Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, has been in force since 27 July 2026. It amended Regulation (EU) 2024/1689, the AI Act, and set 2 December 2027 as the date of application of the obligations for the high-risk systems in Annex III and 2 August 2028 as the date for the systems in Annex I (EUR-Lex). For manufacturing undertakings in the sectors with the highest environmental impact, such as the production of cement, lime, plaster and glass (division 23 of NACE Rev. 2), basic metals (division 24) and the manufacture of paper and chemicals (divisions 17 and 20) (EUR-Lex), the postponement does not amount to a regulatory vacuum. Consider an ISO 14001 certified undertaking that introduces AI systems for the predictive maintenance of kilns and abatement filters, the optimisation of energy consumption, the monitoring of emissions and dust, support for waste classification and quality control by means of computer vision. None of these uses is high-risk as such, and for predictive maintenance the classification depends on the parts being monitored; each of them, however, meets obligations that already apply, worker protections and environmental responsibilities that remain with the undertaking.
The classification of industrial uses after the Digital Omnibus
Under Article 6(1) of the AI Act, an AI system is high-risk where it is intended to be used as a safety component of a product covered by the harmonisation legislation listed in Annex I, or is itself such a product, and the product is required to undergo a third-party conformity assessment (EUR-Lex). The Digital Omnibus amended the definition of safety component in Article 3, point (14), and inserted paragraph 1a into Article 6, under which AI systems that are used solely for non-safety related aspects, such as performance optimisation, service efficiency, automation or quality control, do not qualify as safety components; paragraph 1b, by way of derogation, provides instead that systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components (EUR-Lex).
It follows that energy optimisation and the quality control of non-safety related aspects as a rule remain outside the high-risk category. For predictive maintenance the answer depends on the parts being monitored: the Commission’s draft guidelines on classification include among safety functions the monitoring of the need for maintenance where an omitted intervention may cause physical harm, such as the detection of wear in safety-relevant parts (AI Act Service Desk). The picture also changes if the system performs a safety function for the plant, for example a kiln interlock; in both cases the product must then fall within legislation listed in Annex I with a third-party assessment. As regards Annex III, point 2 concerns safety components of critical infrastructure, including the supply of water, gas, heating or electricity; in our view a manufacturing plant, as such, does not fall within it. Point 4(b), on the other hand, covers systems intended to monitor and evaluate the performance and behaviour of persons in work-related relationships (EUR-Lex). In a plant, the boundary of the high-risk category runs through the workforce more often than through the equipment: if the images collected for quality control were also used to evaluate operators, the undertaking, as deployer, would be bound from 2 December 2027 by the obligations in Article 26, including the obligation to inform workers’ representatives and the affected workers before putting into service or using the system (Article 26(7)).
The obligations already applicable: literacy, emotions, transparency
Article 4, as replaced by the Digital Omnibus, requires providers and deployers to take measures to support the AI literacy of their staff and specifies that the obligation does not require them to guarantee any specific level of literacy (EUR-Lex). On the new wording we refer to what we have written on AI literacy after the Digital Omnibus: in a plant, training must reach first of all maintenance staff, quality staff and environmental managers.
Since 2 February 2025 the prohibition in Article 5(1)(f) has applied, which concerns the use of AI systems to infer the emotions of a natural person in the areas of workplace, except for medical or safety reasons (EUR-Lex). With warning No 342 of 14 May 2026, concerning a sentiment analysis system applied to employees’ messages, the Italian Data Protection Authority (Garante) recalled that prohibition and stated that information on the emotional sphere of workers is information “knowledge of which is therefore precluded to the employer” (Garante privacy). A function that infers the emotions or stress levels of operators is not a neutral accessory of the vision system: it must be excluded at the procurement stage, unless the medical or safety reasons provided for by the rule apply.
Finally, Article 50 has applied since 2 August 2026; for the deployer, the most relevant provision is paragraph 4, on text generated or manipulated by AI and published with the purpose of informing the public on matters of public interest, unless there has been human review or editorial control (EUR-Lex).
Cameras, automated systems and risk assessment: worker protections
The cameras of a computer vision system that also film operators fall under Article 4 of the Workers’ Statute (Law No 300 of 20 May 1970): equipment which also makes it possible to monitor workers’ activity remotely may be used exclusively for organisational and production needs, for workplace safety and for the protection of company assets, subject to a collective agreement with the trade union representatives or, failing that, to authorisation by the National Labour Inspectorate (Normattiva).
If the system provides information relevant to the assignment of tasks, the monitoring or the evaluation of workers, Article 1-bis of Legislative Decree No 152 of 26 May 1997 also applies: information on fully automated decision-making or monitoring systems, risk analysis and data protection impact assessment (paragraph 4), and written notice at least 24 hours before any change affecting working conditions (paragraph 5) (Normattiva). As regards safety, Article 29(3) of Legislative Decree No 81 of 9 April 2008 requires the risk assessment to be revised immediately on the occasion of changes to the production process or to the organisation of work that are significant for health and safety, or in relation to the degree of technical progress, and the related document to be revised within thirty days (Normattiva). Entrusting the predictive operation of a kiln to an algorithm is, in our view, one of those changes. None of these protections depends on the classification of the system under the AI Act.
AI within the environmental management system
ISO 14001:2026, whose main new features we have described, contains no specific provisions on artificial intelligence, but it provides the tools to govern it. We consider that the introduction of an AI system should be treated as a change to be planned in accordance with clause 6.3; that the energy and resources consumed by the system, on premises or at external providers, are an environmental aspect to be assessed in accordance with clause 6.1.2; and that a system used to monitor emissions or consumption is a monitoring and measuring resource to be kept under control under clause 9.1.1. An AI system introduced to reduce environmental impacts is also, in turn, a source of impacts to be assessed.
To frame this assessment the undertaking may take into account the technical report ISO/IEC TR 20226:2025, published in July 2025 by subcommittee ISO/IEC JTC 1/SC 42, which provides an overview of the environmental sustainability aspects of AI systems across their life cycle and of the related potential metrics (ISO). Where computation takes place in external data centres, the environmental aspect extends to the services purchased, on which we refer to the energy bill of artificial intelligence.
Critical aspects: the rebound effect and responsibilities that remain human
The first aspect is one of environmental substance. The European Environment Agency observes that efficiency improvements tend to reduce production costs and prices, encouraging increased production and consumption, a process sometimes referred to as the rebound effect (European Environment Agency). Efficiency per unit of product is not the same as a reduction in overall impact: for this reason we consider that environmental objectives linked to AI should also be measured in absolute terms.
The second aspect concerns the attribution of decisions. Article 184(5) of the Environmental Code (Legislative Decree No 152 of 3 April 2006) provides that “The correct assignment of the waste codes and of the hazardous properties of waste is carried out by the producer”, on the basis of the guidelines of the National System for Environmental Protection and Research (Normattiva). The code proposed by an algorithm remains, in legal terms, a choice of the waste producer. The same applies to the integrated environmental authorisation (AIA): Article 29-decies(2) places on the operator the transmission of the data relating to emission controls and the obligation to inform the competent authority immediately in the event of a breach of the conditions of the authorisation (Normattiva). A false negative of the monitoring system does not transfer that obligation to the software provider. If, moreover, the undertaking uses high-risk systems, the failure to adopt human oversight measures may be of criminal relevance, where it gives rise to a danger to life or physical safety, and may ground the liability of the entity, under the framework introduced by Legislative Decree No 160 of 9 September 2026, which we examined when discussing who is liable when the system acts.
Conclusions
For an ISO 14001 certified manufacturing undertaking, AI applied to kilns, filters, energy, emissions, waste and quality is not high-risk as such, unless the system performs a safety function, as in the maintenance of safety-relevant parts, but it is not in any event free from regulation. The undertaking remains responsible, as of now, for staff literacy, for excluding any inference of workers’ emotions, for the procedures under Article 4 of the Workers’ Statute and Article 1-bis of Legislative Decree No 152 of 1997, for updating the risk assessment and for the environmental responsibilities of the waste producer and of the authorised operator. There is, at present, no shared metric for the environmental footprint of AI systems, which the report ISO/IEC TR 20226 describes without setting requirements. It is advisable to treat every AI system as a change to the environmental management system: to plan it, to assess its environmental aspects, to verify its reliability as a measuring instrument and to document, for every decision relevant to the authorisation or to waste classification, the person who took it.
Author: Valentina Grazia Sapuppo








