EU Regulation 2024/1689, known as the AI Act, is the world’s first organic regulatory framework dedicated to artificial intelligence. It has a direct impact on industrial automation too, where machine vision, collaborative robots and predictive algorithms are now part of everyday production processes. Companies in the sector therefore need to find their way between obligations already in force and others still on the horizon.
How the regulation comes into force
The regulation entered into force on 1 August 2024, but the obligations set out in the AI Act become operational gradually, following a timeline spread across several years. The first bans, covering practices considered an unacceptable risk, took effect on February 2nd 2025. The obligations for general-purpose AI models became applicable on August 2nd 2025, together with the governance framework at European level.
An important milestone comes on August 2nd 2026, when most of the remaining provisions enter into application, including the transparency rules covering content generated or modified by AI. For high-risk systems, a category that concerns companies producing intelligent machinery quite closely, the European Commission has clarified that rules covering the most sensitive areas, such as biometrics, critical infrastructure, education, employment, migration and border control, will apply from December 2nd 2027, according to the official portal dedicated to the European digital strategy.
For high-risk systems built into products already covered by other EU harmonization legislation, which includes industrial machinery regulated under Machinery Regulation 2023/1230, the deadline shifts to 2 August 2028. This extension comes from the Digital Omnibus on artificial intelligence, the simplification package that amends the AI Act together with Machinery Regulation 2023/1230, aiming to make the compliance burden more manageable for businesses without lowering the level of protection the legislation provides.
What this means for industrial automation
In manufacturing, artificial intelligence rarely works on its own. It’s almost always connected to PLCs, robots, inverters, MES systems and operator interfaces, and this web of interlocking technologies makes assessing impact more complex than in other economic sectors. A predictive maintenance system, for instance, calls for a different level of attention depending on whether it simply flags anomalies or actually intervenes on the machine’s operating parameters, perhaps slowing it down or stopping it altogether.
An autonomous mobile robot moving between production lines raises questions mostly tied to the safety of the people sharing that same workspace. A generative AI assistant built into an HMI panel, meanwhile, calls for careful oversight of the responses given to the operator, along with precise traceability of the information it generates. In every one of these cases, the first step is understanding how the AI Act classifies the system in question, because that classification is what determines the concrete obligations to meet.
The Machinery Regulation stays central whenever a digital function can affect safety. In those cases, it needs to feed into the risk analysis, the design of protective measures and the plant’s technical documentation. Alongside it sits the Cyber Resilience Act, which governs the cybersecurity of connected products and which companies should read together with the AI Act rather than treat as a separate compliance task.
Companies in the sector should start with a precise inventory of the AI systems already in use. The next step is sorting them according to the risk levels set out in the regulation, followed by building the risk-management documentation and traceability records that European legislation requires.
