Industry · AI Act

Industry & AI Act: AI at the heart of machines and production lines

Industrial AI is used for quality control, predictive maintenance, and machine operation. The AI Act may classify it as high-risk when it constitutes a safety component of a product subject to harmonisation legislation, such as machinery. This guide clarifies the qualification, the interaction with machinery legislation, and the corresponding obligations.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: AI Act.
  • Manufacturers integrating AI as a safety component in their machinery are primarily concerned, as providers.
  • Qualify the role of AI.
  • Managing risks and data.
  • Ensuring human oversight.
  • Up to €35M or 7% for prohibited practices and €15M or 3% for high-risk non-compliance, on top of the sectoral penalties applicable to machinery.

Regulatory deadlines

The key dates of this regulation.

August 2024

Entry into force

In force

February 2025

Ban on prohibited practices

In force

August 2025

General-purpose AI models (GPAI) & governance

In force

August 2026

High-risk system obligations (Annex III)

In force

August 2027

High-risk embedded in products (Annex I)

Upcoming

What does the AI Act cover?

The AI Act classifies as high-risk those AI systems that constitute a safety component of a product covered by Union harmonisation legislation (including machinery), where that product must undergo a third-party conformity assessment. Obligations cover risk management, data quality, transparency, human oversight, and robustness.

Internal uses with no security role (production analysis, maintenance) generally fall under the limited-risk category.

Is the 'Industry' sector concerned?

Manufacturers integrating AI as a safety component of their machines are primarily concerned, as providers. Operators deploying AI in production are deployers, subject to lighter obligations.

The classification depends on the AI's role: product safety (high-risk) or simple internal optimisation (limited risk).

Detailed obligations

Qualifying the role of AI

Determine whether AI is a safety component (high risk) or an internal tool (limited risk).

Manage risks and data

Implement risk management and data quality controls for high-risk systems.

Ensuring human oversight

Enable effective human oversight, particularly for the control of machinery.

Document and assess

Build the technical documentation and align the assessment with machinery legislation.

Monitoring after market placement.

Organising post-market surveillance of products incorporating AI.

Sanctions & risks

Up to €35M or 7% for prohibited practices and €15M or 3% for high-risk non-compliance, on top of the sectoral penalties applicable to machinery.

A poorly classified AI security system exposes to sanctions and product withdrawal.

Application timeline

  • 1Entry into force. 1 August 2024.
  • 2High risk (security components). According to the timeline for the products concerned, from 2026–2027.

Common mistakes in the sector

  • 1Underestimated security role. Treating an AI steering system as a simple internal tool.
  • 2Separate frameworks. Managing AI Act and Machinery Directive in silos.
  • 3Uncontrolled data. Using non-representative training data.
  • 4Superficial oversight. Displaying human oversight without real means.

Practical case

A machinery manufacturer integrates an AI anomaly-detection system that triggers an emergency stop. This safety function falls under the high-risk category: the manufacturer documents risk management, data quality, and oversight, and aligns its AI Act assessment with that of the Machinery Directive rather than conducting two separate processes.

Compliance roadmap

  1. 1

    Inventory. Inventorying AI use cases (machinery, quality control, maintenance).

  2. 2

    Qualify. Distinguish security component (high risk) from internal use.

  3. 3

    Align the frameworks. Align AI Act documentation with Machinery legislation.

  4. 4

    Frame. Implement human oversight and traceability.

  5. 5

    Monitor. Organising post-market surveillance.

Frequently asked questions

No: only an AI system constituting the safety component of a regulated product is generally covered; quality control or maintenance typically fall under limited risk.

Take action on AI Act

Free assessment or a chat with an expert dedicated to industry.

They already trust us

See how organisations in the industry sector secured their compliance with DCO.

See testimonials