DNA Advisory · AI Governance Benchmark

Telecommunications
AI Governance Readiness

Telecom operators deploy AI at a scale matched only by big tech — across network operations, customer experience, fraud detection, and 5G orchestration. When an AI system fails in telecommunications, millions of subscribers lose connectivity and critical national infrastructure degrades. This benchmark — measured against ISO 42001 — reveals where the telecom sector stands.

Read the Analysis ↓
0
Industry Average
0%
Small (<200)
0%
Medium
0%
Large (1000+)
00 — URGENCY
The Clock Is Ticking
Four major regulatory and operational forces are converging on telecom simultaneously. Telecommunications networks are classified as critical digital infrastructure under the EU AI Act — placing every AI system involved in network management under the Act's most demanding obligations.
Days Until EU AI Act
Critical infrastructure AI · Aug 2, 2026
LIVE
DORA
Fully applicable since Jan 2025
KSA PDPL
Full enforcement · Sep 2025
PUBLISHED
BEREC AI Guidelines
AI in telecoms guidance · 2024
01 — EXECUTIVE SUMMARY
The Telecom AI Governance Gap

Telecommunications organisations are, on average, 39% ready for ISO 42001 certification — placing them in the lower-middle tier. This belies a dangerous paradox: the industry is one of the most aggressive AI adopters, deploying machine learning across network operations, customer experience, fraud prevention, and 5G orchestration at a scale matched only by big tech — yet it governs that AI with frameworks designed for an era of static network configurations.

The EU AI Act classifies AI used in the "management and operation of critical digital infrastructure" as high-risk (Annex III, §2). Telecommunications networks are unambiguously critical digital infrastructure. 5G standalone networks introduce AI at every layer — RAN intelligent controllers making sub-millisecond decisions where human oversight is architecturally impossible. Operators hold behavioural data on 50–150 million individuals, creating privacy and fairness risks that dwarf most other sectors.

The gap isn't operational discipline — telecom operators run 24/7 NOCs with rigorous change management. The gap is extending that discipline to the AI systems that increasingly run those networks. When a network configuration change requires a change advisory board review, but an AI model update that fundamentally alters network behaviour requires nothing, the governance framework has a critical blind spot.

€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
Annex III §2
Critical Infrastructure
Telecom networks = high-risk AI
150M+
Subscribers Per Operator
Scale of AI impact per decision
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations.
ApproachWhat It IsStrengthsLimitations
Internal AI PoliciesSelf-defined governance frameworksFlexible, quick to implement, tailoredNo external validation, not recognized by regulators
EU AI Act ComplianceMeeting Regulation 2024/1689Mandatory in EU, critical infrastructure AI obligationsJurisdiction-specific, not certifiable, reactive
NIST AI RMF 1.0Voluntary US framework
Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001Voluntary, no certification, US-centric
BEREC AI GuidelinesAI in telecoms guidance (2024)
Source: BEREC, 2024
Telecom-specific, addresses traffic management AIAdvisory only, not certifiable, EU-centric
3GPP / O-RAN StandardsNetwork AI specifications (RIC, SON, NWDAF)Technical interoperability, vendor ecosystem alignmentTechnical specs, not governance frameworks. Don't cover bias, fairness, or lifecycle governance.
ISO/IEC 42001:2023International standard for AI Management Systems
Source: ISO/IEC 42001:2023
Certifiable. Full lifecycle. Compatible with ISO 27001/9001. Satisfies EU AI Act QMS requirement. Covers network AI, customer AI, and vendor AI in one framework.New (27 months). Telecom-specific guidance still emerging.
03 — WHY ISO 42001
The Case for ISO 42001
For telecom operators seeking to extend their NOC discipline to AI governance while meeting critical infrastructure obligations under the EU AI Act, ISO 42001 is the strongest available option.
Critical Infrastructure Compliance
The EU AI Act classifies telecom network AI as high-risk critical infrastructure. ISO 42001 certification directly satisfies the quality management system requirement (Art. 17) and provides documented evidence of risk management (Art. 9), human oversight (Art. 14), and transparency (Art. 13).
NOC Discipline → AI Governance
Network operations culture — 24/7 monitoring, change advisory boards, incident escalation, ITIL processes — maps directly to ISO 42001 requirements. The governance infrastructure exists. ISO 42001 extends it to cover AI-specific risks, lifecycle, and accountability.
Enterprise AI Credibility
GCC operators positioning as enterprise AI service providers (e& enterprise, stc SCAI) need demonstrable AI governance. ISO 42001 certification is proof that the operator governs AI to an international standard — essential for winning enterprise and smart city contracts.
What ISO 42001 Does Not Cover
Network technical standards. ISO 42001 governs AI management, not network engineering. 3GPP, O-RAN, and ITU-T standards govern network architecture and interoperability. ISO 42001 complements these by adding AI governance to the management layer.
Spectrum regulation. Spectrum management is governed by national regulators (TRA, CITC, Ofcom). ISO 42001 covers governance of AI systems used in spectrum management, not spectrum allocation itself.
Our position: For telecom operators, ISO 42001 bridges the gap between network operations discipline and AI governance. The NOC culture of monitoring, escalation, and change control is the strongest operational foundation of any sector — the gap is extending it to AI.
The Benchmark
Telecommunications averages 39% readiness.
The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How telecom operators score across each of the 7 mandatory ISO 42001 management system clauses. Click any clause for detailed analysis, gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and telecom-specific compliance infrastructure patterns.
When a network config change needs CAB review but an AI model update that alters network behaviour needs nothing — governance has a critical blind spot.
05 — ANNEX A CONTROLS
Control Maturity by Domain
Each domain scored on a 1–5 maturity scale. Third-party management at 1.3/5.0 reflects the critical gap: network AI vendors (Ericsson, Nokia, Huawei) embed AI that operators cannot see, assess, or govern.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and telecom-specific control implementation analysis.
RAN Intelligent Controllers make decisions in milliseconds — faster than any human oversight loop. Governance must be built into the architecture.
06 — CRITICAL GAPS
Top 5 Gaps in Telecommunications
The most significant AI governance gaps in telecom — ranked by severity, with ISO 42001 clause references and remediation timelines.
The first telecom operator to achieve ISO 42001 demonstrates that critical infrastructure AI can be governed — not just operated.
07 — REGULATORY LANDSCAPE
Telecom AI Regulations
Every regulation affecting AI governance in telecommunications — including critical infrastructure obligations, consumer protection, and data monetisation rules.
RegulationJurisdictionStatusPenaltiesImpact on TelecomISO 42001 Alignment
EU AI ActEU/EEAHigh-risk: Aug 2026€35M / 7%Critical infrastructure AI (Annex III §2). Network management AI = high-risk. Chatbot transparency (Art. 50).Cl.5-10 · A.3-A.13
GDPREU/EEAIn force€20M / 4%Subscriber data in AI. Purpose limitation, automated decisions (Art. 22), DPIAs. Data monetisation governance.A.4 · A.10 · A.5
EECC / BERECEU/EEAIn force / 2024NRA enforcementQuality of service, net neutrality. AI-driven traffic management must comply. BEREC AI guidelines.Cl.8 · A.5 · A.11
DORAEU/EEALive since Jan 2025€10M / 5%ICT third-party risk. Telecom as critical ICT provider faces direct oversight.Cl.8 · A.9 · A.13
TRA/TDRAUAEActiveRegulatory actionUAE telecom regulator. Quality of service, consumer protection, data governance expectations.Cl.4 · Cl.8 · A.5
CITCSaudi ArabiaActiveRegulatory actionSaudi Communications, Space & Technology Commission. AI governance expectations tightening.Cl.4 · Cl.5 · A.5
KSA PDPLSaudi ArabiaFull: Sep 2025SAR 5MSubscriber data in AI. Data localisation. Purpose limitation for AI processing.A.4 · A.9 · A.10
UAE Data ProtectionUAEIn forceAED 5MSubscriber data processing in AI systems.A.4 · A.10
NIST AI RMFUSAVoluntaryNo direct penaltiesRelevant for operators with US operations. EO 14110 rescinded Jan 20, 2025.Cl.6 · Cl.9
The regulatory multiplier: Telecom operators face regulation from telecom regulators (TRA, CITC, BEREC), data protection authorities (GDPR, PDPL), AI-specific regulation (EU AI Act), and financial oversight (DORA). ISO 42001 provides a single governance framework addressing the overlapping requirements of all these regimes simultaneously.
08 — METHODOLOGY
How This Benchmark Was Built
Scores derived from ISO 42001 clause mapping against telecom practices, adjusted for NOC operational maturity, network AI vendor dependency, 5G/edge AI proliferation, and consumer data scale.
Data Sources
  • EU AI Act (Reg. 2024/1689) — Annex III §2 critical infrastructure
  • BEREC Guidelines on AI in Telecoms (2024)
  • Deloitte State of AI in Enterprise 2026 (3,235 leaders)
  • OECD AI Policy Observatory (80+ jurisdictions)
  • O-RAN Alliance AI/ML specifications
  • ISO Survey of Management System Certifications (2019–2024)
Important Caveats
  • NOC operational discipline is a genuine advantage — infrastructure exists
  • Network AI vendor dependency is the unique structural challenge
  • 5G/edge AI creates governance challenges no framework has fully addressed
  • GCC operators face dual pressure: national digital backbone + commercial competition
  • Certification typically requires 70–75% readiness to engage
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates

Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.

He is a transformation leader with over 20 years of experience across North America, Europe, and the GCC. He holds an AI Strategy and Leadership certification from MIT and is the founder of Digital North Associates, an AI governance and transformation firm.

Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology
© 2026 Digital North Associates. All rights reserved.
Where does your organization stand? Take the free ISO 42001 assessment — 15 minutes, no commitment.
Take Free Assessment