Braccio robotico in una cella recintata con una rete luminosa che cresce entro un perimetro

Immagine creata con IAAI-generated image

Machines that learn under Regulation (EU) 2023/1230: third-party assessment and evolving behaviour

Regulation (EU) 2023/1230 of 14 June 2023 on machinery, which repeals Directive 2006/42/EC, applies from 14 January 2027 (EUR-Lex). The new Regulation expressly names systems based on machine learning: Annex I, Part A, includes safety components and machinery with fully or partially self-evolving behaviour ensuring safety functions, and Annex III requires the intended evolution of that behaviour to be assessed from the design stage. Regulation (EU) 2026/1744, the Digital Omnibus on AI, then redesigned the relationship between the Machinery Regulation and Regulation (EU) 2024/1689, the AI Act. For manufacturers and integrators two questions arise: the conformity assessment procedure and liability for the behaviour that the machine develops after being placed on the market.

Annex I, Part A: the two entries on machine learning

Point 5 of Part A concerns “Safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions”. Point 6 concerns “Machinery that has embedded systems with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions that have not been placed independently on the market, in respect only of those systems” (EUR-Lex). The same category appears in point 19 of the indicative list of safety components, in Annex II.

Recital 54 explains the choice by reference to the characteristics of these systems, “data dependency, opacity, autonomy and connectivity”, which may increase the probability and severity of harm. Recital 55 circumscribes the scope of the rule: third-party assessment concerns only systems that learn through machine learning, not software incapable of learning or evolving and programmed to execute automated functions. The threshold of Part A is the capacity to continue learning while ensuring a safety function. Recital 54 adds that machinery incorporating a safety component that has already been certified by a third party when it was independently placed on the market need not be certified again solely because of that incorporation.

The procedures: always a notified body

For the categories in Part A, Article 25(2) allows only three procedures: EU type-examination (module B) followed by conformity to type based on internal production control (module C), full quality assurance (module H) or unit verification (module G). For Part B, paragraph 3 also allows internal production control (module A), provided that the manufacturer applies harmonised standards or common specifications covering all the relevant requirements (EUR-Lex). For Part A machinery, applying harmonised standards does not avoid the involvement of a notified body.

This has a consequence under the AI Act. Article 6(1) classifies as high-risk an AI system that is a safety component of an Annex I product required to undergo third-party assessment (AI Act Service Desk). A learning safety component placed in Part A of the Machinery Regulation satisfies both conditions, if it constitutes an AI system within the definition in Article 3, point (1).

The requirements of Annex III: assessing self-evolving behaviour

Under the general principles in Annex III, Part B, point 1, risk assessment and risk reduction include the hazards that may arise during the lifecycle of the machinery that are foreseeable at the time of placing it on the market “as an intended evolution of its fully or partially self-evolving behaviour or logic” (EUR-Lex). Point 1.2.1, on the safety and reliability of control systems, translates the principle into design requirements. The limits of the safety functions must be established in the risk assessment, and modifications to the settings or rules generated by the machinery or by operators, including during the learning phase, are not permitted where they may lead to hazardous situations. Control systems with self-evolving logic must not cause actions beyond the defined task and movement space, must allow the machinery to be corrected at any time in order to maintain its safety, and must make it possible to record data on the safety-related decision-making process, retaining them for one year solely to demonstrate conformity upon a reasoned request of the national authority. For versions of safety software uploaded after the placing on the market, recording must be enabled for five years.

Point 1.1.9, entitled “Protection against corruption”, requires the software and data critical for compliance with the essential requirements to be identified and protected against accidental or intentional corruption. Article 20(9) links this requirement and point 1.2.1 to the cybersecurity certification provided for by Regulation (EU) 2019/881, with a presumption of conformity insofar as the certificate covers them; on the coordination between cybersecurity regimes we refer to what we have written on NIS 2, DORA and the Cyber Resilience Act. Finally, point 1.1.6, on ergonomics, requires the human machine interface to be adapted to the foreseeable characteristics of operators, also where the machinery operates with varying levels of autonomy. The Regulation requires the manufacturer to delimit in advance what the machine’s learning cannot modify.

What the Digital Omnibus changed

Regulation 2026/1744 deleted from Section A of Annex I to the AI Act the point dedicated to the Machinery Directive and added Regulation 2023/1230 to Section B (EUR-Lex). Recital 42 describes the choice as a shift to a sectoral approach. Under the new Article 2(2) of the AI Act, only Article 6(1), Article 60a and Articles 102 to 112 apply to high-risk systems related to products in Section B. Classification remains that of the AI Act; the requirements pass through the sectoral legislation. On the overall content of the reform we refer to what we have written on the publication of the Digital Omnibus in the Official Journal.

Article 3 of the Omnibus in turn amends the Machinery Regulation. Article 8 is supplemented by an obligation for the Commission to adopt delegated acts amending Annex III, adding requirements for AI systems classified as high-risk under Article 6(1) of the AI Act, as safety components or as products in themselves. Those requirements must ensure that Chapter III, Section 2, and Articles 17, 19, 72 and 73 of the AI Act are reflected, and the delegated acts “shall apply by 2 August 2028”. The power is conferred for five years from 27 July 2026. The new Article 20(10) provides that, until harmonised standards or common specifications specific to the Machinery Regulation are adopted for high-risk AI systems, compliance with the harmonised standards and common specifications under Articles 40 and 41 of the AI Act counts as conformity with the corresponding requirements of Annex III (EUR-Lex).

The timetable therefore has two stages: from 14 January 2027 the requirements already set out in Annex III apply; those derived from the AI Act will come with the delegated acts, applicable by 2 August 2028. For the machinery manufacturer, the operational reference remains the Machinery Regulation, supplemented by the delegated acts.

Critical aspects: answering for behaviour that arises after the placing on the market

The first aspect concerns the Machinery Regulation. The manufacturer answers for the intended and foreseeable evolution at the time of placing on the market, and must prevent, through design, learning from exceeding the limits set. In our view, hazardous behaviour that exceeds those limits is not an event extraneous to the manufacturer: it shows that the limits had not been defined or protected as point 1.2.1 requires. The case of third-party intervention is different. The Regulation defines as “substantial modification” a modification, by physical or digital means, after the placing on the market, “which is not foreseen or planned by the manufacturer”, which creates a new hazard or increases an existing risk and which requires new guards or protective devices with modification of the safety control system, or additional measures for stability or mechanical strength (Article 3, point (16)); whoever carries it out is considered a manufacturer (Article 18). Retraining carried out by the integrator may fall within this definition, but only if all its elements are present.

The second aspect concerns liability for defective products. Directive (EU) 2024/2853 expressly includes software in the notion of product (Article 4, point (1)) and, among the circumstances to be taken into account in assessing defectiveness, lists “the effect on the product of any ability to continue to learn or acquire new features after it is placed on the market or put into service” (Article 7(2)(c)) (EUR-Lex). Recital 32 states that a manufacturer that designs a product capable of developing unexpected behaviour remains liable for harmful behaviour. Article 11(2) moreover excludes the exemption for a defect arising later where it is due to software, including updates or upgrades, to the lack of updates necessary to maintain safety or to a substantial modification, if the product is within the manufacturer’s control. The capacity to learn after the placing on the market thus becomes an element in the assessment of defectiveness. The Directive must be transposed by 9 December 2026 and applies to products placed on the market or put into service after that date. On the relationship with the Italian civil liability rules introduced by Legislative Decree No 160 of 9 September 2026, we refer to what we have written on who is liable when the system acts.

Conclusions

From 14 January 2027 the manufacturer of machinery incorporating a safety component capable of learning must turn to a notified body and demonstrate that it has assessed, before the placing on the market, how that behaviour may evolve and where it must stop. The manufacturer remains responsible for defining the limits, protecting critical software and data, recording safety decisions and ensuring that the machine can be corrected; the integrator that retrains the system remains responsible for verifying that it has not introduced a substantial modification. The delegated acts that will bring the requirements of the AI Act into the Machinery Regulation are still missing. It is advisable to document now the learning envelope, the software versions and the decision data, because both the third-party assessment and any judgement on defectiveness will be measured against that documentation.

Author: Valentina Grazia Sapuppo


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project