Use-case guide
AI in Manufacturing & Industrial IoT
AI in factories and connected industrial devices sits at the intersection of product-safety law (centuries old, ferocious enforcement) and the new AI rules (still being written). The EU AI Act treats AI used as a safety component of a regulated machine or device as high-risk by default, plugging directly into the existing Machinery Regulation, Medical Devices Regulation, and Radio Equipment Directive. In the US, OSHA, the CPSC, and sector regulators (FDA, FAA, NHTSA) are scrutinising AI components inside their existing safety frameworks. The compliance burden often comes from those existing regimes, not new AI law.
For: OT engineers, plant managers, industrial AI vendors, robotics teams, product-safety counsel
What's at stake
AI as a safety component is high-risk under the EU AI Act
Article 6(1) makes any AI system that's a safety component of a product covered by the EU's harmonisation legislation (Machinery, Toy Safety, Lifts, Pressure Equipment, MDR, IVDR, In-Vitro, RED, Cableways) high-risk — full Annex III obligation stack PLUS the existing product-safety conformity assessment.
Pre-market conformity assessment IS the gate
For most high-risk AI in industrial products, conformity assessment via a notified body is required before placing on the EU market. CE marking now incorporates AI Act compliance for in-scope devices.
Connected industrial devices come with cyber-resilience duties
The EU Cyber Resilience Act (in force 2024) layers cyber-secure-by-design and CVE-management requirements on top of any AI in connected industrial products. The NIS2 Directive adds operator-side incident reporting.
Predictive maintenance AI used for worker safety is high-risk too
AI that decides when to shut down equipment, alert workers, or trigger interlocks is in scope as a safety component. Errors don't just cost money — they're an OSHA / worker-safety problem in the US, EU-OSHA in Europe.
Regulations that apply
EU AI Act
LawHigh-risk for AI as safety components of regulated products (Article 6(1) + Annex I). Conformity assessment, technical documentation, post-market monitoring, human oversight, robustness/cybersecurity.
Where in the text: Article 6(1); Annex I; Articles 9-15, 17, 43, 72.
EU Machinery Regulation 2023/1230
RegulationModernised the old Machinery Directive (2006/42/EC) to address safety risks from AI / self-evolving behaviour in machines. Applies from 14 January 2027. Aligns with AI Act conformity assessment.
Where in the text: Regulation (EU) 2023/1230, Article 5, Annex III.
EU Cyber Resilience Act
LawMandatory cyber-secure-by-design for any product with digital elements placed on the EU market, including industrial IoT. AI within scope unless explicitly carved out elsewhere.
Where in the text: Regulation (EU) 2024/2847, Articles 6-13.
US OSHA + sector AI guidance
GuidelineOSHA's General Duty Clause applies to AI used in worker-safety-relevant roles. NHTSA covers AI in vehicles, FDA in regulated devices/equipment used in healthcare manufacturing.
Where in the text: 29 U.S.C. § 654; NHTSA Automated Vehicle Comprehensive Plan; FDA SaMD framework.
Do
- ✓Map every AI component in your bill of materials AGAINST the harmonisation legislation that applies to the parent product, then plan the conformity assessment chain.
- ✓Bake post-market monitoring into your IoT telemetry — Article 72 of the AI Act expects ongoing performance tracking with reporting of serious incidents within 15 days.
- ✓Document the AI risk-management system per Article 9 BEFORE you start the CE marking process; auditors will ask for it first.
- ✓Design for cybersecure firmware updates over the life of the product — the CRA explicitly requires it and there's no grandfathering.
- ✓Plan for the 14 January 2027 EU Machinery Regulation deadline now — that's when AI-in-machinery transitions from grace period to enforceable.
Don't
- ✗Don't ship an AI safety component into the EU without a notified body involved — self-declared conformity is not enough for most Annex III categories.
- ✗Don't treat 'AI as just software'. Industrial AI is a product-safety problem first; the AI Act layers on top of, not instead of, existing regimes.
- ✗Don't rely on model-card-style transparency to satisfy Article 13 instructions for use — your end-user (operator) needs operational, not technical, documentation.
- ✗Don't deploy a connected device into NIS2-essential sectors without a documented incident-reporting plan — operator-side breach within 24 hours.
- ✗Don't reuse training data across product lines without revalidating; distribution shift in industrial settings is a known and often-cited deficiency in conformity reviews.
Also worth knowing
If you sell into automotive: the UNECE WP.29 framework (AV Regulation, Cybersecurity Regulation) is now the operative regime, with the EU AI Act sitting on top. If you sell into medical-device manufacturing: the MDR + AI Act stack is brutally specific — most AI software-as-a-medical-device (SaMD) cases need 510(k) or FDA QSR-equivalent processes plus EU AI Act conformity.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.