search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
INDUSTRY 4.0/IOT/AI


THE ESSENTIALS OF AI: ACT NOW


Iain Bowes, Head of Management System Assurance for TÜV SÜD Business Assurance, says the AI Act will ensure trustworthy, transparent and secure AI, and advises business to regard it more than just ‘box-ticking’


T


he EU’s AI Act is the world’s first comprehensive AI regulation. While the AI Act does not apply in the UK, companies based outside the EU are still bound by it if their AI system is placed on the EU market or if the output of that AI (e.g., a prediction or decision) is used inside the EU. UK businesses trading with or supplying EU partners will therefore need to align their practices with the EU Act. Much of the initial market reaction has focused heavily on providers. A critical and often overlooked category is the user (deployer). Providers are typically developers or manufacturers, and have the heaviest compliance obligations, especially for high-risk and GPAI (General-Purpose AI) systems. Because of this, it is easy for other businesses to assume the regulation does not apply to them. However, the Act also categorises businesses based on how they interact with the AI system – providers, deployers/users, importers or distributors. Users (deployers) of high-risk AI systems have some obligations, though less than providers (developers). This applies to users located in the EU, and third country users where the AI system’s output is used in the EU. If your business uses AI tools to optimise supply chains, manage HR functions, or streamline operations, you are a deployer. Recent amendments through the Digital Omnibus have refined these obligations to be more proportionate. For instance, the Commission and Member States are now tasked with encouraging providers and deployers to ensure a sufficient level of AI literacy among their staff, replacing previous unspecified horizontal obligations.


Double compliance burden


The manufacturing sector is among the most heavily impacted by the Act’s high-risk classifications as it applies to embedded AI, for example where AI is a safety component of a physical product. Under Article 6(1), an AI system is automatically classified as high-risk if it meets two conditions. The first is if


14


it is a product (or a safety component of a product) covered by the EU’s existing product safety laws (listed in Annex I), totalling 20 specific pieces of legislation. The second condition is if the product in question is required to undergo a third-party conformity assessment before it can be sold. This impacts:


• Industrial machinery - AI used to control robotic arms, automated assembly lines or safety sensors in factories, falling under the Machinery Regulation. • Electronics and radio equipment - AI integrated into smart devices, telecommunications hardware or industrial IoT sensors, under the Radio Equipment Directive.


• Medical devices - AI-powered diagnostic


hardware or robotic surgery tools. • Lifts and pressure equipment - AI used to manage


safety protocols in elevators or industrial boilers. If a company manufactures smart machinery or industrial IoT devices, they must follow both the AI Act and the relevant existing safety laws, which creates a double compliance burden. For some products or systems, a CE Mark cannot be applied unless the high- risk requirements of the AI Act have been fulfilled. To address implementation challenges, recent


regulatory updates have linked the implementation timeline of high-risk rules to the availability of standards or other support tools. Failing to comply carries severe financial penalties under a three-tiered system: • Unacceptable risk violations: Fine of up to €35million or 7% of total worldwide annual turnover, whichever is higher.


• Non-compliance with obligations (e.g., data


governance, transparency, human oversight): Fine up to €15 million or 3% of total worldwide annual turnover, whichever is higher.


• Misleading authorities: Fine up to €7.5 million or 1% of total worldwide annual turnover, whichever is higher. To foster innovation and ease this burden,


regulatory simplifications regarding technical documentation and penalty applications have now been extended beyond SMEs to include small mid- caps (SMCs).


PROCESS & CONTROL ENGINEERING | JULY/AUGUST 2026


Best practice governance The EU AI Act represents a major shift in how business is conducted, moving AI from a tech-team project to a board-level compliance and ethics priority. For organisations navigating this transition, compliance is the floor not the ceiling. To truly succeed, businesses must bridge the gap between legal requirements and operational trust. This is where adopting a structured governance framework becomes critical. AI Essentials (AIE) provides a practical, evidence-based method to establish repeatable controls. It maps directly to the fundamental pillars of the ISO/IEC 42001 AI Management System. To turn these regulatory hurdles into a competitive advantage, organisations should therefore adopt the core principles of the AI Essentials framework: • Pillar 1 - Security and Data Integrity: Protecting against logic-based attacks and securing data pipelines.


• Pillar 2 - Transparency and Explainability: Ensuring stakeholders understand they are interacting with AI and can explain how decisions are made. • Pillar 3 - Human-in-the-Loop and Accountability:


Preventing irreversible AI decisions without human review.


• Pillar 4 - Fairness and Bias Mitigation: Ensuring AI does not discriminate or reinforce harmful stereotypes. • Pillar 5 - Reliability and Hallucination Management: Using techniques like Retrieval- Augmented Generation (RAG) to ground the AI in factual data and mitigate fabrication. • Pillar 6 - Societal, Ethical and Consequential Impact: Proactively assessing the broader effects of AI on the environment, workforce, and society. It is vital to remember that AI-enabled systems should not be built for a regulator but for end users. By the time the August 2028 transition windows close, the businesses that thrive will be those that didn’t just “tick the box” of the EU AI Act, but those that implemented AI Essentials to create a transparent, resilient and human-centric AI ecosystem.


TÜV SÜD Business Assurance www.tuvsud.com/en-gb/cybersecurity


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40  |  Page 41  |  Page 42  |  Page 43  |  Page 44