Why the Machinery Regulation matters now
If your company designs, manufactures, imports or distributes machinery for the EU market, the rules are changing in a fundamental way. Regulation (EU) 2023/1230 – the new Machinery Regulation – replaces the long-standing Machinery Directive 2006/42/EC and starts to apply on 20 January 2027. For the first time, mechanical safety and digital safety are treated together, with explicit requirements for software, connectivity, cybersecurity and artificial intelligence. Companies that update their technical documentation and conformity processes early will avoid a scramble as the deadline approaches.
What is the Machinery Regulation?
The Machinery Regulation sets the essential health and safety requirements that machinery and related products must meet before they can be placed on the EU market. Because it is a regulation rather than a directive, it applies directly and uniformly in every member state without needing to be transposed into national law. This reduces the patchwork of national interpretations that existed under the old directive and gives businesses a single, clearer rulebook.
Who is covered?
The regulation applies to manufacturers, importers and distributors of machinery, as well as related products such as safety components, lifting accessories, chains, ropes and removable mechanical transmission devices. It also reaches software that performs a safety function. In short, anyone in the supply chain who places machinery or safety-related components on the EU market has obligations, with the heaviest duties falling on manufacturers.
The most important requirements
Combined mechanical and digital safety
For the first time, the regulation addresses risks from connected and autonomous machinery, the internet of things and AI. Where AI-based systems using self-learning techniques carry out safety functions, they must be designed so that safety is maintained. Software integrity and updates are treated as safety-relevant.
Cybersecurity as a safety issue
Machinery must be protected against corruption and against attempts to alter its behaviour that could create a hazard. In practice this means building in protection against unauthorised interference, complementing the horizontal rules of the Cyber Resilience Act.
New conformity assessment and CE marking
The regulation revises the conformity assessment procedures and updates the list of high-risk machinery categories. Manufacturers must carry out a risk assessment, compile technical documentation, apply the correct assessment route and affix the CE marking before placing a product on the market.
Digital documentation permitted
Instructions and certain documentation may now be provided in digital form, provided users can access, download and store them, and request a paper version where required. This modernises compliance but must be implemented carefully.
The timeline you need to plan around
The Machinery Regulation entered into force in 2023 and applies from 20 January 2027. Until that date, manufacturers may continue to place products on the market under Directive 2006/42/EC. From 20 January 2027, only machinery that complies with the new regulation may be placed on the EU market. There is no long grandfathering period for new products, so redesign, testing and documentation work should be planned around this hard date.
Practical example
Consider a manufacturer of automated warehouse robots that connect to a cloud platform for updates. Under the old directive, cybersecurity and software updates were not squarely addressed. Under the Machinery Regulation, the manufacturer must assess risks arising from connectivity, protect the robot against manipulation that could cause a hazard, and treat software updates as part of ongoing safety. The technical file and conformity assessment must reflect all of this before 20 January 2027.
Common mistakes companies make
A frequent error is assuming that compliance with the old directive automatically carries over – it does not. Others overlook that software and AI safety functions are now in scope, or treat cybersecurity as separate from product safety. Importers and distributors sometimes assume the obligations rest only with the manufacturer, when they too must verify that CE marking and documentation are in place. Leaving redesign work until 2026 risks missing the deadline entirely.
Recommended actions
Map your product portfolio against the new requirements and identify where connectivity, software or AI functions change the risk profile. Update your risk assessments, technical documentation and conformity assessment routes. Review whether any of your products fall into the revised high-risk categories. Check your supply chain roles so that importers and distributors understand their verification duties. Build the 20 January 2027 date into your product roadmap now.
Frequently asked questions
When does the Machinery Regulation start to apply?
It applies from 20 January 2027. Until then, products may still be placed on the market under the existing Machinery Directive 2006/42/EC.
Does it cover software and AI?
Yes. Software that performs a safety function is within scope, and machinery using AI or self-learning techniques for safety functions must be designed so that safety is maintained.
Do importers and distributors have obligations?
Yes. While manufacturers carry the primary duties, importers and distributors must ensure that products carry the CE marking, are accompanied by the required documentation and comply with the regulation.
Conclusion
The EU Machinery Regulation 2023/1230 modernises product safety for a connected, software-driven and AI-enabled world, and the 20 January 2027 application date is closer than it looks. Manufacturers, importers and distributors should start now to update risk assessments, technical documentation and conformity processes. At Lawgent we help companies interpret new EU product and digital regulation and build practical compliance into their processes. Contact Lawgent to prepare your machinery and safety-related products for 2027.