Skip to content
TECHNOMATON | Docs SAI Certified Trainers

Manufacturing

Compliance requirements for the manufacturing sector.


Sector Profile

AttributeValue
AI Act impactMEDIUM
NIS2 categoryImportant (Annex II) or Out of scope
GDPR impactMEDIUM
Other regulationsMachinery Directive, Product Safety

AI Act for Manufacturing

Typical AI Systems

SystemClassificationObligations
Predictive maintenanceLOWMinimal
Quality control (visual)LOWMinimal
Production optimizationLOWMinimal
Safety systems (AI)MEDIUMDocumentation
Worker monitoringMEDIUMTransparency
Robotics (collaborative)MEDIUMSafety assessment

Safety-critical AI

Embedded AI in Products

If your product contains AI:

  • You must classify the AI component
  • Documentation for downstream users
  • Product safety implications

NIS2 for Manufacturing

Scope Determination

CriterionEssentialImportantOut of scope
Medical device manufacturingYes
Computer/electronics manufacturingYes
Machinery manufacturingYes
Chemical manufacturingYes
Food productionYes
Other manufacturingYes (usually)

Condition: >50 employees OR >EUR 10M revenue

OT Security (Operational Technology)

Specific Requirements

AreaRequirementPriority
IT/OT segmentationNetwork separationCritical
OT monitoringIDS for industrial protocolsHigh
Legacy protectionCompensating controlsHigh
Backup/recoveryOT system backupsCritical
Vendor managementRemote access controlsHigh

GDPR for Manufacturing

Typical Data

CategoryExamplesLegal basis
Employee dataAttendance, performance, safetyContract + Legal
Supplier dataContacts, contractsContract
Customer dataOrders, contactsContract
CCTVSecurity camerasLegitimate interest
Access logsFacility entryLegal + Legitimate

Employee Monitoring


Machinery Directive + AI

AI in Machinery

If AI affects machine safety:

AspectRequirement
Risk assessmentMachine + AI combined
CE markingEntire system
DocumentationAI as component
ValidationAI behavior testing
UpdatesChange management for AI updates

CE Marking with AI


Checklist for Manufacturing

Immediate (Weeks 1-2)

  • Inventory of AI in production and products
  • NIS2 scope assessment
  • IT/OT network mapping

Short-term (Months 1-3)

  • OT security gap analysis
  • Employee monitoring GDPR review
  • Vendor access audit

Medium-term (Months 3-6)

  • IT/OT segmentation project
  • Legacy system protection
  • Product AI documentation

Long-term (Months 6-12)

  • OT monitoring implementation
  • NIS2 full compliance (if in scope)
  • AI Act product compliance

Typical Costs

ItemEstimate
IT/OT security assessmentEUR 15-30k
Network segmentationEUR 30-60k
OT monitoringEUR 20-50k
GDPR employee data auditEUR 10-20k
Product AI complianceEUR 15-30k/product
Total Y1EUR 90-190k

Resources