In brief
- Regulation: AI Act.
- Manufacturers integrating AI as a safety component in their machinery are primarily concerned, as providers.
- Qualify the role of AI.
- Managing risks and data.
- Ensuring human oversight.
- Up to €35M or 7% for prohibited practices and €15M or 3% for high-risk non-compliance, on top of the sectoral penalties applicable to machinery.
Regulatory deadlines
The key dates of this regulation.
August 2024
Entry into force
In forceFebruary 2025
Ban on prohibited practices
In forceAugust 2025
General-purpose AI models (GPAI) & governance
In forceAugust 2026
High-risk system obligations (Annex III)
In forceAugust 2027
High-risk embedded in products (Annex I)
UpcomingWhat does the AI Act cover?
The AI Act classifies as high-risk those AI systems that constitute a safety component of a product covered by Union harmonisation legislation (including machinery), where that product must undergo a third-party conformity assessment. Obligations cover risk management, data quality, transparency, human oversight, and robustness.
Internal uses with no security role (production analysis, maintenance) generally fall under the limited-risk category.
Is the 'Industry' sector concerned?
Manufacturers integrating AI as a safety component of their machines are primarily concerned, as providers. Operators deploying AI in production are deployers, subject to lighter obligations.
The classification depends on the AI's role: product safety (high-risk) or simple internal optimisation (limited risk).
Detailed obligations
Qualifying the role of AI
Determine whether AI is a safety component (high risk) or an internal tool (limited risk).
Manage risks and data
Implement risk management and data quality controls for high-risk systems.
Ensuring human oversight
Enable effective human oversight, particularly for the control of machinery.
Document and assess
Build the technical documentation and align the assessment with machinery legislation.
Monitoring after market placement.
Organising post-market surveillance of products incorporating AI.
Sanctions & risks
Up to €35M or 7% for prohibited practices and €15M or 3% for high-risk non-compliance, on top of the sectoral penalties applicable to machinery.
A poorly classified AI security system exposes to sanctions and product withdrawal.
Application timeline
- 1Entry into force. 1 August 2024.
- 2High risk (security components). According to the timeline for the products concerned, from 2026–2027.
Common mistakes in the sector
- 1Underestimated security role. Treating an AI steering system as a simple internal tool.
- 2Separate frameworks. Managing AI Act and Machinery Directive in silos.
- 3Uncontrolled data. Using non-representative training data.
- 4Superficial oversight. Displaying human oversight without real means.
Practical case
A machinery manufacturer integrates an AI anomaly-detection system that triggers an emergency stop. This safety function falls under the high-risk category: the manufacturer documents risk management, data quality, and oversight, and aligns its AI Act assessment with that of the Machinery Directive rather than conducting two separate processes.
Compliance roadmap
- 1
Inventory. Inventorying AI use cases (machinery, quality control, maintenance).
- 2
Qualify. Distinguish security component (high risk) from internal use.
- 3
Align the frameworks. Align AI Act documentation with Machinery legislation.
- 4
Frame. Implement human oversight and traceability.
- 5
Monitor. Organising post-market surveillance.
Frequently asked questions
No: only an AI system constituting the safety component of a regulated product is generally covered; quality control or maintenance typically fall under limited risk.
Take action on AI Act
Free assessment or a chat with an expert dedicated to industry.
They already trust us
See how organisations in the industry sector secured their compliance with DCO.