What is the AI Act?
The AI Act, Regulation (EU) 2024/1689, is the European law that sets requirements for artificial intelligence based on the risk an AI system poses: the higher the risk to safety or fundamental rights, the heavier the obligations. For industry the law is mainly relevant when AI performs a safety function in a machine or installation. Applications such as predictive maintenance or visual quality inspection usually fall into a lower risk class.
π§ What risk classes does the AI Act define?
| Risk class | Examples | Consequence |
|---|---|---|
| Unacceptable | Social scoring, emotion recognition in the workplace | Prohibited |
| High risk | AI as a safety component of a machine (Annex I); AI in critical infrastructure (Annex III) | Strict requirements, conformity assessment, CE |
| Transparency | Chatbots, AI-generated content | Inform the user |
| Minimal | Predictive maintenance, process optimisation without a safety function | No specific requirements |
Two high-risk routes matter for industry. Annex I covers AI in products already subject to EU product legislation, such as the Machinery Regulation. Annex III lists AI used as a safety component in the management of critical infrastructure such as water, gas, electricity and traffic.
ποΈ When do the obligations apply?
The digital omnibus (in force since 27 July 2026) postponed the high-risk obligations:
| Date | What applies |
|---|---|
| 1 August 2024 | Entry into force |
| 2 February 2025 | Prohibited practices and AI literacy |
| 2 August 2025 | Rules for general-purpose AI models |
| 2 August 2026 | Transparency obligations (Article 50) |
| 2 December 2027 | High-risk systems in Annex III (including critical infrastructure) |
| 2 August 2028 | High-risk AI in Annex I products (including machinery) |
π What must a high-risk AI system address?
- Risk management across the whole lifecycle, including risk assessment
- Data quality β representative training data with as few errors as possible
- Technical documentation and logging so that decisions can be traced
- Human oversight β an operator must be able to understand and override the system
- Accuracy, robustness and cybersecurity β resilient against manipulation of data or model
- Post-market monitoring and reporting of serious incidents
The cybersecurity requirement links to the Cyber Resilience Act: a product that complies with the CRA is deemed to meet the AI Actβs cybersecurity requirement as well.
π What does the AI Act mean for OT applications?
- Industrial AI without a safety function β such as condition monitoring or energy optimisation: usually minimal risk
- AI that lets a robot, cobot or AMR work safely alongside people β often high risk via Annex I
- AI that decides on switching in a power grid or water treatment plant β high risk via Annex III
- Everyone who deploys AI β has had to ensure sufficient AI literacy among staff since 2 February 2025
π οΈ How do you map your AI applications?
- Inventory all AI applications: developed in-house, purchased and embedded in machines or software
- Determine your role β are you a provider (you develop the AI system or place it on the market) or a deployer (you use it)? The heaviest obligations lie with the provider
- Classify the risk β is the AI a safety component of an Annex I product, or does the application fall under Annex III?
- Check for prohibited practices β for example emotion recognition of employees with cameras on the shop floor
- Ensure AI literacy β training for staff who work with AI, mandatory since 2 February 2025
- Plan for high risk β documentation, logging, human oversight and conformity assessment before the applicable deadline
| Application | Likely class |
|---|---|
| Vision system that rejects defective products | Minimal risk |
| AI that stops a robot cell when a person comes too close | High risk (Annex I, safety function) |
| AI that determines switching actions in a distribution grid | High risk (Annex III) |
| Chatbot for fault reports | Transparency obligation |
β Frequently asked questions
When does the AI Act take effect?
The AI Act entered into force on 1 August 2024 and applies in phases. Prohibited practices have applied since 2 February 2025, rules for general-purpose AI models since 2 August 2025 and transparency obligations since 2 August 2026. After the digital omnibus, high-risk requirements apply from 2 December 2027 and 2 August 2028.
Is AI-based predictive maintenance high risk?
AI-based predictive maintenance is usually not a high-risk application under the AI Act, because it does not perform a safety function. The system advises on maintenance but does not itself decide on a machineβs safe state. The AI literacy obligation does apply to staff who work with it.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has it developed, and places it on the market under its own name. A deployer uses an AI system within its own organisation. A plant using AI from a supplier is usually a deployer; a machine builder that integrates AI into its machine is a provider.
What is the AI Act digital omnibus?
The digital omnibus is an amending regulation that entered into force on 27 July 2026 and postponed the AI Actβs high-risk obligations. High-risk systems in Annex III must comply from 2 December 2027, and AI in Annex I products such as machinery from 2 August 2028. Other obligations were unchanged.
What fines does the AI Act impose?
The AI Act provides for fines of up to 35 million euros or 7% of worldwide annual turnover for prohibited practices. Failure to meet other obligations, such as the requirements for high-risk systems, carries fines of up to 15 million euros or 3% of turnover. Lower maximums apply to SMEs.
π In summary
The AI Act regulates AI based on risk; in industry, AI mainly becomes high-risk when it performs a safety function in a machine or in critical infrastructure. After the digital omnibus, those high-risk requirements apply from 2 December 2027 (critical infrastructure) and 2 August 2028 (machinery).
