What is the AI Act?

The AI Act, Regulation (EU) 2024/1689, is the European law that sets requirements for artificial intelligence based on the risk an AI system poses: the higher the risk to safety or fundamental rights, the heavier the obligations. For industry the law is mainly relevant when AI performs a safety function in a machine or installation. Applications such as predictive maintenance or visual quality inspection usually fall into a lower risk class.


🧠 What risk classes does the AI Act define?

Risk class Examples Consequence
Unacceptable Social scoring, emotion recognition in the workplace Prohibited
High risk AI as a safety component of a machine (Annex I); AI in critical infrastructure (Annex III) Strict requirements, conformity assessment, CE
Transparency Chatbots, AI-generated content Inform the user
Minimal Predictive maintenance, process optimisation without a safety function No specific requirements

Two high-risk routes matter for industry. Annex I covers AI in products already subject to EU product legislation, such as the Machinery Regulation. Annex III lists AI used as a safety component in the management of critical infrastructure such as water, gas, electricity and traffic.


πŸ—“οΈ When do the obligations apply?

The digital omnibus (in force since 27 July 2026) postponed the high-risk obligations:

Date What applies
1 August 2024 Entry into force
2 February 2025 Prohibited practices and AI literacy
2 August 2025 Rules for general-purpose AI models
2 August 2026 Transparency obligations (Article 50)
2 December 2027 High-risk systems in Annex III (including critical infrastructure)
2 August 2028 High-risk AI in Annex I products (including machinery)

πŸ” What must a high-risk AI system address?

  • Risk management across the whole lifecycle, including risk assessment
  • Data quality β€” representative training data with as few errors as possible
  • Technical documentation and logging so that decisions can be traced
  • Human oversight β€” an operator must be able to understand and override the system
  • Accuracy, robustness and cybersecurity β€” resilient against manipulation of data or model
  • Post-market monitoring and reporting of serious incidents

The cybersecurity requirement links to the Cyber Resilience Act: a product that complies with the CRA is deemed to meet the AI Act’s cybersecurity requirement as well.


🏭 What does the AI Act mean for OT applications?

  • Industrial AI without a safety function β€” such as condition monitoring or energy optimisation: usually minimal risk
  • AI that lets a robot, cobot or AMR work safely alongside people β€” often high risk via Annex I
  • AI that decides on switching in a power grid or water treatment plant β€” high risk via Annex III
  • Everyone who deploys AI β€” has had to ensure sufficient AI literacy among staff since 2 February 2025

πŸ› οΈ How do you map your AI applications?

  1. Inventory all AI applications: developed in-house, purchased and embedded in machines or software
  2. Determine your role β€” are you a provider (you develop the AI system or place it on the market) or a deployer (you use it)? The heaviest obligations lie with the provider
  3. Classify the risk β€” is the AI a safety component of an Annex I product, or does the application fall under Annex III?
  4. Check for prohibited practices β€” for example emotion recognition of employees with cameras on the shop floor
  5. Ensure AI literacy β€” training for staff who work with AI, mandatory since 2 February 2025
  6. Plan for high risk β€” documentation, logging, human oversight and conformity assessment before the applicable deadline
Application Likely class
Vision system that rejects defective products Minimal risk
AI that stops a robot cell when a person comes too close High risk (Annex I, safety function)
AI that determines switching actions in a distribution grid High risk (Annex III)
Chatbot for fault reports Transparency obligation

❓ Frequently asked questions

When does the AI Act take effect?

The AI Act entered into force on 1 August 2024 and applies in phases. Prohibited practices have applied since 2 February 2025, rules for general-purpose AI models since 2 August 2025 and transparency obligations since 2 August 2026. After the digital omnibus, high-risk requirements apply from 2 December 2027 and 2 August 2028.

Is AI-based predictive maintenance high risk?

AI-based predictive maintenance is usually not a high-risk application under the AI Act, because it does not perform a safety function. The system advises on maintenance but does not itself decide on a machine’s safe state. The AI literacy obligation does apply to staff who work with it.

What is the difference between a provider and a deployer?

A provider develops an AI system, or has it developed, and places it on the market under its own name. A deployer uses an AI system within its own organisation. A plant using AI from a supplier is usually a deployer; a machine builder that integrates AI into its machine is a provider.

What is the AI Act digital omnibus?

The digital omnibus is an amending regulation that entered into force on 27 July 2026 and postponed the AI Act’s high-risk obligations. High-risk systems in Annex III must comply from 2 December 2027, and AI in Annex I products such as machinery from 2 August 2028. Other obligations were unchanged.

What fines does the AI Act impose?

The AI Act provides for fines of up to 35 million euros or 7% of worldwide annual turnover for prohibited practices. Failure to meet other obligations, such as the requirements for high-risk systems, carries fines of up to 15 million euros or 3% of turnover. Lower maximums apply to SMEs.


πŸ“Œ In summary

The AI Act regulates AI based on risk; in industry, AI mainly becomes high-risk when it performs a safety function in a machine or in critical infrastructure. After the digital omnibus, those high-risk requirements apply from 2 December 2027 (critical infrastructure) and 2 August 2028 (machinery).