Starting January 20, 2027, every humanoid robot sold in the European Union will be judged against a new law. That’s the day the EU Machinery Regulation, Regulation (EU) 2023/1230, replaces the 2006 Machinery Directive. It’s the first EU machinery law written with learning, self-evolving and autonomous mobile machines in mind. Any humanoid placed on the EU market after that date carries its CE marking against this text.
Two things make it a big deal for humanoid makers. First, if a robot’s safety function relies on machine learning that keeps adapting, the maker can no longer certify it alone; an outside notified body has to assess it. Second, a July 2026 amendment to the EU AI Act moved AI rules for machines into machinery law, which makes this regulation, not the AI Act, the main gate for AI-powered humanoids in Europe. Here’s what changes, the dates to put in a 2027 to 2028 roadmap, and what buyers should ask now. It’s a policy summary, not legal advice.
A regulation, not a directive, and why that matters
The old Machinery Directive (2006/42/EC) had to be written into each country’s national law. The new text is a regulation, so it applies directly and identically in all 27 member states, with no national variations to track. Most of it applies from January 20, 2027. Some provisions, including the rules on notified bodies, have applied since January 20, 2024.
The dates for a humanoid roadmap
| Date | What happens | Source type |
|---|---|---|
| Jul 19, 2023 | Machinery Regulation (EU) 2023/1230 enters into force (published OJ L 165, June 29, 2023) | Law |
| Jan 20, 2024 | Notified-body provisions start to apply | Law |
| Jul 27, 2026 | Digital Omnibus on AI (EU) 2026/1744 enters into force; machinery moves to AI Act Annex I Section B | Law |
| Sep 11, 2026 | Cyber Resilience Act (EU) 2024/2847 vulnerability and incident reporting obligations begin | Law |
| Dec 9, 2026 | Deadline for member states to transpose the new Product Liability Directive (EU) 2024/2853, which treats software as a product | Law |
| Jan 20, 2027 | Machinery Regulation applies; Machinery Directive 2006/42/EC repealed | Law |
| Dec 11, 2027 | Cyber Resilience Act main obligations apply to products with digital elements | Law |
| Aug 2, 2028 | AI Act high-risk obligations for Annex I products; Machinery Annex III delegated acts with AI requirements must apply by this date | Law (delegated acts not yet adopted) |
Learning safety systems now need an outside assessor
Annex I Part A lists the machinery that has to go through third-party conformity assessment. Two new entries matter for humanoids. One is safety components with fully or partially self-evolving behaviour using machine-learning approaches that ensure safety functions. The other is machinery that embeds such systems, for the system itself, where it wasn’t placed on the market separately. Recital 55 limits this to systems that actually learn. Software “programmed only to execute certain automated functions” isn’t caught.
In practice, the line falls here. A humanoid whose safety layer is a learned model that keeps adapting would face a notified body; think of person detection that triggers a protective stop. A humanoid that runs a learned manipulation policy but keeps a conventional, deterministic safety controller underneath may stay on the self-assessment route. Expect vendors to design their products around exactly that line.
Hard limits on what a self-evolving robot may do
Annex III section 1.2.1 sets three conditions for control systems of machinery that has self-evolving behaviour or is designed to run with varying levels of autonomy. First, they must not let the machine perform actions beyond its defined task and movement space. Second, they must enable recording of data on the safety-related decision-making process after the machine is placed on the market, kept for one year for use on a reasoned request from a national authority. Third, they must allow the machine to be corrected at all times to maintain its inherent safety.
A separate requirement in the same section applies to all machinery, learning or not: a tracing log of interventions and of safety-software versions uploaded after the machine is placed on the market, enabled for five years after each upload. For humanoid fleets that get over-the-air policy updates, that’s a legal paper trail for every safety-relevant change.
Cybersecurity becomes a machinery safety requirement
Section 1.1.9, “protection against corruption,” says connecting another device, locally or remotely, must not create a hazardous situation. Hardware and software critical to compliance must be protected against accidental or intentional corruption, and evidence of legitimate or illegitimate interventions has to be collected. For a fleet-connected humanoid, this is where remote access, teleoperation and update channels meet machinery safety law. Our guide to cybersecurity risks of connected robots covers the practical side.
Walking between cells counts as autonomous mobile machinery
The regulation defines autonomous mobile machinery as mobile machinery with an autonomous mode in which all essential safety functions are ensured in its travel and working area without permanent operator interaction. Supplementary requirements in Annex III section 3 cover supervisory functions and safe behaviour in autonomous mode. They also require either protected zones or detection of people and obstacles. Under 3.6.3.3, the instructions must spell out the intended travel area, working area and danger zones. A walking humanoid that moves between cells on its own is squarely in scope.
Two more provisions matter for integrators. A substantial modification is a physical or digital change the manufacturer didn’t foresee that creates a new hazard or increases a risk. It can make whoever performs it legally responsible as the manufacturer. Adding new end-effectors, new AI policies or new tasks is therefore a contract and compliance question, not just an engineering one. And digital instructions are now allowed, though the user can request a free paper copy at the time of purchase.
The July 2026 AI Act change that rerouted the rules
The original AI Act (Regulation (EU) 2024/1689) treated AI safety components in machinery as high-risk AI under Annex I Section A. That would have meant two parallel rulebooks for the same robot. The Digital Omnibus on AI (Regulation (EU) 2026/1744, adopted July 8, 2026, published July 24, 2026) took a sectoral approach instead. It moved the Machinery Regulation to Section B of AI Act Annex I, where only a short list of AI Act articles applies directly.
In exchange, the Commission must adopt delegated acts amending Machinery Regulation Annex III. These carry over the AI Act’s high-risk requirements (Chapter III Section 2 and Articles 17, 19, 72 and 73) and must apply by August 2, 2028. Until machinery-specific AI standards exist, manufacturers may rely on harmonised standards or common specifications under the AI Act for presumption of conformity. The Omnibus also moved the AI Act’s high-risk dates, to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems.
The upshot: the Machinery Regulation is the main gate for AI-enabled humanoids in the EU, and more AI-specific requirements are scheduled to arrive inside it by 2028.
Built in Texas or Shenzhen, the same rules apply
What counts is where a robot is placed on the market, not where it’s built. Any humanoid sold, leased or put into service in the EU from January 2027 needs an EU-compliant technical file, risk assessment, declaration of conformity and CE marking. That includes the US, Chinese and Korean robots now turning up at EU trade shows. Robots supplied under robots-as-a-service contracts still need a responsible economic operator in the EU.
Manufacturers usually show conformity using technical standards such as ISO 10218, ISO/TS 15066 and mobile-robot standards; our ISO and safety standards guide covers that stack. Harmonised standards for the new regulation are still being updated, so check the Official Journal list before relying on any one of them.
Seven questions for a 2027 EU pilot
- Which Machinery Regulation conformity route will the vendor use, and does any safety function use self-evolving ML (the notified-body route)?
- What’s the defined task and movement space, and how is it enforced in software and hardware?
- Where are the 5-year safety-software version log and the 1-year safety-decision log, and who holds them?
- How do the instructions define travel area, working area and danger zones for autonomous mode?
- Who’s the manufacturer of record after integration, new tools or new AI policies (substantial modification)? Get it in writing.
- How do remote access, teleoperation and over-the-air update channels map to section 1.1.9 and the Cyber Resilience Act timeline?
- When will you review the August 2028 Annex III AI delegated acts?
The next thing to watch is the Commission’s draft of those Annex III delegated acts. They’ll decide how much of the AI Act’s paperwork lands on humanoid makers, and the clock to August 2, 2028 is already running.
Frequently asked questions
When does the EU Machinery Regulation apply to humanoid robots?
From January 20, 2027, for machinery placed on the EU market from that date. It replaces Machinery Directive 2006/42/EC and applies directly in every member state.
Do AI-powered humanoids need a notified body in the EU?
Only if a safety function relies on fully or partially self-evolving machine-learning behaviour. Those safety components, and machinery embedding them, are in Annex I Part A and need third-party assessment. Learned task policies running on top of a conventional safety controller don’t automatically trigger it.
Does the EU AI Act apply directly to humanoid robots?
Mostly not, after the July 2026 Digital Omnibus (Regulation (EU) 2026/1744). Machinery moved to Section B of AI Act Annex I, and AI requirements will be added to the Machinery Regulation through delegated acts that must apply by August 2, 2028.
Does this affect robots made outside the EU?
Yes. What counts is placing the robot on the EU market or putting it into service there, not where it was made. Imported humanoids need CE marking under the new regulation from January 2027.
Sources
- Regulation (EU) 2023/1230 on machinery, EUR-Lex: CELEX 32023R1230 (Annex I Part A; Annex III 1.1.9, 1.2.1, section 3; recitals 54–55)
- EU-OSHA, Regulation 2023/1230 summary: osha.europa.eu (application from January 20, 2027; notified bodies from January 20, 2024)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex: CELEX 32026R1744 (recitals 40 and 42; Article 2(2) as amended)
- Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2024/2847 (Cyber Resilience Act); Directive (EU) 2024/2853 (Product Liability)
Related: What certifications guarantee a robot is safe to use · Robot liability and insurance for humanoids · FCC Covered List and foreign-made robots
Last updated: October 7, 2026. This is a policy summary, not legal advice. To report an error, see our corrections page. Articles are drafted with AI assistance and reviewed and edited by an editor; see our editorial policy.
