AI Act and smart machinery
All articles

Cybersecurity

AI Act, Digital Omnibus and smart machinery: implications for industrial companies

AI Act, Digital Omnibus, CRA and Machinery Regulation: what companies that integrate AI into machines and plants need to check.

Artificial intelligence has quietly become part of industrial machinery: vision systems that identify rejects, predictive maintenance algorithms, autonomous mobile robots, adaptive adjustments, operator assistants, quality control, remote diagnostics, intelligent HMI and software that modifies the behaviour of the system according to data.

For years, these systems were treated as advanced software functions. Regulation (EU) 2024/1689, known as the AI Act, and the Digital Omnibus amendments change the question: it is no longer enough to establish whether the algorithm works. Companies must determine whether the AI affects safety, health, fundamental rights, cybersecurity, traceability or product liability.

Because industrial AI is no longer just software

In the industrial sector, AI rarely lives isolated. It is connected to sensors, PLC, safety PLC, robot, inverter, MES/SCADA systems, cloud, teleassistance, production database and operator interfaces. When an algorithmic decision influences a movement, a stop, access, a speed, a recipe or a working mode, the problem is not only computer science: it also becomes a safety problem of the machines.

This point should not be underestimated; an AI model used to classify images does not have the same weight as a model that authorizes movement of an axis or recognizes the presence of an operator in a dangerous area. The regulatory classification depends on the real function, not on the commercial name of the software.

AI Act: the European risk-based framework

The AI Act introduces a risk-based model. Some practices are prohibited, others are classified as high-risk, others still require transparency obligations or remain at a minimum risk. For industrial companies the most important category is that of high-risk systems, because it can cover AI used as a safety component or integrated in products regulated by European product regulations.

The rules for high-risk systems require:

  • risk management
  • quality of data
  • Technical documentation
  • registration of events
  • information for the user
  • human surveillance
  • robustness
  • accuracy
  • cybersecurity.

In practice: AI must be designed, controlled, verified and maintained as part of a demonstrable technical system.

Digital Omnibus: what changes in timing and application

The Digital Omnibus was created to simplify the application of the AI Act and reduce operational uncertainties. The European Commission has indicated a more gradual path for high-risk systems: some high-risk areas will have a later application date, while systems integrated into regulated products, such as elevators or toys, will have an even longer window.

For companies this should not become a reason for procrastination, full application dates can slip, but industrial projects have long cycles: machines, plants and software come into development years before placing on the market. Expecting the deadline means almost always having to correct already frozen architectures.

When industrial AI can become high-risk

Not every AI system integrated into a machine is high-risk. An algorithm that optimises energy consumption or recommends maintenance may have a limited risk profile if it does not directly affect safety and the operator retains full decision-making control. The situation is different when AI forms part of a safety function, enables or disables movement, influences robot behaviour or replaces human judgement in a critical context.

The evaluation must start with three simple questions: what does the AI system decide? Which machine or process does it work on? What if it's wrong, it's manipulated, degrades over time or works out of the training domain?

Practical examples on machines, robots and plants

  • Artificial vision for quality control: normally it is not high-risk if it discards products and does not affect safety. It becomes critical if its output changes access, speed or motion permissions.
  • AI system to detect people in a dangerous area: it can become a safety component and should be treated with validation logic, redundancy, limits and much more robust evidence.
  • Predictive maintenance: it is less critical if it only generates recommendations. It becomes more delicate if it controls stops, bypasses or automatic operating conditions.
  • Autonomous mobile robots or AMR: navigation, recognition of obstacles and trajectory decisions can affect people's safety directly.
  • Generative assistant on HMI or digital instructions for use: requires control of responses, usage limits, traceability of information and risk management of incorrect instructions.

Machinery Regulation, CRA, NIS2 and AI Act: different roles

Machinery Regulation (EU) 2023/1230 remains central when AI is integrated into a machine or machine set. If a digital function can compromise safety, it must enter risk analysis, design safety functions, validation and technical documentation. Reference Reference

The Cyber Resilience Act addresses the cybersecurity of products with digital elements and can also apply to machinery. NIS2 concerns the cyber resilience of essential and important entities, with an emphasis on operational continuity and organisational security. The AI Act regulates AI systems according to risk categories. These are different legal frameworks, but they intersect in industrial applications: a machine incorporating AI may be subject to safety, cybersecurity, software traceability, data-management and post-market monitoring obligations.

Technical documents to be prepared

If your machines integrate AI systems, the first thing to build is an inventory of AI systems used or integrated in products. Without inventory there is no classification, without classification it is not possible to establish obligations, responsibility and priority. Below is a short list of steps to be taken for the conformity of machines that integrate AI algorithms:

  1. AI Inventory: model, supplier, version, function, data used, interfaces and output generated.
  2. Role classification: provider, deployer, importer, distributor or manufacturer that integrates AI into the product.
  3. AI Act rating: minimum risk, transparency, high-risk, GPAI or motivated exclusion.
  4. Safety analysis: impact on safety functions, machinery risks, PL/SIL, stopping functions and operating modes.
  5. Cybersecurity analysis: access, updates, data manipulation, model protection, logs and hardening.
  6. Technical documentation: requirements, data, tests, limits, instructions, human surveillance and post-market monitoring.
  7. Change management: versioning, retraining, updates, rollback, validation and traceability.

The critical point: use domain and model drift

An AI system can work well in testing and make it worse over time if materials, lighting, layout, speed, operators, recipes or environmental conditions change. This phenomenon, often called “drift”, is particularly dangerous when the output of the algorithm affects the safety or quality of an automatic decision.

This also involves instructions for use that must indicate usage conditions, limits, periodic controls, requalification criteria, abnormal management and user responsibility. A model not validated in the real domain should not be used to make critical decisions.

Frequently Errors

treat AI as simple software functionality without analysis of the regulatory role

not distinguish between decision support and automatic control

do not document dataset, training domain, limits and validation conditions

integrate a third-party model without clarifying responsibility between the provider and machine manufacturer

forget cybersecurity, updates, remote access and data manipulation

do not update instructions for use, technical file, instructions and post-market procedures. Reference

How Waves Engineering supports companies

Waves Engineering helps manufacturers, integrators and manufacturing companies to transform AI integrated into a documented and verifiable system. The work starts from the mapping of algorithms and digital functions, continues with the normative classification and arrives at the technical documentation necessary to demonstrate risk control.

Support may include AI Act classification, integrated safety, cybersecurity and AI risk assessment, analysis of the impact of the Machinery Regulation, review of safety functions, checks of instructions and the technical file, validation procedures, version management and post-market monitoring requirements.

FAQ

Does the AI Act also concern industrial machines?

Yes, when an AI system is integrated into a machine, in a safety component or in a regulated product and can affect safety, health or fundamental rights. The assessment must be made by case.

Are all factory-used IAs high risk?

No. Many industrial AI systems can remain at a limited or minimal risk. They become critical when they command functions, influence safety, replace human decisions in sensitive contexts or are integrated into regulated products.

Does Digital Omnibus eliminate AI Act’s obligations?

No. Digital Omnibus aims to simplify and coordinate the application. It is not advisable to interpret it as a cancellation of obligations: companies must however classify the systems and prepare the documentation.

What is the relationship between AI Act and Machinery Regulation?

The Machinery Regulation governs the machine safety. The AI Act governs the AI system. If AI affects the safe behaviour of the machine, the two paths must be managed together.

Where to go to adjust?

Start with an inventory of the AI systems, identify the company’s role and assess the impact on machinery safety, cybersecurity, data, instructions and technical documentation.

From insight to action

Bring these decisions
into your machinery.

Tell us about the project, development stage and outstanding questions. A Waves engineer will identify the most effective route.

Request a technical assessment

Keep reading

Related
insights.

Industrial machinery cybersecurityCybersecurity · 6 min

Machinery cybersecurity: what manufacturers need to know

Protection of machinery against corruption: prEN 50742Cybersecurity · 18 min

prEN 50742: protecting connected machinery against corruption of data and software