1. What has applied since 2 August 2026 - and what the Omnibus deferred

The EU AI Act - formally Regulation (EU) 2024/1689 - has been applicable in its essential parts since 2 August 2026. Three weeks before that date the EU rebuilt the timetable once more: the Digital Omnibus Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026, defers the obligations for high-risk systems, softens the AI literacy duty and also amends the Machinery Regulation. Anyone working from a 2025 timeline is working from the wrong dates.

ObligationApplies since / fromChange by the Omnibus
Prohibited practices (Article 5), AI literacy (Article 4)2 February 2025Article 4 rewritten: take measures instead of ensuring a level
Obligations for general-purpose AI models (Chapter V)2 August 2025unchanged
General application: transparency (Article 50), governance, penalties (Article 99)2 August 2026unchanged; marking duty under Article 50(2) for legacy systems only from 2 December 2026
High-risk systems under Annex III (including employment decisions)2 December 2027deferred, previously 2 August 2026
High-risk systems under Annex I (AI as a safety component of products)2 August 2028deferred, previously 2 August 2027; machinery additionally moved to Section B (see section 3 of this article)

Dates under Article 113 of the AI Act in the consolidated version of 27 July 2026. The high-risk dates are fixed calendar dates; the link to the availability of harmonised standards proposed by the Commission in November 2025 did not become law.

The pressure to act is real, but distributed differently from what many summaries suggest. According to Bitkom (survey of 603 German companies with 20 or more employees, published 14 September 2026), 37 percent of companies expect to be affected by the AI Act as users; of those, 89 percent expect a high implementation effort, and 66 percent of all respondents see more disadvantages than advantages in the AI Act. The figure missing from this debate is the second role: only 1 percent of companies saw themselves affected as a provider in the Bitkom study report of February 2026. In mechanical and plant engineering that share is likely to be far higher - every manufacturer that builds AI into its controls or ships an assistant under its own brand belongs to it.

2. Provider or deployer: the roles of the AI Act

The AI Act distributes its obligations not by industry but by role in the value chain. Article 3 defines four roles, and two of them decide almost everything in machinery manufacturing:

RoleDefinition (Article 3, abridged)Typical case for a machinery manufacturer
Provider (point 3)develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademarkAI in the machine shipped to customers; assistant in the customer portal; self-built internal assistant
Deployer (point 4)uses an AI system under its own authority, except in a personal non-professional activitypurchased AI assistant in service, AI tools in engineering, sales, office
Importer (point 6)places an AI system from a third-country provider on the EU marketcontrol component with AI from Asia or the US imported under that supplier’s brand
Distributor (point 7)makes an AI system available in the supply chain without being the provider or importersales partner passing on an AI component unchanged

Terms under Article 3 of the AI Act, Regulation (EU) 2024/1689. The classification does not depend on who trained the model, but on who hands the system to whom under which name.

Two misunderstandings regularly cost time in conversations with machinery manufacturers. First: the deployer of the AI Act (German: Betreiber) is not the plant operator of occupational safety law and not the works council - it is simply any organisation that uses an AI system professionally. Second: the role attaches to the system, not to the company. The same firm is a provider for the AI in its machine and a deployer for the assistant in its service department - and must run both sets of obligations separately. This distinction is missing from almost every overview written for the machinery industry.

3. Role 1: the machinery manufacturer as provider - AI inside the machine

Whether AI inside a machine falls under the high-risk rules is decided by Article 6(1) with two conditions that must both be met: the AI system must be used as a safety component of a product covered by Annex I (or be such a product itself), and that product must be subject to a third-party conformity assessment. The Omnibus sharpened the notion of a safety component: a component performs a safety function if its intended purpose is to prevent or reduce risks to the health and safety of persons or property (Article 3(14)). And the new Article 6(1a) clarifies what is not a safety component: AI used solely for user assistance, performance optimisation, efficiency, automation, user convenience or quality control - unless its failure would endanger health and safety.

That makes the circle narrower than the debate of recent years suggested. A vision model that classifies surface defects, or an AI-based parameter optimisation, is not a high-risk system. The case is different for what the Machinery Regulation (EU) 2023/1230 names explicitly in Annex I Part A: safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions (point 5) and machinery with corresponding embedded systems (point 6). For these categories the Machinery Regulation prescribes a conformity assessment by a notified body from 20 January 2027 - which satisfies both conditions of Article 6(1).

The point most overviews do not yet contain: the Omnibus moved the Machinery Regulation in Annex I from Section A to Section B (point 21). For products in Section B, Article 2(2) means only the classification as a high-risk system still applies, not the whole of Chapter III with its provider obligations. Instead, the Commission must adopt delegated acts adding requirements for high-risk AI directly to Annex III of the Machinery Regulation - they are to reflect the substance of the AI Act and apply by 2 August 2028 at the latest (Article 8 of the Machinery Regulation as amended). Until machinery-specific standards exist, harmonised standards under the AI Act also confer the presumption of conformity under the Machinery Regulation (Article 20(10)). In practice this means one conformity assessment under machinery law instead of two parallel procedures. The VDMA, the German mechanical engineering association, calls the deferred high-risk deadlines for machinery a core demand of the association that has been met.

Three things remain despite the relief. The Machinery Regulation itself sets requirements for control systems with self-evolving behaviour from 20 January 2027 - independently of the AI Act. No harmonised standards under the AI Act have been listed in the Official Journal so far; CEN and CENELEC adopted an accelerated procedure in October 2025 and are aiming for first publications at the end of 2026. And the Commission’s guidelines on high-risk classification under Article 6(5), due on 2 February 2026, exist to this day only as a draft from May 2026. Anyone developing a learning safety component is therefore currently designing against the text of the regulation, not against a standard - and should build the technical documentation accordingly. How closely documentation and AI obligations are already converging is visible in the digital instructions for use from 2027.

4. Role 2: the machinery manufacturer as deployer - AI in service, sales and the office

The second role affects practically everyone: according to Bitkom, 57 percent of companies now use AI, and 22 percent use it for internal knowledge management - twice as many as the year before. An AI assistant that gives service technicians answers from the company’s own documentation, a translation tool in technical writing or an assistant in sales all make the company a deployer. And for deployers of AI systems that are not high-risk, the catalogue of obligations is short. It has two entries and two traps.

4.1 The two obligations

  1. AI literacy (Article 4), since 2 February 2025. Providers and deployers must take measures to support the AI literacy of their staff. The original version required ensuring a sufficient level; the Omnibus turned this into a duty to take measures and states expressly that no particular level has to be guaranteed. The Commission makes clear in its questions and answers: no certificate is needed, an internal record of trainings and guidelines suffices. What does not suffice is nothing: according to the Bitkom study report, 43 percent of companies have so far trained nobody in the use of AI, and only 8 percent all employees. For a service technician, literacy means concretely: knowing that the assistant answers from documents and not from its own knowledge, knowing how to check the source, and knowing when not to trust it.
  2. Transparency (Article 50), since 2 August 2026. Whoever provides an AI system intended to interact directly with natural persons must ensure that users learn they are interacting with an AI - unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person. The duty falls on the provider; a deployer who has purchased the assistant should make sure in the contract that the supplier meets it. The Regulation contains no exemption for purely internal systems used only by employees. In practice, for a tool clearly labelled as AI, a note in the interface is enough.

4.2 The two traps

The first trap is the purpose. An assistant that answers questions about machines does not fall under Annex III. But as soon as it evaluates the performance and behaviour of employees or allocates tasks based on individual behaviour, it sits in Annex III point 4(b) - and becomes a high-risk system with full deployer obligations under Article 26 from 2 December 2027: use in accordance with the instructions for use, human oversight by trained persons, retention of logs for at least six months, and informing workers’ representatives and the affected employees before putting it into service at the workplace. A dashboard that derives from the assistant’s logs which technician asks the most questions or generates the most follow-ups is exactly this case. The boundary between the short and the long catalogue of obligations lies on the path from knowledge system to performance measurement.

The second trap is sharper and already live: Article 5(1)(f) has prohibited AI systems that infer the emotions of natural persons in the workplace since 2 February 2025, except for medical or safety reasons. A sentiment analysis over hotline calls or technician chats, of the kind some service tools offer as an add-on, is therefore not a compliance topic but a prohibited practice - carrying the highest fine bracket in the Regulation.

What is not on the list matters just as much. A fundamental rights impact assessment (Article 27) is owed only by public bodies and certain financial and insurance providers, never by a private machinery manufacturer. The obligations for general-purpose AI models (Chapter V) sit with the model provider, not with whoever uses a system built on it. And the GDPR continues to apply alongside the AI Act - the question of where service data is processed and whether it feeds a training run is settled in the contract, not in the AI Act. Which questions must be answered there is set out in the buyer’s checklist for AI assistants in service.

5. When a deployer becomes a provider

The roles are not static. Article 25(1) names three routes by which a distributor, importer, deployer or other third party becomes the provider of a high-risk system and takes over the provider obligations under Article 16: putting their name or trademark on a high-risk system already placed on the market; making a substantial modification to it; or changing the intended purpose of an AI system - expressly including a general-purpose AI system - in such a way that it becomes a high-risk system. The third route is the one that happens unnoticed in daily operations: a purchased knowledge system is extended by an analysis that measures technician performance - and the deployer is now the provider of a high-risk system, whose original manufacturer under Article 25(2) only has to hand over documentation, known limitations and technical access.

But the role change is not limited to high-risk, and many summaries miss this. Under Article 3(3), a provider is also whoever develops an AI system or has it developed and puts it into service - and putting into service under Article 3(11) expressly includes supply for own use. Whoever builds their own service assistant, even on a third-party language model, is therefore provider and deployer in one and carries the transparency duty under Article 50 themselves. The same applies to anyone who puts an assistant under their own brand into a customer portal: the provider is the one whose name is on it, not the one who trained the model.

ScenarioRoleWhat attaches to it
Purchased AI assistant for your own service teamDeployerArticle 4; secure transparency and data sovereignty contractually with the supplier
Self-built assistant, even on a third-party modelProvider and deployeradditionally Article 50(1) and (2) under your own responsibility
Assistant under your own brand in the customer portalProviderArticle 50; not high-risk as long as there is no Annex III intended purpose
Assistant evaluates technician performance or allocates jobs by behaviourDeployer of a high-risk system; provider if you changed the purpose yourself (Article 25(1)(c))Article 26 from 2 December 2027; possibly Article 16 provider obligations
Learning safety component in your own machineManufacturer under the Machinery Regulation, provider under Article 6(1)third-party conformity assessment from 20 January 2027; AI requirements via Annex III of the Machinery Regulation by 2 August 2028
Third-party AI module integrated into the machine under your own nameas aboveadditionally a written agreement with the supplier on information and access (Article 25(4))

Our reading based on the consolidated legal texts, not legal advice. The intended purpose you document decides the row - which is why it is the first document any supervisory authority wants to see.

6. Penalties and supervision: who is responsible in Germany

Article 99 grades the fines in three tiers: up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices, up to 15 million euros or 3 percent for infringements of the obligations of providers and deployers including the transparency obligations, up to 7.5 million euros or 1 percent for incorrect information supplied to authorities - in each case whichever is higher. For small and medium-sized enterprises the lower amount applies in all three tiers (Article 99(6)); the Omnibus extended this cap to small mid-caps, but only for the two lower tiers. Article 4 does not appear in the list of fines; Member States must nevertheless lay down penalties for any infringement of the Regulation, and the Commission notes that national authorities can sanction infringements of Article 4.

In Germany, supervision has been settled since the summer - late, but settled. The Act on Market Surveillance and Innovation Promotion of Artificial Intelligence (KI-MIG) of 22 July 2026 entered into force on 29 July 2026, four days before general application began. It makes the Federal Network Agency (Bundesnetzagentur) the market surveillance authority and single point of contact; its AI Service Desk with the AI Compliance Compass is the first address for classifying roles. For AI in machinery the familiar pattern remains: market surveillance of products lies with the authorities designated under state law, as a rule the occupational safety and trade supervisory authorities of the German states. Whether and how the KI-MIG already reflects the move of the Machinery Regulation to Annex I Section B is, on our reading, open - the act was promulgated two days after the Omnibus. Germany was not alone in being late: the deadline for designation was 2 August 2025, and according to the European Parliamentary Research Service only 8 of 27 Member States had notified a single point of contact by March 2026.

7. Five steps to take now

The effort depends almost entirely on which rows of the table in section 5 you occupy. The sequence that has proven itself therefore does not begin with training, but with a list.

  1. Build an inventory of all AI systems - with roles. Every system used in-house or shipped with the machine, with intended purpose, supplier, user group and the role the company takes for it. The inventory is the basis for everything else and the first question of any authority.
  2. Set down and narrow the intended purpose in writing. A knowledge system whose purpose is documented as answering technical questions from the documentation stays outside Annex III - as long as nobody turns it into performance measurement. That boundary belongs in the concept, in the usage rules and in the contract with the supplier.
  3. Implement and document Article 4 measures. Short, role-specific training for the user groups, a usage policy, a folder of evidence. For service technicians: how the assistant answers, how to check sources, what it cannot do. No certificate, no academy - but proof that something has happened.
  4. Bring transparency and data sovereignty into the supplier contract. Who fulfils Article 50? Where is data processed, does it feed a training run, what documentation does the provider deliver if the intended purpose changes (Article 25(2) and (4))? These questions cost nothing at the offer stage and a great deal later.
  5. Plan the Machinery Regulation path for learning safety functions. Whoever develops machine learning in a safety function needs a notified body from 20 January 2027 and, by 2 August 2028, technical documentation that carries the coming AI requirements of the Machinery Regulation. Since standards and guidelines are missing, documenting your own risk management is currently the only evidence.

8. When the AI Act is (almost) a non-issue for you

Honesty is part of it, so here is the other direction. For a considerable share of machinery manufacturers, the AI Act is today a manageable task - under three conditions:

  1. Nothing in your machines learns while carrying a safety function. Classic controls, rule-based safety technology and AI that merely optimises, assists or checks quality trigger neither Annex I nor the new categories of the Machinery Regulation. Then you are not a provider within the meaning of the high-risk rules for your products.
  2. You use AI only as purchased and only for knowledge, text and images - not for people. No evaluation of employees, no allocation by behaviour, no emotion analysis, no candidate screening. Then you are a deployer without a high-risk system, and the catalogue of obligations ends with Article 4 and a clean supplier contract.
  3. You pass nothing on to customers under your own name. As long as the assistant stays internal and is provided by the supplier under the supplier’s brand, the provider obligations stay with the supplier.

Whoever meets all three conditions needs no compliance programme, but an afternoon: inventory, intended purpose, training record, contract review. The effort begins where the three conditions tip - and that rarely happens through a decision, but through a feature someone switches on later.

9. Frequently asked questions

Is an internal AI assistant for service technicians a high-risk system?

Usually not. An assistant that answers questions about machines from the company's own documentation falls under neither Annex I (safety component of a product) nor Annex III of the AI Act. It becomes high-risk only when its intended purpose slips into an Annex III area - for instance when it evaluates the technicians' performance or allocates jobs based on individual behaviour (Annex III point 4(b)). Those obligations apply from 2 December 2027.

Does the assistant have to tell technicians they are talking to an AI?

The transparency obligation in Article 50(1) falls on the provider of an AI system intended to interact directly with natural persons - employees included. It lapses only where the AI nature is obvious to a reasonably well-informed person. For a tool clearly labelled as an AI assistant that is usually the case; a note in the interface costs nothing and ends the discussion. Whoever builds the assistant themselves carries this obligation themselves.

Do we need a certificate for AI literacy under Article 4?

No. The European Commission's questions and answers on Article 4 state explicitly that no certificate is needed; an internal record of the measures is enough. Since the Digital Omnibus, Article 4 also only requires taking measures to support AI literacy - no longer guaranteeing a particular level. What remains is the duty to do something at all and to be able to show it.

Do we become a provider if we offer the assistant to our customers too?

Yes. Whoever places an AI system on the market under their own name or trademark is a provider within the meaning of Article 3(3) - regardless of who developed the language model behind it. For an assistant without a high-risk intended purpose the provider obligations are manageable (above all transparency under Article 50 and AI literacy under Article 4), but they then sit with you, not with the technology supplier.

Does 2 August 2028 apply to every AI in our machines?

No. High-risk under Article 6(1) is only AI that performs a safety function as a safety component and whose product is subject to third-party conformity assessment - for machinery, typically safety components with self-evolving behaviour under Annex I Part A of the Machinery Regulation. AI that serves only operator assistance, performance optimisation, automation or quality control is expressly not a safety component under Article 6(1a). And since the Omnibus, the concrete requirements no longer come from the AI Act itself but reach the Machinery Regulation through delegated acts.

10. Sources

Legal texts in their consolidated versions, studies with survey data. Studies by vendors and associations with an interest of their own are marked as such. Several sources are in German; the English article cites them because they are the actual evidence.


The AI Act does not ask whether you are a machinery manufacturer, but what you do with which system under whose name. Whoever answers that question cleanly once for every system will find that most of the effort sits in two rows of a table - and that the rest is an afternoon. And whoever, looking at the inventory, notices that a feature is currently pushing the knowledge system into performance measurement has read this article at the right moment.