopted this summer postponed, and what, either way, remains the real safeguard — the quality of the human check that follows detection.

Published on 30 August 2026, reviewed on 11 September 2026 — regulations in force as of September 2026.

Since 2 August 2026, most of the Regulation applies — but not its headline obligation

The Regulation (EU) 2024/1689 of 13 June 2024, known as the AI Act, has been entering into application in successive waves since it came into force on 1 August 2024 : a ban on certain practices from February 2025, obligations for providers of general-purpose AI models since August 2025, then, on 2 August 2026, most of the rest of the text — governance, general rules, and, in principle, the obligations specific to Annex III high-risk systems.

It is precisely that last layer that summer 2026 news changed. Regulation (EU) 2026/1744, known as the "Digital Omnibus", adopted by the European Parliament on 16 June 2026 and definitively approved by the Council on 29 June 2026, in force since 27 July 2026, split the high-risk-system timeline into two new deadlines : 2 December 2027 for Annex III systems (which, as we will see, automatic detection applied to critical infrastructure falls under), and 2 August 2028 for Annex I systems built into products already covered by sector-specific rules (machinery, medical devices…). This postponement, however, does not touch the Article 50 transparency obligations, the rules already in force for general-purpose AI model providers, or the penalty regime — up to €35 million or 7 % of worldwide turnover for the most serious breaches, €15 million or 3 % for others.

For a drone contractor as much as for its client — a company, a local authority, a network operator —, the first practical lesson can be put in one sentence : the AI Act has applied since this summer, but its most demanding layer for an anomaly-detection tool has been postponed, not scrapped. Confusing the two leads either to excessive worry or to a neglect that will prove costly once the 2027 deadline arrives.

Is a detection tool run on drone imagery a high-risk system?

Annex III, point 2 of the Regulation classifies as high-risk any AI "intended to be used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity". That scope directly overlaps several services we detail elsewhere on this site : automatic hot-spot detection on an electrical line or substation, leak-spotting on a drinking-water network, or automatic crack classification on a road bridge or engineering structure.

The criterion that tips a tool into this category is not the mere presence of AI, but its role as a "safety component" : a system that on its own triggers, or that a safety-affecting decision directly depends on — automatic decommissioning, a binding priority order for an emergency intervention — is unambiguously covered. A tool that only pre-flags an anomaly within a batch of images, leaving an expert to confirm it before any operational decision, sits in a grey zone the Regulation addresses explicitly, which is the subject of the filter covered in the next section. Either way, this classification only becomes binding from 2 December 2027, owing to the postponement mentioned above — but working it out today avoids having to do so in a rush.

The Article 6(3) filter: why human vigilance, not the law, makes the real difference

The Regulation itself provides a safety valve : Article 6(3) excludes from the "high-risk" classification a system which, although prima facie caught by Annex III, is confined to one of four tasks — performing a narrow procedural task, improving the result of a previously completed human activity, detecting deviations from a prior decision-making pattern without replacing human assessment, or carrying out a preparatory task. That is exactly the description of a tool that pre-flags cracks or hot spots for a remote pilot or engineer who then validates the report. The exception, however, never applies where the system profiles natural persons, which is not normally the case for detection run on concrete, metal or a pipe.

The point requiring vigilance is not just textual, but practical : a study by J. Laux and H. Ruschemeier, forthcoming in the European Journal of Risk Regulation, devoted precisely to the legal implications of the automation bias the Regulation itself names, shows that the human-oversight duty the text imposes runs into a documented phenomenon : human operators' tendency to over-endorse an AI output rather than question it, which empties human review of its substance unless the protocol actively organises against it (see the study on Google Scholar). In other words : a remote pilot who signs off without genuinely reopening each flagged image is not performing human review within the meaning of the exemption, only a rubber-stamp — and that is precisely what the Article 6(3) exemption does not cover.

This caution is all the more warranted because the tools themselves remain imperfect : a systematic review of 123 studies by S. Talebi, S. Wu, A. Sen and co-authors, published in 2025 in the International Journal of Construction Management, on machine-learning-based automatic infrastructure defect detection — roads, bridges, sewer networks —, highlights the lack of standardised datasets and the persistent difficulty of automatically assessing a defect's severity rather than its mere presence (see the study on Google Scholar). A contractor who documents its review protocol — which image gets reopened, on what criterion, with what audit trail — secures both the report's value and its client's position under the Regulation.

What already applies: transparency, third-party models, and how a contractor should organise

Postponing the "high-risk" obligations does not clear everything : Article 50, in force since 2 August 2026 and unaffected by the Digital Omnibus, requires disclosing that content has been generated or modified by AI — relevant as soon as a report includes an automatically drafted summary — unless that content has undergone human review and a natural or legal person assumes editorial responsibility for its publication, which comes down to exactly the same principle as the previous section : it is the reality of the review, not the mere presence of AI, that determines the applicable regime. In addition, where the detection or drafting-assistance software relies on a third-party general-purpose AI model, the obligations on that model's provider — technical documentation, copyright compliance, transparency on training data — have been in force since August 2025, independently of the final system's own status.

In practice, a client — an industrial company, a social housing landlord, a local authority, a network operator — benefits from asking its drone contractor three questions before any AI-assisted campaign : exactly what role the algorithm plays in the decision chain, what the human-review protocol is and how it is logged, and where the model in use comes from. These points fit naturally into the same contractual framework we detail for drone data ownership and security, and complement, without replacing, the NIS2 Directive framework for essential entities. To properly interpret AI's share in a deliverable, our guide to reading a thermography report already sets out what a method note should contain.

The cost of putting this in order remains, in 2026, marginal against the service itself : documenting a review protocol and a tool's origin is typically a few hours of methodological write-up, folded into the final report rather than billed separately, with no notable effect on the lead time of an automatic defect-detection mission. The stake is therefore not a short-term financial one : it is the ability to show, once the 2027 deadline arrives or should a dispute arise before then, that a human genuinely looked at what the machine flagged. Request a quote stating whether you want an AI-assisted detection component included, and the level of review traceability you expect.

Frequently asked questions

Does a drone inspection report using AI already have to meet the AI Act's "high-risk" obligations?

Not yet, in the vast majority of cases. Regulation (EU) 2024/1689 did enter into application for most of its provisions on 2 August 2026, but the so-called "Digital Omnibus" adjustment text, in force since 27 July 2026, postponed the obligations specific to Annex III high-risk systems (which a detection tool applied to critical infrastructure would fall under) to 2 December 2027. What already applies, though, are the Article 50 transparency obligations and, for the provider of the underlying AI model, the obligations on general-purpose AI model providers in force since August 2025.

How do I know whether my drone contractor's detection tool is a high-risk system under the AI Act?

Ask a single question : does the tool only pre-flag an anomaly that a certified remote pilot or expert then examines before any decision is made, or does it trigger a safety-affecting action on its own — closing a structure, cutting off a line ? In the first case, the Article 6(3) exemption (narrow procedural task, improving the result of a previously completed human activity) very likely applies, provided the human review is genuine and documented, not a rubber-stamp. In the second, the tool falls squarely under Annex III and will eventually need to be brought into compliance.

Does the Regulation's postponement change anything in practice for a local authority ordering AI-assisted drone inspections?

In the short term, no : no "high-risk" compliance obligation applies before December 2027 (or August 2028 for certain systems built into products already regulated). But planning ahead remains in a public buyer's interest : requiring, from today, a description in the tender of exactly what role the AI plays, proof of a documented human review, and disclosure of the underlying model's origin avoids having to rebuild everything in a hurry once the deadline arrives, and already secures the report's evidential value should a dispute arise.

Request a free quote

Also worth reading