The AI Act Slipped. The Machinery Deadline Didn't.

The digital omnibus pushed high-risk AI obligations out to December 2027, but the machinery regulation still lands in January 2027, and that gap is where the work sits.

Listen - AI recap

A laminated card, taped inside the door of a motor control centre, is one of the more useful objects in a processing plant. Program version. Download date. The initials of whoever last touched it, sometimes a printed checksum. Nobody legislated that card into existence. It's there because a PLC program nobody can account for is a safety problem, and the trade worked that out the hard way, over years, one bad shutdown at a time.

Two DIN rails over sits a fanless gateway running a model on the current signature of the same motor. No card. Ask which build is live and you get a filename with a date in it if you're lucky, a shrug if you're not. Nobody's being sloppy. Change control grew up around ladder logic and never got extended to the thing that learned its own thresholds.

The distance between those two cabinet doors is what the summer's legislating just made everyone's problem, and the coverage has mostly pointed the other way. On 29 June 2026 the Council gave its final green light to the digital omnibus on AI. Per the European Commission, the Annex III high-risk rules now apply from 2 December 2027, and rules for AI built into regulated products from 2 August 2028. Most write-ups rounded that to "two more years." For a plant, that's the wrong figure to walk away with.

One clock stopped, the other one didn't

The deferral moved the AI Act. It didn't move the machinery rules, and on a processing site the machinery rules are the ones stapled to a purchase order.

Regulation (EU) 2023/1230 replaced the old machinery directive, and per EU-OSHA it applies from 20 January 2027. That sits ten months ahead of the AI Act date everyone has just written into their calendar. Specifying a new depalletiser, a bagging line, an AGV fleet, a pick cell, a press with adaptive control? The machinery clock is the short one.

But the omnibus did something more consequential than shift a date, and this is the part worth reading twice. Products covered by the machinery regulation were carved out of the AI Act's direct applicability. In their place, the Commission gains power to add AI-specific health and safety requirements through secondary legislation under the machinery regulation itself. The same package sets up a way to pare the AI Act back wherever sectoral law already imposes similar AI-specific duties, covering medical devices, toys, lifts and watercraft on the same logic.

So the route changed, not merely the timing. For equipment, questions you'd have expected to answer through an AI Act conformity assessment are migrating into the machinery file: the technical documentation, the CE marking, the notified body where your conformity route needs one. Anyone who spent last year building an AI compliance workstream running parallel to their machinery workstream now has one workstream with a seam down the middle of it.

The extra time landed on the obligations, not on the equipment. Machinery placed on the EU market from 20 January 2027 has to be right the day it ships.

There's a trap in that sentence for end users who think machinery law is the OEM's problem. It usually is. But modify a machine substantially and you can inherit the manufacturer's duties yourself, which is old ground under machinery law and long predates any of this. Bolting a model onto an existing line is exactly the kind of change that invites the question. Reading a torque signal and displaying a health score on a screen won't trouble anyone. Writing back to the drive, changing the interlock logic, altering what the guarding was assessed against, and you're in a different conversation, one where the technical file with your name on it has to say what the model does. The line between those two cases is a wire, and the person who lands that wire is often a contractor working from a scope written before anyone thought about conformity.

The deferral didn't change your scope answer

Worth saying plainly, because the panic and the relief have both been overdone: a later date reclassifies nothing. Whatever your models were before 29 June, they still are. Annex III lists specific uses. Critical infrastructure appears on that list, which is why process engineers' inboxes filled up, but the entry aims at safety components in essential supply networks rather than at any factory that happens to run a model.

A vibration model that flags a developing outer-race defect on a slurry pump and raises an alarm on the HMI isn't a safety component of anything. Neither is a soft sensor estimating dryer moisture, nor a model predicting when a plate heat exchanger needs its next CIP from approach-temperature drift. They advise. A human decides.

What matters isn't whether a thing uses machine learning. It's whether its output moves anything on its own, and whether what it moves is protective. A model trimming a setpoint inside a permissive band is one animal. A model that can inhibit a trip, bias level control on a vessel sitting under a high-high interlock, or influence a safety-related valve is another animal entirely, and that one sat inside your functional safety assessment long before Brussels got involved.

Waste-to-energy operators should sit with this longer than food or metals colleagues. Export electricity to the grid or heat to a district network and you're nearer the supply-of-energy framing than a dairy is. The answer turns on the actual wording and on how your national authority reads it, which makes it a question for counsel with the text open rather than something to settle from a blog post. What I'll say with confidence is that the count of genuinely high-risk models on a typical site is smaller than the number of people currently worried about it, and separating the two is a morning's work.

What surprised us was the asymmetry

Walk into a site running a safety instrumented system and ask for the proof-test records. You'll get them. Ask for SIL verification calculations, the cause-and-effect matrix, the last function test on a high-high level switch, and it's filed, indexed, and someone can put a hand on it, because IEC 61511 put it there and auditors check.

Now ask the same site which version of the pump anomaly model is running on the gateway in the MCC room. What date range trained it. Whether anyone retrained after the impeller swap last autumn. Who acknowledged its last dozen alarms. The room goes quiet.

It isn't negligence and it isn't unusual. Models came in through a different door. Ladder logic arrived through engineering with a change process wrapped around it; models arrived through a pilot, often with real enthusiasm from operations, and pilots don't come with document control. So a plant with immaculate functional safety paperwork can be running a model that's been quietly biasing a setpoint for eight months, whose training data nobody can reconstruct, born in a notebook on a laptop that left with a contractor.

The physical layer makes it worse in a way that's easy to miss. These boxes get reimaged. A gateway dies on a Sunday, someone swaps in the spare from the store, flashes it from whatever image is on the share, and the line runs again by Monday morning (which is, to be fair, exactly the right call at 2 a.m.). Nothing records that the model on the replacement is two revisions behind the one that died. Industrial SD cards wear out, images drift, and the box that's been quietly running your dryer control since commissioning may not match anything anyone has on file. Ask to see the golden image for the edge fleet and watch what happens.

And read the high-risk obligations against that picture: they stop sounding like overreach. The Commission's summary asks for risk assessment and mitigation, data quality good enough to avoid bad outcomes, logging of activity for traceability of results, documentation sufficient to understand the system, clear information to the deployer, genuine human oversight, and a high level of accuracy and cyber-resilience. Strip the legal register off and you have a maintenance engineer describing a model worth trusting at three in the morning.

You already own most of the machinery for this

When a regulation lands, the instinct is to buy a governance platform. Resist that for a quarter. Nearly every item on the list has an analogue already running on your site, and extending what exists beats standing up something parallel that operations will route around by March.

What the obligation asks forWhat you already runWhat's actually missing
Logging for traceability of resultsThe historianModel output lands as a bare tag. No version, no input vector, no confidence.
Data quality and governanceTag dictionary, calibration records, NAMUR NE 107 statusNothing ties a training set to which instruments were in calibration at the time.
Human oversightAlarm rationalisation, operator response proceduresModel alarms skipped rationalisation, and overrides go unrecorded.
Technical documentationFDS, FAT and SAT packs, as-builtsThe model has no functional design spec, so there's nothing to test it against.
Accuracy and cyber-resilienceIEC 62443 zones and conduits, patch processGateways get commissioned into a zone, then drift outside the patch cycle.
Obligation wording follows the European Commission's published summary of high-risk requirements under the AI Act; the plant-side mapping is the author's.

Read down that third column and notice what it isn't. None of it is legal work. It's tag configuration, naming discipline, a change process, and somebody deciding a model gets the same treatment as a control narrative. A competent controls engineer with a clear brief closes most of that column. No lawyer can close any of it.

The logging row is the one that draws the most argument, usually on storage grounds, and the argument is generally wrong. Nobody's asking you to write a model version string alongside every sample at one-second scan. You log a run identifier with the output tag, and you log a change event whenever the deployment changes: new version, new training set, new threshold, who approved it. The run identifier costs a handful of bytes per sample against a float you're already storing; the change events amount to a few rows a year on a stable asset. Traceability comes from being able to join those two, not from duplicating metadata into every row. Any historian worth its licence handles this, and if yours can't, the constraint is the tag naming convention rather than the disk.

The calibration row is the subtle one. A model trained across a window when a temperature transmitter was reading two degrees low has learned that offset as physics. Recalibrate the transmitter and the model's world quietly shifts underneath it, which shows up months later as drift nobody can explain. Keeping calibration history joinable to training windows isn't a compliance nicety. It's the difference between a model you can debug and one you re-train blind and hope.

Spending the runway

Sixteen months to the Annex III date, two years to the embedded-product one. That's enough time to do this properly and far too much to start in month fourteen. Roughly the order we'd sequence it.

Inventory by cabinet, on foot. Every model, where it physically runs, what it reads, what it writes. That last column is the one that counts, because writing is what turns a curiosity into a compliance question. Do it walking. Asset registers lie about edge hardware, and the gateway somebody added during a shutdown is never in the register. Expect to find at least one box nobody can name an owner for; that's normal, and finding it is the point of the exercise.

Then draw the advisory line and write it down. Each model gets one of two labels: it advises a human, or its output reaches a control or protective function. That single classification drives risk assessment depth, documentation depth, and whether functional safety needs to be in the room. Err cautious and it costs paperwork. Err the other way and it costs considerably more than paperwork.

Pin versions into the record. Where the historian logs a model output, it should log the run identifier beside it, same row, same timestamp. Highest-value change on this list, and usually a day's work on the edge telemetry and analytics platform plus a naming convention. Skip it and every other obligation becomes unanswerable after the fact, because you can't explain a decision when you can't say what made it.

Put the procurement questions in writing now, because machinery lands in January 2027. Ask the OEM at quotation stage: does this machine contain AI-based functions, are any safety-related, what's in the technical file about them, and what happens to your conformity assessment when a firmware update changes model behaviour? That last one catches people. Vendors who've thought it through answer crisply. The ones who haven't tell you a great deal by how they don't.

Buying rather than building shifts which obligation bites hardest, and the one to watch is the duty to give the deployer clear information about the system. Plenty of process skids now ship with a model inside: a CIP unit that predicts rinse endpoint, a separator that trims its own discharge interval, a burner management package with adaptive tuning. Ask what the model was trained on and whether that training reflects your feedstock. A separator model tuned on someone else's solids loading is a reasonable starting point and a poor final answer. The useful question at the factory acceptance test isn't whether the model works, but what it does when the input drifts outside anything it saw in training, and whether it says so or just keeps producing confident numbers.

And rationalise model alarms like any other alarm. If an operator can't say what to do when the anomaly score crosses its threshold, human oversight is a checkbox, not a control. Give it a response procedure, a priority, and somewhere to record that a person looked and disagreed. Recorded disagreement is training data. It's also your evidence that the oversight was real, which is the thing an auditor will actually ask to see.

The quiet cost of a longer runway

One risk in a deferral rarely gets mentioned. A deadline concentrates attention, and pushing this one out by sixteen months removes the forcing function at precisely the moment most sites are scaling from three pilot models to thirty. The fleet grows either way. What changes is whether it grows with a naming convention and an owner, or as an accumulation of boxes installed by four different integrators across two shutdowns, each with its own idea of what a tag should be called.

Staff turnover does the rest. The engineer who built the first model and knows why the threshold sits where it does moves on, and the tribal knowledge that substituted for documentation goes with them. A runway this long is enough for that to happen more than once on a busy site. So the practical argument for doing the work now has nothing to do with December 2027 and everything to do with the fact that retrofitting provenance onto thirty undocumented models costs several times what building it into three costs today.

The reason to do it even if none of it applies

Say the scope question comes back the way it will for most food, beverage and metals sites: nothing on the floor is Annex III high-risk, the machinery you buy is the OEM's conformity problem, and December 2027 passes without touching you. Was the work wasted?

No, and not for a compliance reason. A model you can version, whose inputs trace to calibrated instruments, whose alarms carry response procedures, and whose disagreements with operators get written down, is a model that survives contact with the plant. The other kind gets ignored within two shifts of its first bad week, then quietly unplugged inside a year. Everyone in this trade has watched that happen at least once. The regulation is simply the first outside body to write down what makes the difference, and on that point it's right.

The card inside the cabinet door didn't come from a regulation either. It came from engineers who got tired of not knowing what was running. Print one for the gateway. Tape it to the door.

Notes

This is an engineer's reading of what the timing change means for plant work, not legal advice. Scope under Annex III turns on the actual text and on how your national authority applies it, so get counsel with the regulation open before concluding a given model is in or out. Two limits worth stating: the omnibus was adopted on 29 June 2026 and enters into force shortly after publication in the Official Journal, so the secondary legislation carrying AI-specific health and safety requirements under the machinery regulation doesn't exist yet, and nobody can responsibly predict its content. The obligation-to-artefact mapping above is general, and not every site will recognise all five rows. Waste-to-energy operators exporting power or district heat, and anyone whose models touch a protective function, should treat the scope question as genuinely open rather than settled.

References

  1. Artificial intelligence: Council gives final green light to simplify and streamline rules (Council of the EU, 29 June 2026)
  2. AI Act - regulatory framework for AI (European Commission, Shaping Europe's digital future)
  3. Regulation (EU) 2023/1230 on machinery (EU-OSHA legislation summary)

Reuse & license

This article is published by Zoniax Innovations LLC under a Creative Commons Attribution 4.0 International (CC BY 4.0) license. You are free to share and adapt it for any purpose, including commercially, as long as you give appropriate credit to Zoniax and link back to the original article.

Disclaimer

These Field Notes are general technical information, published as-is for industry peers. They are not professional, engineering, safety, legal, or financial advice, and nothing here is a recommendation to buy, sell, or act. Figures are cited from public sources believed reliable but are not independently guaranteed - verify them against the primary sources and your own plant conditions before acting. Zoniax Innovations LLC and the author accept no liability for decisions made from this content. Naming a standard, product, or vendor is not an endorsement.

Cite this article

Nõmm, A. (2026). The AI Act Slipped. The Machinery Deadline Didn't.. Zoniax. https://zoniax.com/blog/posts/ai-act-high-risk-deferral-machinery-plants