EU Machinery Regulation 2027: What Exporters Must Recheck for AI, Software and Cyber-Safety [GeXPs26-0817EN]

EU Machinery Regulation 2027: What Exporters Must Recheck for AI, Software and Cyber-Safety

EU Machinery Regulation 2027: What Exporters Must Recheck for AI, Software and Cyber-Safety

From 20 January 2027, Regulation (EU) 2023/1230 becomes the core EU machinery framework, replacing the Machinery Directive for new products placed on the market. For exporters, the change is not simply a new CE-marking exercise. The practical shift is toward a more explicit connection between mechanical safety, digital modification, safety-critical software, connected-product integrity, machine-learning safety functions and traceable evidence.

Why this matters to exporters now

In 2025, EU imports from South Korea in HS Section XVI “Machinery and appliances” reached €20.685 billion. Eurostat’s broader product group shows €10.066 billion in “Other machinery” and €5.205 billion in “Non-electrical machinery”. These figures are an exposure indicator, not a direct measure of products covered by the Machinery Regulation: product scope must still be assessed case by case.

1. A digital change can become a substantial modification

The Regulation expressly includes substantial modifications made by physical or digital means. If a post-market modification creates a new hazard or increases an existing risk and requires additional protective measures, the person carrying out that modification may be treated as the manufacturer for the modified machinery and may need a new conformity assessment.

2. Cyber-safety is part of machinery safety

Safety-critical hardware, software and data must be protected against accidental or intentional corruption. Machinery must be able to identify software required for safe operation and collect evidence of interventions or software/configuration changes where relevant to compliance.

3. Safety-software evidence becomes operational

The Regulation requires the tracing log for interventions and versions of safety software uploaded after market placement to be enabled for five years. For self-evolving control systems, safety-related decision-making data must also be recordable and retained for the period specified by the Regulation.

4. Machine-learning safety functions receive special treatment

Annex I specifically covers safety components and embedded systems with fully or partially self-evolving behaviour using machine-learning approaches that ensure safety functions. This does not mean every AI-enabled machine follows the same route. The exact conformity-assessment path depends on product classification and the function performed by the AI system.

5. Do not confuse the 2027 Machinery timeline with the AI Act timeline

The 2026 AI Omnibus moved AI-enabled machinery toward a sectoral approach to reduce overlap. The Machinery Regulation applies from January 2027, while the main AI Act rules for high-risk AI embedded in physical products such as machinery apply from 2 August 2028. Exporters should therefore manage two connected but different compliance milestones.

6. Digital instructions are allowed — with conditions

Digital instructions must be printable, downloadable and savable, and remain accessible online for the expected lifetime of the machinery and at least ten years after placement on the market. A paper copy must be supplied free of charge within one month when requested at purchase.

2026 action plan for exporters

  1. Classify the product: machinery, related product, safety component or partly completed machinery.
  2. Run a gap analysis against the current Machinery Directive technical file.
  3. Map PLCs, firmware, remote access, connected devices, safety software and AI/ML safety functions.
  4. Update risk assessment, validation, version/intervention logs, technical documentation and instructions.
  5. Separate pre-20 January 2027 products, post-2027 new products and field-modified products in the transition plan.

Bottom line

The 2027 change is best understood as a move from “mechanical CE compliance” toward a physical-plus-digital safety evidence system. Exporters that wait until January 2027 may discover that the biggest gap is not the CE mark itself, but the design records, software traceability and modification governance behind it.


Official sources

Information checked on 2026-08-17. Product-specific applicability and conformity routes should be verified against the current EU legal text, harmonised standards and the competent conformity-assessment route.


Watch the Full Video

EU Machinery CE Rules Change in 2027|5 Things to Check for AI, Software & Cyber-Safety

▶ Watch the full video on YouTube: https://youtu.be/f9pwbJtLUhI

Comments