Telecom operators deploy AI at a scale matched only by big tech — across network operations, customer experience, fraud detection, and 5G orchestration. When an AI system fails in telecommunications, millions of subscribers lose connectivity and critical national infrastructure degrades. This benchmark — measured against ISO 42001 — reveals where the telecom sector stands.
Four major regulatory and operational forces are converging on telecom simultaneously. Telecommunications networks are classified as critical digital infrastructure under the EU AI Act — placing every AI system involved in network management under the Act's most demanding obligations.
—
Days Until EU AI Act
Critical infrastructure AI · Aug 2, 2026
LIVE
DORA
Fully applicable since Jan 2025
—
KSA PDPL
Full enforcement · Sep 2025
PUBLISHED
BEREC AI Guidelines
AI in telecoms guidance · 2024
01 — EXECUTIVE SUMMARY
The Telecom AI Governance Gap
Telecommunications organisations are, on average, 39% ready for ISO 42001 certification — placing them in the lower-middle tier. This belies a dangerous paradox: the industry is one of the most aggressive AI adopters, deploying machine learning across network operations, customer experience, fraud prevention, and 5G orchestration at a scale matched only by big tech — yet it governs that AI with frameworks designed for an era of static network configurations.
The EU AI Act classifies AI used in the "management and operation of critical digital infrastructure" as high-risk (Annex III, §2). Telecommunications networks are unambiguously critical digital infrastructure. 5G standalone networks introduce AI at every layer — RAN intelligent controllers making sub-millisecond decisions where human oversight is architecturally impossible. Operators hold behavioural data on 50–150 million individuals, creating privacy and fairness risks that dwarf most other sectors.
The gap isn't operational discipline — telecom operators run 24/7 NOCs with rigorous change management. The gap is extending that discipline to the AI systems that increasingly run those networks. When a network configuration change requires a change advisory board review, but an AI model update that fundamentally alters network behaviour requires nothing, the governance framework has a critical blind spot.
€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
Annex III §2
Critical Infrastructure
Telecom networks = high-risk AI
150M+
Subscribers Per Operator
Scale of AI impact per decision
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations.
Approach
What It Is
Strengths
Limitations
Internal AI Policies
Self-defined governance frameworks
Flexible, quick to implement, tailored
No external validation, not recognized by regulators
EU AI Act Compliance
Meeting Regulation 2024/1689
Mandatory in EU, critical infrastructure AI obligations
Jurisdiction-specific, not certifiable, reactive
NIST AI RMF 1.0
Voluntary US framework Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001
Voluntary, no certification, US-centric
BEREC AI Guidelines
AI in telecoms guidance (2024) Source: BEREC, 2024
Technical specs, not governance frameworks. Don't cover bias, fairness, or lifecycle governance.
ISO/IEC 42001:2023
International standard for AI Management Systems Source: ISO/IEC 42001:2023
Certifiable. Full lifecycle. Compatible with ISO 27001/9001. Satisfies EU AI Act QMS requirement. Covers network AI, customer AI, and vendor AI in one framework.
New (27 months). Telecom-specific guidance still emerging.
03 — WHY ISO 42001
The Case for ISO 42001
For telecom operators seeking to extend their NOC discipline to AI governance while meeting critical infrastructure obligations under the EU AI Act, ISO 42001 is the strongest available option.
Critical Infrastructure Compliance
The EU AI Act classifies telecom network AI as high-risk critical infrastructure. ISO 42001 certification directly satisfies the quality management system requirement (Art. 17) and provides documented evidence of risk management (Art. 9), human oversight (Art. 14), and transparency (Art. 13).
NOC Discipline → AI Governance
Network operations culture — 24/7 monitoring, change advisory boards, incident escalation, ITIL processes — maps directly to ISO 42001 requirements. The governance infrastructure exists. ISO 42001 extends it to cover AI-specific risks, lifecycle, and accountability.
Enterprise AI Credibility
GCC operators positioning as enterprise AI service providers (e& enterprise, stc SCAI) need demonstrable AI governance. ISO 42001 certification is proof that the operator governs AI to an international standard — essential for winning enterprise and smart city contracts.
What ISO 42001 Does Not Cover
Network technical standards. ISO 42001 governs AI management, not network engineering. 3GPP, O-RAN, and ITU-T standards govern network architecture and interoperability. ISO 42001 complements these by adding AI governance to the management layer.
Spectrum regulation. Spectrum management is governed by national regulators (TRA, CITC, Ofcom). ISO 42001 covers governance of AI systems used in spectrum management, not spectrum allocation itself.
Our position: For telecom operators, ISO 42001 bridges the gap between network operations discipline and AI governance. The NOC culture of monitoring, escalation, and change control is the strongest operational foundation of any sector — the gap is extending it to AI.
The Benchmark
Telecommunications averages 39% readiness. The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How telecom operators score across each of the 7 mandatory ISO 42001 management system clauses. Click any clause for detailed analysis, gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and telecom-specific compliance infrastructure patterns.
When a network config change needs CAB review but an AI model update that alters network behaviour needs nothing — governance has a critical blind spot.
05 — ANNEX A CONTROLS
Control Maturity by Domain
Each domain scored on a 1–5 maturity scale. Third-party management at 1.3/5.0 reflects the critical gap: network AI vendors (Ericsson, Nokia, Huawei) embed AI that operators cannot see, assess, or govern.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and telecom-specific control implementation analysis.
RAN Intelligent Controllers make decisions in milliseconds — faster than any human oversight loop. Governance must be built into the architecture.
06 — CRITICAL GAPS
Top 5 Gaps in Telecommunications
The most significant AI governance gaps in telecom — ranked by severity, with ISO 42001 clause references and remediation timelines.
The first telecom operator to achieve ISO 42001 demonstrates that critical infrastructure AI can be governed — not just operated.
07 — REGULATORY LANDSCAPE
Telecom AI Regulations
Every regulation affecting AI governance in telecommunications — including critical infrastructure obligations, consumer protection, and data monetisation rules.
Regulation
Jurisdiction
Status
Penalties
Impact on Telecom
ISO 42001 Alignment
EU AI Act
EU/EEA
High-risk: Aug 2026
€35M / 7%
Critical infrastructure AI (Annex III §2). Network management AI = high-risk. Chatbot transparency (Art. 50).
Cl.5-10 · A.3-A.13
GDPR
EU/EEA
In force
€20M / 4%
Subscriber data in AI. Purpose limitation, automated decisions (Art. 22), DPIAs. Data monetisation governance.
A.4 · A.10 · A.5
EECC / BEREC
EU/EEA
In force / 2024
NRA enforcement
Quality of service, net neutrality. AI-driven traffic management must comply. BEREC AI guidelines.
Cl.8 · A.5 · A.11
DORA
EU/EEA
Live since Jan 2025
€10M / 5%
ICT third-party risk. Telecom as critical ICT provider faces direct oversight.
Cl.8 · A.9 · A.13
TRA/TDRA
UAE
Active
Regulatory action
UAE telecom regulator. Quality of service, consumer protection, data governance expectations.
Cl.4 · Cl.8 · A.5
CITC
Saudi Arabia
Active
Regulatory action
Saudi Communications, Space & Technology Commission. AI governance expectations tightening.
Cl.4 · Cl.5 · A.5
KSA PDPL
Saudi Arabia
Full: Sep 2025
SAR 5M
Subscriber data in AI. Data localisation. Purpose limitation for AI processing.
A.4 · A.9 · A.10
UAE Data Protection
UAE
In force
AED 5M
Subscriber data processing in AI systems.
A.4 · A.10
NIST AI RMF
USA
Voluntary
No direct penalties
Relevant for operators with US operations. EO 14110 rescinded Jan 20, 2025.
Cl.6 · Cl.9
The regulatory multiplier: Telecom operators face regulation from telecom regulators (TRA, CITC, BEREC), data protection authorities (GDPR, PDPL), AI-specific regulation (EU AI Act), and financial oversight (DORA). ISO 42001 provides a single governance framework addressing the overlapping requirements of all these regimes simultaneously.
08 — METHODOLOGY
How This Benchmark Was Built
Scores derived from ISO 42001 clause mapping against telecom practices, adjusted for NOC operational maturity, network AI vendor dependency, 5G/edge AI proliferation, and consumer data scale.
Data Sources
› EU AI Act (Reg. 2024/1689) — Annex III §2 critical infrastructure
› BEREC Guidelines on AI in Telecoms (2024)
› Deloitte State of AI in Enterprise 2026 (3,235 leaders)
› OECD AI Policy Observatory (80+ jurisdictions)
› O-RAN Alliance AI/ML specifications
› ISO Survey of Management System Certifications (2019–2024)
Important Caveats
› NOC operational discipline is a genuine advantage — infrastructure exists
› Network AI vendor dependency is the unique structural challenge
› 5G/edge AI creates governance challenges no framework has fully addressed
› GCC operators face dual pressure: national digital backbone + commercial competition
› Certification typically requires 70–75% readiness to engage
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates
Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.
He is a transformation leader with over 20 years of experience across North America, Europe, and the GCC. He holds an AI Strategy and Leadership certification from MIT and is the founder of Digital North Associates, an AI governance and transformation firm.
Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology