EU AI Act & GDPR for the Machinery Industry: Practical Guide 2026
How machinery manufacturers apply the EU AI Act after the 2026 Digital Omnibus: revised deadlines, risk classification, data sovereignty and audit trails.
Key takeaways
- The deadlines moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, took effect on 27 July 2026. Obligations for stand-alone high-risk systems now apply from 2 December 2027, and for AI built into regulated products from 2 August 2028.
- Transparency already applies. The Article 50 duty to tell people they are dealing with AI has been in force since 2 August 2026. It was not postponed.
- Machinery is now a special case. The Machinery Regulation moved into Section B of the AI Act’s Annex I. For AI that performs a safety function in a machine, the Machinery Regulation is the lead framework, and the double conformity assessment is gone.
- Most enterprise use cases are not high-risk. Service, sales and product knowledge agents are normally limited risk. The duties that bite are transparency, data sovereignty and traceability.
- Architecture decides compliance. Citation chains, audit trails and rights management have to be built into the platform, not bolted on afterwards.
Anyone planning AI in the machinery industry in 2026 is working against a moving target. The EU AI Act has been law since 2024, but its timetable was rewritten in the summer of 2026. Much of the guidance still circulating online refers to deadlines that no longer apply.
This guide sets out what is actually binding today, what changed specifically for machinery, and how to classify your own use cases.
What changed in 2026: the Digital Omnibus
On 24 July 2026 the EU published Regulation (EU) 2026/1744, the Digital Omnibus on AI. It entered into force on 27 July 2026, six days before the original high-risk deadline, and it is the first amendment to the AI Act since it was adopted.
The Omnibus amends three instruments at once: the AI Act itself, the aviation regulation, and, importantly for this industry, the Machinery Regulation (EU) 2023/1230.
Two points matter most:
- The heavy compliance machinery for high-risk systems (risk management, data governance, technical documentation, human oversight, conformity assessment) was deferred by roughly sixteen months.
- The new application dates are fixed calendar dates. They are no longer tied to the availability of harmonised standards, so they will not drift again for that reason.
What was not deferred is the part most manufacturers actually touch first: transparency.
The deadlines that actually apply
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited AI practices and AI literacy duties |
| 2 Aug 2025 | Obligations for general-purpose AI models |
| 2 Aug 2026 | Article 50 transparency duties; AI Office supervision and enforcement powers |
| 2 Dec 2026 | Marking duties under Article 50(2) for systems already on the market; newly added prohibitions |
| 20 Jan 2027 | Machinery Regulation (EU) 2023/1230 becomes fully applicable |
| 2 Aug 2027 | Member States must operate at least one AI regulatory sandbox |
| 2 Dec 2027 | High-risk obligations for stand-alone systems (Article 6(2), Annex III) |
| 2 Aug 2028 | High-risk obligations for AI embedded in regulated products (Article 6(1), Annex I) |
For a machinery builder, the two dates worth putting in the plan are 2 December 2026, when the remaining transparency duties close, and 20 January 2027, when the Machinery Regulation replaces the Machinery Directive without a grace period.
Why machinery is now a special case
This is the change most general AI Act summaries miss.
Before the Omnibus, an AI system acting as a safety component in a machine was caught twice: once by the Machinery Regulation for the machine as a whole, and once by the AI Act for the AI component. Two conformity assessments, two sets of documentation, one product.
The Omnibus moved the Machinery Regulation out of Section A of the AI Act’s Annex I and into Section B. The practical effect is a sectoral approach: the technical requirements for high-risk AI in machinery will live in the Machinery Regulation rather than being applied directly through the AI Act. In principle, one conformity assessment under the Machinery Regulation now covers the machine including its AI component.
Three caveats before anyone relaxes:
- The obligations did not disappear, they moved. The Commission has to adopt delegated acts folding the AI requirements into Annex III of the Machinery Regulation by 2 August 2028. Until those exist, harmonised standards developed under the AI Act can provide a presumption of conformity under Article 20 of the Machinery Regulation.
- CE marking is unchanged. Conformity assessment procedures, technical documentation, the EU Declaration of Conformity and the CE mark all stay exactly as they are.
- The sectoral route does not cover everything. An AI system inside a machine can still be caught separately, for example by an Annex III use case such as employment decisions, or by the transparency duties.
Is your AI use case actually high-risk?
The most common and most expensive misconception is that every AI system in an industrial setting is high-risk. It is not.
The Omnibus narrowed the definition of a safety component. An AI system counts as one when its intended purpose is to prevent or mitigate risks to health and safety. AI used purely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not become high-risk simply because it sits inside a regulated product. The backstop still applies: if failure or malfunction of the system would endanger health and safety, it qualifies as a safety component regardless of how it is labelled.
Mapped onto typical machinery use cases:
- Normally limited risk: service hotline support, maintenance and troubleshooting agents, proposal and product knowledge agents, internal document search, sales preparation. Duties here are transparency, documentation and traceability.
- Potentially high-risk: AI that performs a safety function in a machine, and Annex III uses such as decisions in recruitment, worker management or access to essential services.
- Prohibited regardless of sector: the practices listed in Article 5, including emotion inference in the workplace outside narrow medical and safety exceptions.
If you take one action from this article, make it this: write down, per use case, which of those three boxes it falls into and why. That single document is the foundation every later obligation builds on.
Provider or deployer: which one are you?
Machinery manufacturers are regularly both, and the two roles carry very different weight.
You are a deployer when you use an AI system in your own business, for example a service agent answering hotline questions or an agent drafting proposals. Deployer duties are comparatively light: use the system as intended, ensure human oversight, inform affected people, keep logs.
You are a provider when you place an AI system on the market or put it into service under your own name, which includes shipping a machine with an AI safety component built in. Provider duties are the heavy ones: risk management, data governance, technical documentation, conformity assessment and registration.
The same company can be a deployer for its internal agents and a provider for what it sells, with two different timelines: December 2027 for stand-alone systems, August 2028 for what is embedded in the product.
Transparency: the duty that is already live
Since 2 August 2026, people must be told when they are interacting with an AI system unless it is obvious from the context. Content that is artificially generated or manipulated has to be marked as such in a machine-readable form. For systems already on the market on that date, the marking requirement under Article 50(2) closes on 2 December 2026.
In practice this is a small change to a service chat or customer portal and a policy decision about generated content. It is also the duty an authority can check most easily, which is why it is worth closing first.
What non-compliance costs
The penalty tiers were not changed by the Omnibus:
- Up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, for prohibited practices under Article 5.
- Up to 15 million euros or 3 percent for breaches of other obligations, including high-risk and transparency duties.
- Lower ceilings apply for supplying incorrect or misleading information to authorities.
The 14-point checklist
- Per-use-case risk classification documented
- Intended purpose and limits in writing
- Provider or deployer role determined per system
- Training and input data traceably documented
- Transparency notice for users (you are interacting with AI)
- Human oversight embedded
- Error and escalation paths defined
- Citation chain for every answer
- Audit trail retained for at least 12 months
- Data sovereignty via EU hosting or dedicated tenant
- No customer data used for third-party model training
- DPIA where personal data is involved
- Technical security (ISO 27001, TLS, encryption at rest)
- Roles-and-rights management, plus regular quality and fairness reviews
Data sovereignty: what actually matters
EU hosting alone is not enough. What matters: which inference endpoint is actually used, how logging is structured, and whether customer data is used for model training. Clear contractual exclusions and a technical audit trail are mandatory.
This is also where the AI Act and GDPR meet. The AI Act does not replace GDPR, it runs alongside it. Where personal data is processed, the GDPR obligations apply in full, including the data protection impact assessment. Where the AI Act adds duties, they sit on top.
How Genow covers this
EU hosting in Frankfurt, Azure OpenAI EU, optional VPC or on-prem deployments, dedicated tenant scope, per-answer citation chain, versioning and rights management in the Context Engine, ISO-27001-compliant operations. For every answer you can trace which sources in which version were used.
At the same time, high-quality results provide employees with optimal support in carrying out their tasks. More detail on controls and certifications is on the security and compliance page.
Implementation roadmap
-
Inventory all planned AI use cases.
-
Classify risk per use case, and record whether you act as provider or deployer.
-
Close the transparency duties that already apply.
-
Install a governance board (compliance, IT, business).
-
Pick a platform with audit-trail capability (for example, Genow).
-
Policies, training, review cadence, with a checkpoint before 20 January 2027 for anything that ships inside a machine.
FAQ
Did the EU AI Act high-risk deadline really change?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. Obligations for stand-alone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products from 2 August 2027 to 2 August 2028.
Which EU AI Act rules apply right now?
The prohibitions on unacceptable practices since February 2025, the rules for general-purpose AI models since August 2025, and the Article 50 transparency duties since 2 August 2026. The high-risk requirements are the part that was deferred.
What's the biggest misconception about the EU AI Act?
That every enterprise AI is automatically classified as high-risk. It isn't. Most productive use cases fall under limited risk, with duties around transparency, documentation and traceability.
Is a service or sales agent a high-risk AI system?
Normally no. Service hotline support, maintenance agents, proposal and product knowledge agents typically sit in limited risk. High-risk status arises when safety-critical decisions are automated without human override, or when the use case appears in Annex III, for example recruitment or worker management.
Is AI inside our machines automatically high-risk?
No. It is high-risk when it acts as a safety component and the product needs third-party conformity assessment. The Digital Omnibus narrowed this: AI used for quality control, performance optimisation or convenience is not high-risk merely because it sits inside a regulated product, unless its failure would endanger health and safety.
Do we still need two conformity assessments for AI in machinery?
No. The Omnibus moved the Machinery Regulation into Section B of the AI Act's Annex I, so the Machinery Regulation is the lead framework for AI safety functions in machines. In principle one conformity assessment covers the machine including its AI component. The Commission must fold the AI requirements into the Machinery Regulation via delegated acts by 2 August 2028.
Are we a provider or a deployer?
Often both. You are a deployer when you use AI internally, for example a service agent. You are a provider when you place an AI system on the market under your own name, which includes shipping machines with AI safety components. Providers carry the heavier obligations.
Does the AI Act replace GDPR?
No. Both apply in parallel. GDPR governs personal data, while the AI Act adds transparency, risk and documentation duties on top.
What are the penalties under the EU AI Act?
Up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3 percent for other breaches, including high-risk and transparency obligations. The Digital Omnibus did not change these tiers.
Do I need a dedicated AI certification?
In most cases, no. Documentation, audit trails and governance are sufficient for limited-risk use cases. Certification and conformity assessment come into play for high-risk systems and for products that already require third-party assessment.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026
- Regulation (EU) 2024/1689 (AI Act)
- Regulation (EU) 2023/1230 (Machinery Regulation)
This article is general information on the current state of regulation, not legal advice. Classifying your own systems should be confirmed with your legal or compliance function.