On this page
7. Relationship to law
EU rules already require continuity measures in some sectors. High-risk AI rules also address human oversight and safe stopping. KLOD is voluntary; the legal duties depend on the organisation, system and jurisdiction. Applying the pattern does not by itself establish compliance.
Informative legal context, reviewed on 11 September 2026.
7.1 Why supplier dependence matters
The European Systemic Risk Board's Warning of 25 June 2026, ESRB/2026/3 identifies dependence on a small number of AI and cloud providers as a resilience risk. Its warning is a reason to examine dependencies, not a requirement to use KLOD.
7.2 Existing continuity requirements
These duties apply to organisations within each law's scope. NIS2 covers qualifying entities in sectors including energy, transport, healthcare, digital infrastructure and public administration. Check its scope and the applicable national law; sector membership alone does not determine coverage.
| Rule | Requirement | Who is covered |
|---|---|---|
| DORA Art 28(8) | Documented, tested exit plans for ICT services supporting critical or important functions, with alternatives and transition arrangements | Financial entities within DORA's scope |
| Regulation (EU) 2022/2554 Art 29(1)(a) | Assessment of concentration risk where a provider is "not easily substitutable" | Financial entities |
| Regulation (EU) 2022/2554 Art 11, Art 12 | ICT continuity policy, business impact analysis, yearly testing, backup and restoration, RTO and RPO | Financial entities |
| Directive (EU) 2022/2555 (NIS2) Art 21(2)(c) | Business continuity, backup management, disaster recovery, crisis management | Essential and important entities |
| Directive (EU) 2022/2555 Art 21(2)(d) | Supply chain security | Essential and important entities |
These laws address continuity and supplier risk. They do not prescribe KLOD or require every AI task to have a manual equivalent.
7.3 Human oversight and safe stopping
AI Act Article 14 requires high-risk systems to support effective human oversight. As appropriate and proportionate, people must be able to override outputs and interrupt operation through a stop button or similar procedure that brings the system to a safe state. Article 26(2) requires deployers to assign oversight to people with competence, training, authority and support.
High-risk classification follows Article 6: specified products or safety components subject to third-party conformity assessment, and listed Annex III uses subject to the Article 6(3) exceptions. A medical, industrial or public-sector use is not automatically high-risk.
Under Article 113 as amended by Regulation (EU) 2026/1744, the relevant Chapter III requirements apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Check the applicable exclusions and transitional rules for an existing system.
Oversight during operation does not establish continuity after supplier withdrawal. Article 15(4) permits backup or fail-safe arrangements; it does not impose a universal manual path.
7.4 Use this in a design review
- Identify the affected work, its users and the rules that apply to the organisation.
- Design the required continuity and control measures: retained data, independent access, operator permissions, safe stopping and a usable human workflow where appropriate.
- Test those measures and keep the results. Use the legally required procedures and intervals alongside the evidence needed for any KLOD declaration.
For decisions about people, also check GDPR Article 22. It restricts solely automated decisions with legal or similarly significant effects, subject to its exceptions and safeguards. The Article 29 Working Party guidance requires meaningful human involvement by someone able to change the decision. KLOD's drill evidence can inform a review of competence; it is not a legal definition of competence.
Download the specification (Markdown)View or edit the source on GitHub