Regulation

AI-generated text

EU’s digital omnibus streamlines market entry for AI-driven robots while keeping high-risk rules intact

The EU’s digital omnibus regulation, effective July 27, 2026, reduces overlapping compliance requirements for AI-driven robots and other physical AI systems by aligning high‑risk AI checks with sectoral product‑safety rules.

EU’s digital omnibus streamlines market entry for AI-driven robots while keeping high-risk rules intact

The EU’s digital omnibus regulation, which entered into force on July 27, 2026, reduces overlapping compliance obligations for AI‑driven robots and other physical AI systems by better aligning the AI Act with sectoral product‑safety rules. The change targets developers of so‑called physical AI — systems that sense their environment and make decisions or perform physical actions — such as industrial robots, autonomous warehouse vehicles, AI‑based safety components, and some medical and biometric devices.

Why the change was needed

In physical systems an algorithmic error can produce not only incorrect output but also unintended movement, dangerous collisions or other physical harm. Until now, such systems could fall under both the AI Act and various sectoral rules (for example, the Machinery Regulation or cyber‑resilience legislation), each with different requirements and timelines. The digital omnibus aims to eliminate redundant compliance procedures.

What the omnibus does

The key innovation is that high‑risk AI systems embedded in machines will from now on be primarily assessed through the applicable sectoral product‑safety framework. For industrial robots this means the conformity assessment under the Machinery Regulation remains the principal procedure, supplemented by European Commission delegated acts that define AI‑specific health and safety requirements.

In practice, manufacturers will no longer need to assess the same risks under two parallel systems. However, not all AI‑enabled products are brought into this simplified regime: items listed in Annex I of the AI Act that are not considered machines (for example certain toys or lifts) may still be subject simultaneously to their sectoral rules and the full high‑risk AI requirements.

The European Commission must therefore issue guidance on how companies can comply with overlapping obligations while minimizing administrative burden.

Implementation timeline: 2026–2028

Obligations will be phased in:

  • 2 December 2026: Requirements on labelling AI‑generated content (e.g. watermarking) and bans on AI systems capable of creating or manipulating intimate content without consent or material depicting sexual abuse of children take effect.
  • 2 December 2027: Rules for high‑risk systems used autonomously in biometric identification, critical infrastructures and other sensitive domains become applicable.
  • 2 August 2028: Requirements for AI functioning as safety components of products (for example algorithmic emergency‑stop and collision‑avoidance systems) come into force.

Cybersecurity and incident reporting

The digital omnibus does not replace the Cyber Resilience Act; both apply in parallel. From 11 September 2026, manufacturers of products containing digital elements must report actively exploited vulnerabilities and serious security incidents — initially with notifications within 24 hours, followed by more detailed reports. The Cyber Resilience Act becomes fully applicable on 11 December 2027.

Accordingly, robotics companies should prepare unified technical documentation, cybersecurity systems and post‑market surveillance frameworks that meet sectoral product‑safety, AI and cybersecurity requirements at once.

Registration, data processing and enforcement

The rules tighten registration and data‑processing duties: providers must register their systems in the EU high‑risk database even if they themselves consider those systems outside the regulation’s scope. Processing of sensitive personal characteristics (such as health status or origin) is permitted only when strictly necessary for the intended purpose.

The EU AI Office will play a larger role in supervising companies that develop both general‑purpose AI models and applications built on them. Nevertheless, oversight in law‑enforcement, border management, the judiciary and financial services will remain with national or sectoral authorities.

Conclusion

The digital omnibus reduces duplicative compliance for manufacturers by channeling high‑risk AI embedded in machines through sectoral product‑safety rules, but it does not relax safety, data‑protection or cybersecurity requirements. Companies building AI‑driven robotics and related equipment must adapt processes, documentation and reporting to meet staggered obligations coming into force between 2026 and 2028.