🏭 AI rules: Manufacturing, machines and products
For manufacturers AI meets product law: the Machinery Regulation, the Cyber Resilience Act, the Data Act and the new product liability rules.
Typical AI uses and their risk level
Minimal — the Omnibus clarified that quality-control AI is not a safety component.
Machinery Regulation from 20 Jan 2027; AI Act Annex I.
Minimal; protect trade secrets.
High risk; ZVOP-2 and consultation.
What to do
- Map connected products: Data Act access, CRA reporting since 11 Sep 2026.
- Plan Machinery Regulation conformity for learning safety functions.
- Update product liability insurance for software and AI.
- Check NIS2/ZInfV-1 status (manufacturing is a covered sector).
Common pitfalls
- Over-the-air updates of AI models can be substantial modifications — keep change records.
Examples
Quality control only → not a safety component; CRA applies to the software; Data Act if the machine is connected.
Rules that apply
Robots, cobots and machines with AI safety functions: the machinery rules apply; the AI Omnibus moved the machinery regulation to Annex I Section B of the AI Act.
Applies in phasesCyber Resilience ActAI software and devices with AI are products with digital elements. A high-risk AI system that meets the CRA’s essential requirements is presumed to meet the AI Act’s cybersecurity requirement.
Applies in phasesData ActData from machines and devices is valuable for AI. The Data Act decides who may use it: the user of the product can obtain it and share it with a third party — for example an AI maintenance service.
Coming soonProduct Liability DirectiveIf an AI product causes injury, damage to property or loss of data, the injured person can claim compensation without proving fault. A substantial modification (e.g. retraining or an update) can make you a manufacturer.
In forceGeneral Product Safety RegulationWhen assessing safety, the evolving, learning and predictive functions of a product must be taken into account — relevant for consumer products with AI.
Applies in phasesAI ActApplies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.
In forceNIS2AI tools and AI suppliers are part of your ICT supply chain: include them in risk analysis, access control and incident response — e.g. what happens if staff paste confidential data into an external AI.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.