Independent EU AI Act information resourceLegal text verified against EUR-Lex

Sector guide

The EU AI Act for manufacturing and infrastructure

Industrial AI is reached through the product-safety route rather than Annex III — and this is the sector the 2026 amendment changed most, by narrowing what counts as a safety component and moving machinery to a sectoral approach.

What the Act actually names in this sector

These are the provisions that reach manufacturing and infrastructure, quoted from the Official Journal. Everything below follows from them.

  • Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity
    Annex III, 2 →
  • AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components
    Article 6(1a) →

Common use cases, classified

High-risk

Permitted, but carries the full Chapter III obligations: risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity.

  • Safety function in machinery or a product

    A safety component of a product covered by the Annex I legislation, where that product needs third-party conformity assessment, is high-risk.

    The Digital Omnibus moved the machinery regulation from Section A to Section B of Annex I and inserted Article 6(1a) to (1c), which narrow what counts as a safety component.

    Article 6(1) with Annex I →
  • Managing critical infrastructure

    Point 2 names safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity.

    Annex III, 2 →

Depends on the detail

The Act does not settle this from the description alone. The note says what decides it.

  • Predictive maintenance and quality control

    Article 6(1a), inserted by the 2026 amendment, states that systems used solely for non-safety aspects such as performance optimisation, automation or quality control do not qualify as safety components.

    Article 6(1b) pulls it back in where failure or malfunction would endanger health and safety.

    Article 6(1a) →

What gets misread here

Over-classification is the quieter failure: treating something as high-risk when the Act carves it out costs real money and never triggers a complaint, so nobody catches it.

  • “Anything on the factory floor is a safety component.”

    Article 6(1a), inserted by the Digital Omnibus, excludes systems used solely for performance optimisation, automation or quality control. Article 6(1b) pulls back in anything whose failure would endanger health and safety.

    Article 6(1a) →
  • “Machinery AI follows the same route it did in 2024.”

    The Omnibus moved the machinery regulation from Section A to Section B of Annex I, limiting the AI Act's application to those machines and relocating the requirements into the machinery regulation itself.

    Digital Omnibus →

Dates that matter in this sector

  • 2 Aug 2028Annex I product-safety high-risk obligations apply — AI systems that are safety components of products already regulated under EU harmonisation law (medical devices, machinery, vehicles, lifts, toys and the rest of Annex I) come into scope on 2 August 2028. (date changed by the Omnibus)

Dates are as amended by the Digital Omnibus. See the full timeline for what each one covers.

What the Commission has said

These guidelines are not binding, but they are the Commission’s own reading of the provisions above, and they are the first place a supervisory authority will look. Where they and this guide differ, follow them.

What to do next

Screen your own systems with the scope finder, run a single system through the risk classifier, or work the obligations in order with the checklist.

This guide points you at the provisions that govern your sector. It is not legal advice, and whether a particular system meets a provision turns on facts about that system and on whether you hold it as provider or deployer — see Article 3 and Article 25.