Quadro di comando con pulsante di arresto di emergenza e modulo elettronico

Immagine creata con IAAI-generated image

Predictive maintenance, energy efficiency and quality control after the Digital Omnibus: when AI is a safety component

Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, has been in force since 27 July 2026. It amends Regulation (EU) 2024/1689, the AI Act, including in the part that determines which systems integrated into products are high-risk (EUR-Lex). The Regulation supplemented the definition of “safety component” in Article 3, point (14), and inserted paragraphs 1a, 1b and 1c into Article 6. These are the provisions that decide whether a predictive maintenance, consumption optimisation or quality control system installed on a regulated product is high-risk; on the rest of the reform we refer to what we have written on the publication of the Digital Omnibus in the Official Journal.

The new definition: the safety function as intended purpose

In the amended text, a safety component is “a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property” (EUR-Lex). The first part reproduces the 2024 wording (AI Act Service Desk); the novelty lies in the second, which links the safety function to the intended purpose, that is, to the use specified by the provider in the instructions for use, in the promotional material and in the technical documentation under Article 3, point (12).

The definition retains two distinct cases: in the first, what matters is what the system is intended to do; in the second, what happens when the system fails. Recital 7 of Regulation 2026/1744 specifies that the safety function “should be an intended purpose of the system, which is determined by the provider of the system” and that the mere integration of an AI system into a regulated product does not, in itself, mean that it fulfils a safety function (EUR-Lex).

Paragraphs 1a, 1b and 1c of Article 6

Paragraph 1a provides: “For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components”. Paragraph 1b sets the limit: “Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components”. Paragraph 1c rules out that a third-party assessment required solely for risks other than risks to health and safety, such as electromagnetic interference, is sufficient for classification purposes (EUR-Lex).

The two conditions of Article 6(1) remain cumulative: the system must be intended to be used as a safety component of a product covered by the legislation listed in Annex I, or be itself such a product, and the product must be required to undergo a third-party conformity assessment (AI Act Service Desk). According to recital 20 of the Omnibus, the second condition does not in itself require the involvement of a notified body, where the sectoral legislation allows a procedure based on harmonised standards.

Two words of the text guide the reading. The adverb solely narrows the exclusion: paragraph 1a protects only systems that perform no safety-related function at all. The conditional would endanger, by contrast, shifts the assessment to the hypothetical consequences of a malfunction: a declared efficiency purpose is not sufficient if an error of the system may endanger health and safety.

Predictive maintenance, energy and quality: the practical consequences

On 19 May 2026 the Commission published the draft guidelines on the classification of high-risk systems (European Commission). Among safety functions, the draft lists the monitoring of the need for maintenance or inspection where an omitted intervention may cause physical harm, with the example of a system that detects wear in safety-relevant parts; among mitigation functions, systems that trigger a safe stop in the presence of hazardous conditions. The examples include a system that monitors gas concentration and commands the shutdown of equipment for explosive atmospheres and one that predicts an uncontrolled rise in pressure and activates the protections. By contrast, performance optimisation where failure would not lead directly to risks to health or safety, and quality control of non-safety related functions, are not safety functions (AI Act Service Desk).

Applied to a production plant, these criteria lead to differentiated results. A system that optimises the heating curve of a kiln to reduce consumption falls, as a rule, within paragraph 1a. The same system changes its nature if it commands an interlock or the shutdown of the kiln for overtemperature, or if the replacement of components on which safety depends is based on its predictions. Predictive maintenance is not excluded as such: what matters is which parts it monitors and what happens if it fails. A vision system that verifies the dimensional or aesthetic conformity of the product is quality control within the meaning of paragraph 1a; it remains to be verified, case by case, whether its error may translate into a risk for those who use the product or for those who work on the line.

Identifying a safety component is only the first step: it must then be established whether the kiln or the plant falls within legislation listed in Annex I that provides for a third-party assessment, and the answer depends on the applicable product legislation.

Annex I, machinery and timetable

The Omnibus deleted from Section A of Annex I the point relating to the Machinery Directive and added Regulation (EU) 2023/1230 to Section B (EUR-Lex). Section A retains, among others, the legislation on lifts, equipment for potentially explosive atmospheres, pressure equipment, personal protective equipment and appliances burning gaseous fuels (AI Act Service Desk). The new Article 2(2) provides that only Article 6(1), Article 60a and Articles 102 to 112 apply to high-risk systems related to products in Section B. For machinery, the requirements will therefore come through delegated acts amending Annex III to Regulation 2023/1230 which, according to the new text of Article 8 of that Regulation, “shall apply by 2 August 2028” (EUR-Lex).

For systems classified under Article 6(1) and Annex I, Chapter III, Sections 1, 2 and 3, applies from 2 August 2028; for those in Annex III, from 2 December 2027 (EUR-Lex). The guidelines provided for in Article 6(5) should have been provided by 2 February 2026 (AI Act Service Desk). They are still in draft form: the targeted consultation closed on 23 July 2026 and the Commission announces their final adoption by the end of 2026 (European Commission). The draft, which predates the adoption of the Omnibus, is not binding but reflects the Commission’s interpretation (European Commission).

Critical aspects: who establishes that a failure does not endanger safety

The first aspect concerns the author of the judgement. The intended purpose is set by the provider, but the derogation in paragraph 1b depends on an objective factor, the consequences of the malfunction, which the provider’s declaration cannot alter. For Annex III systems, Article 6(4) requires a provider who considers that its system is not high-risk to document its assessment; for Annex I safety components there is no similar rule. Precisely because there is no express obligation, a documented assessment is the provider’s first safeguard before the market surveillance authority. Its natural place is the risk assessment already required by product legislation, extended to the failure modes of the system.

The second aspect concerns the employer. Article 29(3) of Legislative Decree No 81 of 9 April 2008 requires the risk assessment to be revised on the occasion of changes to the production process that are significant for health and safety or in relation to the degree of technical progress (Normattiva), and Article 71 requires the employer, when choosing work equipment, to consider the risks arising from its use and to ensure maintenance suitable for guaranteeing the safety requirements over time (Normattiva). In our view, where the predictions of an AI system determine the timing of interventions on safety-relevant parts, that system becomes part of the way in which the employer fulfils the maintenance obligation. The provider’s classification does not replace the risk assessment that the law assigns to the employer.

The third aspect concerns use other than the intended one. For products that remain in Section A, Article 25(1)(c) considers as a provider anyone who modifies the intended purpose of a system not classified as high-risk in such a way that it becomes high-risk (AI Act Service Desk). Connecting the output of an optimisation system to a stop command may turn the undertaking that integrates it into a provider. On the civil and criminal consequences of a malfunction, also in the light of Legislative Decree No 160 of 9 September 2026, we refer to what we have written on who is liable when the system acts.

Conclusions

After the Omnibus, AI systems used solely for efficiency, automation or quality control are not safety components, unless their failure or malfunctioning would endanger health and safety. The boundary is determined by analysing the consequences of the error, regardless of the name given to the function. The provider remains responsible for the intended purpose and for the classification; the employer remains responsible for the risk assessment and for the maintenance of work equipment. The final guidelines and, for machinery, the delegated acts are still missing. It is advisable for engineering departments and HSE managers to document now, system by system, why a failure would not compromise safety, so as to have a verifiable justification when the high-risk rules become applicable to Annex I products, from 2 August 2028.

Author: Valentina Grazia Sapuppo


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project