Machine builders integrating AI into safety functions face a binding dual-track compliance regime: Regulation 2024/1689 (AI Act) and Regulation 2023/1230/EU (Machinery Regulation), both of which apply in parallel and can each trigger a third-party conformity assessment [S4].
Most AI Act provisions apply from 2 August 2026, but the obligations that matter to machine builders, covering high-risk AI systems used as safety components, apply from 2 August 2027 [S2]. A 2 August 2028 backstop exists in the Digital Omnibus draft, contingent on a European Commission adequacy decision [S4]. UK builders shipping into the EU must also comply [S2].
Defining an AI System and the Provider/Deployer Split
Article 3(1) of the AI Act defines an AI system as a machine-based system that operates with varying levels of autonomy, may exhibit adaptiveness after deployment, and infers from inputs how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments [S5].
Article 3(3) defines the provider as the natural or legal person that develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark, while Article 3(4) defines the deployer as the person using the AI system under its authority [S5]. Under this split, a machine builder embedding AI is treated as the provider, the end user as the deployer, and a substantial modification by the deployer can convert the deployer into a provider, which materially shifts the compliance burden [S2][S4].
When Does AI in a Machine Become High-Risk?
Article 6(1) flags an AI system as high-risk when two conditions are met: (a) the AI is intended as a safety component of a product (or is itself a product) listed in Annex I, and (b) that product requires third-party conformity assessment under Annex I legislation [S4].
Article 3(14) defines a safety component as one that fulfils a safety function, or whose failure or malfunction endangers health and safety of persons or property [S5]. Applied to industrial robotics, the Bird & Bird table maps collision avoidance for a robotic arm and autonomous factory navigation as safety components, production scheduling optimisation as not, and predictive maintenance alerts as borderline, depending on whether the failure creates a safety hazard [S4].
For a cutting machine or coding machine cell, the same logic applies: AI that decides when to retract a guard or stop a spindle is a safety component, while AI that optimises throughput or ink consumption is not [S4].
Compliance Steps, CE Marking and Conformity Assessment

Before an AI system is placed on the EU market or put into service for the first time, it must be CE marked, whether supplied standalone or embedded in a product such as a machine; the product manufacturer assumes provider obligations for the embedded AI [S2].
Because the AI Act CE marking process mirrors the Machinery Directive CE marking process, most steps (technical file, risk assessment, declaration of conformity) will be familiar to engineers who have CE marked machinery before [S2]. Where the AI qualifies as a safety component of a product listed in Annex I, third-party conformity assessment by a notified body is required, and the substantial-modification rule reopens that assessment for any post-2027 modification that changes the safety function [S2][S4].
The AI Act is not retrospective, so AI systems placed on the market before the applicable date are not covered; a substantial modification after the date pulls the system into full compliance [S2].
Comparison: Which AI Functions Trigger High-Risk Treatment
Three decision criteria separate safety-component AI from non-safety AI: (1) does the function prevent or mitigate a hazard to persons or property, (2) does its failure endanger health and safety, and (3) does the host product require third-party conformity assessment under Annex I legislation [S4][S5].
Applied across typical machine-builder use cases: collision avoidance for a robotic arm scores yes on all three and is high-risk; pharmaceutical quality inspection scores yes on (1) and (2) because defects become a patient safety risk, and is high-risk; packaging inspection scores no on (1) because it is a commercial/aesthetic issue and is not high-risk; predictive maintenance that does not create a safety hazard on failure is borderline and typically not high-risk [S4]. For a filling machine line, AI-driven fill-weight control is generally not high-risk unless a failure mode would create a contamination or over-pressure hazard, in which case it moves into the high-risk column [S4].
Liability, Worker Safety and the Human-Factor Question

The AI Act's stated objective is to maintain the previous level of worker protection when work equipment uses AI, treating AI alternatively as a tool of employer power, a tool of work execution, or an individual/collective (intelligent) protection device [S1].
Where AI takes on the role of manager or autonomous executor of a work process, Italian Commentary references Article 2087 of the Italian Civil Code as the residual employer duty that cannot be delegated, meaning the residual organisational, managerial, control and spending power of the H&S guarantors must remain well-defined [S1]. The AI Act cannot answer all of those liability questions on its own, because its legal basis is Articles 114 and 16 TFEU (single market and competition), not worker safety, so the Machinery Regulation 2023/1230/EU and national OSH codes (for example, Italian Legislative Decree 81/2008, Titles I and III) continue to govern the worker-safety profile in parallel [S1].
Practical Engineering Controls and Documentation
Bird & Bird's working compliance list for industrial AI robotics is: document the safety function analysis; for borderline cases, weigh the cost of over-classification (unnecessary compliance burden) against under-classification (regulatory exposure and re-assessment if reclassified later); and watch the substantial-modification trigger, including in data-pooling scenarios where pooled retraining can amount to a substantial modification by the deployer [S4].
For a labeling machine using computer-vision AI to verify label placement, the engineering question is whether a missed label could create a downstream safety hazard (pharmaceutical mislabel) or only a commercial one (cosmetic mislabel), because the answer flips the system from non-high-risk into high-risk and pulls in Annex I conformity assessment [S2][S4].
Standards, Sources and What's Verifiable

The binding instruments to cite in a technical file for an EU-placed machine with AI safety components are Regulation 2024/1689 (AI Act) and Regulation 2023/1230/EU (Machinery Regulation), with AI Act Article 6(1) and Article 3(14) as the load-bearing definitions for high-risk classification and safety component status [S4][S5].
Comparable engineering context for control-system reliability on industrial cells, including redundancy, diagnostics and safe-stop architecture for the hardware under that software, is covered in the machine safety reference and in the core machine build-up of a typical automated cell [S2].
For 2026 process engineers, the next trackable nodes are: the European Commission adequacy decision under the Digital Omnibus draft that would push the high-risk date to 2 August 2028, any Commission decision confirming that the high-risk obligations are met, and the publication of harmonised standards under the AI Act that will give presumption of conformity for safety-component AI used in machinery [S4].
Background reading: Fan Affinity Laws: Why Speed Cuts Save So Much Energy.