Cyberattacks and AI are redefining machine safety

Developments such the emergence of AI and the rise of cybercrime are challenging established concepts of machine safety. Thomas Pilz, managing partner at the safety specialist Pilz, examines some of these issues and how they are being tackled. He believes an international approach will be needed.
We all know the CE mark. You can see it on electrical appliances, toys or household goods, as well as on plant and machinery. It stands for Conformité Européenne. The CE mark is effectively the seal that shows that products placed on the market in the European Economic Area (EU and EFTA) meet essential health, safety and environmental requirements.
By attaching the mark, the person placing the product on the market signals that they have complied with the applicable legal requirements for the safety of the product within the EU. For the past 30 years, every product that falls under an EU directive has required an EC Declaration of Conformity.
These directives include the Machinery Directive, which has also been mandatory since 1995. It describes standardised health and safety requirements for interaction between humans and machines. It replaced a host of individual national regulations on machinery safety that existed previously.
What was initially a major challenge for manufacturers is now something no one would do without. CE marking and the Machinery Directive create transparency and trust between manufacturers and users. They are therefore success stories. They have also served as a model for establishing legal frameworks for machine safety in other parts of the world, and continue to do so.
In Brazil, for example, there has been a national law since 2010 that stipulates minimum safety requirements for machinery and work equipment. Where possible, it adopted the safety requirements from Annex I of the Machinery Directive, including individual special requirements for certain types of machinery. In Europe, this law is known as the “Brazilian Machinery Directive”.
India is also adopting a legal framework for machine safety. Its Ministry of Heavy Industries has published two relevant regulations. The Omnibus Technical Regulations specify safety requirements for various types of machinery and electrical equipment.
There are now mandatory certifications and a conformity mark in India. Most of the new requirements are in line with international standards. Anyone wishing to export to India must appoint an authorised representative based in India.
The subject of machinery safety will certainly continue to develop in India. In future, it will not be possible to import any machinery or products into India that do not comply (in other words, that do not have the Indian CE mark). This could mean that machines or products could be held by Indian customs until the supplier has met the required specifications.
Let’s go back to the mid-1990s, when Tim Berners-Lee released the technology for using the World Wide Web at the CERN research centre in Switzerland. Theis was a breakthrough for networking and digitisation in society and industry.
Now, 30 years later, security is defined differently. As a result of networking and digitisation, products and machinery with digital elements are exposed to completely different risks – data manipulation, for example.
European legislators have reacted. The principle of CE marking remains in place. But the requirements for obtaining it have been adapted to the current state of the art. The new Machinery Regulation was published in 2023 and will replace the Machinery Directive in 2027.
Can AI be safe?
In a science fiction story published back in 1942, Isaac Asimov formulated his so-called robot law for intelligent machines. It stated that: “A robot may not injure a human being.” Today, 83 years later, developments in artificial intelligence mean that the rules for interaction between human and machine need to be reconsidered.
Europe’s legislators have recognised this and taken the subject of AI into account in the new Machinery Regulation. It talks about machines with self-evolving behaviour. How safe can a machine be if the way it reacts in dangerous situations is determined not by humans, but by an algorithm?
In an extreme case, we need to consider whether self-learning software could potentially result in a new machine. This is an extremely interesting subject, not just for manufacturers, but also for notified bodies.
AI doesn’t just affect the world of machinery. The EU Regulation on Artificial Intelligence – the so-called AI Act – regulates what AI systems may and may not do.
It prohibits various AI practices, such as the manipulation of people. This means that AI must not lead people to make a decision that would cause significant harm to themselves or others. Certain applications – in the areas of education, critical infrastructure or law enforcement, for example – have been categorised as high-risk AI systems, which must meet special requirements. These high-risk AI systems must also be CE-marked in future.
At Pilz, we see the AI Regulation as being extremely important. It ensures that opportunities can be exploited, while also ensuring that the risks posed by AI are reduced.
No CE mark without security
Due to the rapid increase in cyberattacks and damage caused by manipulation, the new Machinery Regulation will, in future, also require protection against the corruption of safety functions – of controllers, for example – and thus sets out requirements for industrial security. The concept of machinery safety is being redefined.
The EU has introduced legal requirements for industrial security for engineering on three levels. There are requirements for machinery, products with digital elements, and companies:
- The Machinery Regulation applies to machinery.
- The Cyber Resilience Act (CRA) defines cybersecurity requirements on products with digital elements.
- And the NIS 2 (Network and Information Security 2) Directive focuses on enhancing cybersecurity across the EU, and applies to almost all companies with more than 50 employees.
This presents industry with a huge task. All three laws have already been published by the EU. The clock is already ticking for the first two, and industry now has around 18 months to adapt development, production and engineering accordingly, including all associated processes and tasks such as training and documentation. This is a truly mammoth task – as was the original implementation of the Machinery Directive.
I’ve already mentioned the Machinery Regulation. The CRA requires that products with digital elements are designed, developed and manufactured in accordance with basic cybersecurity requirements. In concrete terms, this means that there are now requirements for risk assessment and assurance, vulnerability management, documentation and reporting obligations.
This affects Pilz too. In order to implement this, several years ago we introduced a certified “secure” process for product development in accordance with IEC 62443-4-1, and had it certified in 2022. That allows us to guarantee that our developments comply with the CRA.
We have an extensive product portfolio and each product has had to be assessed to determine the extent to which it is affected by the CRA and whether it may need to be adapted. This necessary measures were introduced at an early stage.
The third piece of legislation, the EU’s NIS-2 Directive, which obliges companies to prepare for cyberattacks, has to be transposed into national law. Nine of the 27 EU member states have completed this. In the remaining countries – including Germany and Austria – political circumstances have sometimes prevented laws from being passed.
A cyberattack victim’s viewpoint
Based on our own experience of being the victim of a cyberattack in 2019, I can say that it would be disastrous to wait until there is agreement at the political level before implementing security protection measures. It’s not about fulfilling legal requirements, but about securing companies and their continued existence.
With all of the new requirements, the question arises as to whether other markets besides the EU will also face up to the new challenges, such as AI or cybercrime. To answer that, I’d like to return to the successful CE marking model.
As with the Machinery Directive, European laws and standards will probably serve as worldwide models when it comes to AI and cybersecurity. Most governments have a strong interest in ensuring that their citizens are as well protected as possible from these hazards, while machine-builders and manufacturers are keen to be able to market their products worldwide. This means that economic operators outside the EU will also have to meet the new requirements if they wish to continue exporting to the EU.
Security has many facets that affect us, our partners, customers and society in general. The new approval process in India and the new AI and security requirements in the EU are examples of how important it is to have functioning cross-market cooperation.
Laws and international standards are key. They help us to rely on global technical security mechanisms.

