EU Agrees Embedded Tech Regulatory Changes

  • July 21, 2026
  • William Payne

The EU has addressed an escalating problem with its AI Act which threatened to paralyse industrial and smart tech deployments across multiple key sectors in Europe. The Digital Omnibus on AI Act, agreed by the European Parliament on June 16, has carved out exemptions and deferrals from the EU’s AI Act for embedded systems across manufacturing, industrial systems, energy grids, buildings and construction, mining, logistics and smart ports.

Yet the new exemptions and deferrals are creating a complex, sprawling network of sector-specific requirements, and in some cases embedded and smart technologies now face far shorter compliance deadlines.

The crisis has been caused by the European AI Act requiring embedded and smart systems to comply with a new set of technical standards by an August 2, 2026 deadline. However, European standards bodies have failed to deliver the new required standards before the deadline, leaving embedded tech and IoT providers and users placed in an impossible situation.

Facing a hard August 2026 deadline for high-risk systems without the required harmonised technical standards, the framework has risked paralysing industrial deployment across manufacturing, energy grids, construction, logistics and other sectors.

However, while the Digital Omnibus defers the most onerous high-risk compliance dates to 2027 and 2028, it is not a deregulatory reprieve. Instead, it has reallocated the compliance burden, reassigning what had been cross sector horizontal rules into a complex matrix of sector-specific mandates. Crucially, it has added immediate transparency obligations.

Solving the Pacing Problem

The original architecture of the EU AI Act created a regulatory bottleneck, widely characterised as a pacing problem. Under the initial framework, systems integrated as safety components into industrial equipment or critical infrastructure were classified as high-risk, subject to stringent ex-ante compliance mandates scheduled for 2 August 2026.

However, European standard-setting organisations, such as CEN-CENELEC, have failed to deliver the harmonised technical standards required to prove conformity. This has left developers facing an operational catch-22: a legal obligation to comply with technical guidelines that did not yet exist.

The Digital Omnibus resolves this impasse through a staggered deferral mechanism.

It decouples the hard 2026 deadline, extending enforcement to December 2, 2027 for stand-alone high-risk systems under Annex III, and to 2 August 2028 for AI embedded in products governed by Annex I safety legislation.

The Omnibus also mandates the expansion of regulatory sandboxes, allowing for controlled, real-world testing environments, and extends compliance relief previously reserved for SMEs to small mid-cap (SMC) enterprises.

This recalibration shifts the regulatory stance from a rigid, compliance-first model to a more pragmatic framework, acknowledging that ex-ante regulation of dynamic systems requires mature technical standards before enforcement can realistically begin.

Machinery & Self Evolving AI

For industrial equipment operators and manufacturers, the most important structural shift of the Digital Omnibus is granting a new status for equipment that fall under the EU Machinery Regulation (EU) 2023/1230.

To avert the threat of dual-certification, the Omnibus carves machinery out of the AI Act’s direct high-risk purview. Instead, AI-related health and safety requirements for these products will be governed by sectoral product legislation.

However, the Machinery Regulation’s definition of ‘machinery’ is expansive. It captures not only complete physical assemblies but also interchangeable equipment and, crucially, software functioning as a safety component. The regulatory pivot hinges on the treatment of self-evolving systems.

Under Annex I of the Machinery Regulation, any safety component or embedded system exhibiting fully or partially self-evolving behaviour via machine learning is subject to mandatory third-party conformity assessment. For example, an industrial algorithm that continuously updates its collision-avoidance parameters based on real-time sensor data falls into this category. So while the Omnibus spares manufacturers the immediate burden of horizontal AI Act compliance, it does not eliminate the regulatory friction. It merely relocates it. Industrial AI systems that learn and adapt autonomously must still navigate a rigorous, sector-specific audit regime to prove their operational safety.

Implications for Industrial IoT

For manufacturers of Industrial Internet of Things (IIoT) devices, the original AI Act presented a significant barrier to deployment: the prospect of dual certification. A connected robotic arm or a predictive manufacturing line would have required conformity assessments under both the Machinery Regulation for physical safety and the AI Act for software safety. The Digital Omnibus removes this dual-track regime, offering a structural reprieve that alters compliance for edge AI.

A important consequence for IIoT is the clarification surrounding narrow-use exemptions and the precise definition of a ‘safety component’.

Under the revised framework, AI systems deployed solely for non-safety-related user assistance, performance optimisation, service efficiency, or quality control do not automatically qualify as safety components. Consequently, edge AI applications performing routine industrial tasks, such as vibration analysis, anomaly detection, and predictive maintenance, will largely bypass the onerous documentation and registration burdens associated with the high-risk perimeter.

However, caution is required about the boundaries of these exemptions. Classification is dictated by the realistic failure mode of the system, not its commercial positioning. An AI feature designed to optimise industrial energy consumption sits outside the high-risk category if its failure merely reduces efficiency. Conversely, if that same system’s malfunction could result in dangerous overheating or physical damage, it retains its status as a safety component.

The Omnibus allows IIoT manufacturers to scale connected factory deployments without stalling product launches while waiting for harmonised standards. Yet this operational freedom requires careful documented mapping of intended purposes and failure modes to satisfy market surveillance authorities.

Industrial Segments Principally Affected

The shift toward the Machinery Regulation (MR) creates a distinct regulatory environment for heavy industry. Manufacturing is the primary affected sector. The definition of machinery products captures the physical backbone of the factory floor—industrial robots, CNC machine tools, and automated assembly lines. For firms deploying collaborative robots (cobots), the Omnibus provides a streamlined path: safety loops are audited under the MR, bypassing the AI Act’s horizontal filing requirements.

This alignment, viewed by many as a concession to the German industrial lobby, protects connected factory ecosystems from the added burden of dual-certification.

In logistics and smart ports, the impact is equally systemic.

Modern logistics hubs rely heavily on Automated Guided Vehicles (AGVs), Autonomous Mobile Robots (AMRs), and automated gantry cranes. Here, the “self-evolving” clause of the MR is the critical pivot. If the AI managing a vehicle’s braking or collision-avoidance continuously updates its model based on real-time sensory data, it triggers a mandatory third-party conformity assessment. Logistics hub and port operators are required to distinguish between static navigation algorithms and those that adapt autonomously in dynamic environments.

The construction and mining sectors face similar scrutiny for autonomous haul trucks, excavators, and drilling rigs. In these high-hazard environments, AI used for bystander detection or semi-autonomous grading is classified as a safety component. Similarly, in agriculture, while traditional tractors follow separate safety frameworks, independent weeding and harvesting robots fall under the MR’s remit.

The energy and utilities sector is more nuanced. While software-only power routing and smart grid load-balancing do not meet the physical definition of machinery, the physical generation assets, such as wind turbine pitch control assemblies and robotic pipe crawlers, do.

As a whole, the Omnibus has not simplified compliance so much as reallocating it to sector-specific engineering and safety teams. Compliance now becomes an exercise in technical mapping across overlapping safety frameworks.

Exceptions

While the Digital Omnibus insulates general machinery from dual-certification, this regulatory relief is not universal.

To prevent jurisdictional overlap, the Machinery Regulation explicitly excludes major transport and consumer sectors, which remain governed by their own specific EU safety frameworks. Motor vehicles, aeronautical products, railway systems, and traditional agricultural tractors are carved out entirely.

Nor does the machinery exemption extend to other product categories listed in Annex I of the AI Act. Medical devices, connected toys, lifts, and marine equipment remain fully ensnared in the dual-regulatory net.

For manufacturers involved across multiple sectors, the Omnibus creates a fragmented compliance landscape. An AI component embedded in a factory robot now follows a streamlined sectoral path, whereas the same underlying model adapted for a medical device faces the full brunt of horizontal AI Act requirements. This fragmentation undercuts the European Commission’s argument of simplification, leaving companies to navigate a more complex and multi-tiered regulatory framework.

Unexpected Operational Adjustments

Beyond the main deferrals, the Digital Omnibus introduces several unexpected operational adjustments that require immediate attention from compliance and privacy teams.

The most profound is a revised approach to bias correction. Under the new Article 4a, the right to process special categories of personal data—such as race or health data—to detect algorithmic bias has been extended from high-risk providers to all AI developers and deployers. However, this is not a blanket authorisation. Legislators imposed a “necessity” standard, requiring organisations to prove that bias mitigation cannot be achieved using synthetic or anonymised data. This revision creates a tension between AI Act obligations and GDPR data minimisation principles.

Furthermore, while high-risk timelines have been extended, transparency requirements have actually been shortened. The grace period for legacy generative AI systems to implement machine-readable watermarking and synthetic content labelling has been cut from six to three months, creating a new hard deadline of December 2, 2026. This coincides with new, immediate prohibitions on AI systems generating non-consensual intimate imagery.

In addition, the anticipated abolition of registration requirements for systems self-assessed as non-high-risk did not survive negotiations. These systems must still be logged in the EU database, retaining a significant administrative overhead.

Legal Commentary

The consensus among international legal practices, including Freshfields, DLA Piper, and Dentons, is that the Digital Omnibus is a pragmatic rescue mission, not a deregulatory pivot.

While the deferral of high-risk obligations provides breathing room, legal analysts warn against treating this as a compliance holiday. The core architecture of the AI Act remains intact. The extended deadlines are barely sufficient for complex organisations to map their data flows and establish governance.

Commentators also remain sceptical of the Commission’s “simplification” narrative. Firms such as Dentons and GamingTechLaw highlight that the Omnibus fails to resolve the structural friction between the AI Act and parallel regimes like the GDPR, DORA, and NIS2. The revised rules for processing sensitive data for bias correction, for example, create immediate tension with data minimisation principles. Instead of a unified digital rulebook, organisations face a sprawling network of overlapping obligations.

Legal commentary has also pointed to the contractual dimension of the AI value chain. Firms such as DLA Piper argue that compliance can no longer be treated as an isolated internal engineering challenge. Allocating responsibility for technical documentation, failure modes, and model updates across third-party suppliers has become a critical procurement exercise. The regulatory burden has simply shifted from abstract compliance to contractual governance.