Talk to Luna
About TTAN.IO

TTAN.IO Robotics / EU regulatory map

EU robotics cybersecurity.
Know the law before the robot moves.

Robotics in Europe does not sit under one single “robot law”. A robot can simultaneously be machinery, a product with digital elements, a connected product, radio equipment, an AI system, workplace equipment and — depending on its use — a medical device, drone or ATEX product. TTAN.IO Robotics tracks these layers separately so cybersecurity architecture, evidence and operational governance can be mapped to the obligations that actually apply.

Built to support compliance with new EU robotics cybersecurity requirements.

Regulatory principleOne robot. Multiple legal layers.

Applicability depends on product role, intended purpose, market placement, connectivity, AI function, sector, operator and Member State implementation where a Directive is involved.

The laws we design around.

These are the central EU legal instruments a modern connected or AI-enabled robot may need to consider. “Core” means broadly relevant to the TTAN.IO Robotics architecture; “when applicable” depends on the robot, economic-operator role and deployment.

CORE · CYBERSECURITY

Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847

Horizontal cybersecurity requirements for products with digital elements. It addresses cybersecurity risk assessment, secure-by-design/default properties, vulnerability handling, support periods, documentation, conformity and reporting.

Robotics relevance: connected robot software, gateways, controllers and other digital products can fall within CRA scope. Article 14 reporting starts 11 September 2026; the Regulation applies generally from 11 December 2027.

Official EU text →
CORE · MACHINERY

Machinery Regulation

Regulation (EU) 2023/1230

The next EU machinery framework, applicable from 20 January 2027. Annex III explicitly addresses protection against corruption of connected machinery, safety-critical hardware/software/data and evidence of legitimate or illegitimate intervention.

Robotics relevance: industrial robots, robot cells and machinery integrating connected or software-controlled functions. Cyber compromise that can create a hazardous situation becomes directly relevant to machinery compliance.

Official EU text →
TRANSITION · CURRENT MACHINERY LAW

Machinery Directive

Directive 2006/42/EC

Still part of the current machinery conformity framework for products placed on the market before the Machinery Regulation transition. It is repealed with effect from 20 January 2027.

Robotics relevance: manufacturers and integrators must manage the 2026–2027 transition carefully rather than pretending the new Regulation already replaced every current conformity route.

Official EU text →
CORE WHEN AI APPLIES

EU AI Act

Regulation (EU) 2024/1689

Risk-based rules for AI systems. The Regulation applies generally from 2 August 2026, with phased dates for certain high-risk requirements. AI used as a safety component of products covered by Annex I legislation can enter the high-risk product route.

Robotics relevance: AI-enabled manipulation, navigation, perception, decision support or safety-related functions may create AI Act obligations. Not every robot using AI is automatically high-risk.

Official EU text →
CORE WHEN ENTITY IN SCOPE

NIS2

Directive (EU) 2022/2555

Entity-level cybersecurity risk-management, governance, supply-chain and incident-reporting duties implemented through Member State law. It covers many essential/important sectors and includes certain manufacturing categories.

Robotics relevance: NIS2 usually regulates the organisation operating or manufacturing systems, not the individual robot as a product. TTAN.IO evidence can support operational cybersecurity and incident reconstruction.

Official EU text →
CONNECTED PRODUCTS

EU Data Act

Regulation (EU) 2023/2854

Rules on access to and use of data generated by connected products and related services. It applies from 12 September 2025, with specific product-design/data-access obligations phased for connected products placed on the market after 12 September 2026.

Robotics relevance: industrial and service robots generate operational, sensor, maintenance and usage data. Security architecture must not confuse legitimate data access rights with command authority.

Official EU text →
PERSONAL DATA WHEN APPLICABLE

GDPR

Regulation (EU) 2016/679

EU personal-data protection rules governing lawful processing, purpose limitation, data minimisation, security, rights and accountability.

Robotics relevance: cameras, microphones, biometrics, location, workforce telemetry, human-robot interaction and cloud analytics can process personal data. Robotics telemetry is not automatically “machine-only” data.

Official EU text →
LIABILITY

Product Liability Directive

Directive (EU) 2024/2853

Modernised strict product-liability framework that expressly recognises software as a product and addresses digital services/components relevant to product safety. Member States must transpose it by 9 December 2026; it applies to products placed on the market or put into service after that date.

Robotics relevance: software, AI and updates can contribute to product defects and damage. Evidence about versions, decisions, updates and observed outcomes becomes materially important.

Official EU text →
CONSUMER ROBOTS WHEN APPLICABLE

General Product Safety Regulation

Regulation (EU) 2023/988

General EU product-safety framework applicable since 13 December 2024, especially relevant where consumer products are not fully covered by more specific harmonisation rules.

Robotics relevance: consumer/service robots, connected domestic devices and other products sold to consumers can create GPSR duties alongside sector-specific rules.

Official EU text →
WIRELESS ROBOTS · TRANSITION

Radio Equipment Directive + cyber requirements

Directive 2014/53/EU · Delegated Regulation (EU) 2022/30 · Regulation (EU) 2026/339

Wireless/radio equipment can be subject to RED essential requirements. Cybersecurity requirements activated for specified radio-equipment categories from 1 August 2025 remain relevant during the transition. The 2022/30 delegated act is repealed from 11 December 2027 as the CRA takes over the horizontal product-cybersecurity role.

Robotics relevance: Wi-Fi, Bluetooth, cellular and other radio-enabled robots or accessories can trigger RED obligations independently of ROS/DDS security.

RED official text →
2026 transition act →
EU CYBER CERTIFICATION FRAMEWORK

EU Cybersecurity Act

Regulation (EU) 2019/881

Establishes ENISA’s role and the EU framework for cybersecurity certification schemes for ICT products, services and processes.

Robotics relevance: not a generic “robot certification”, but an important part of the wider EU cybersecurity assurance landscape that can affect components and services used by robotics systems.

Official EU text →
MARKET ENFORCEMENT

Market Surveillance Regulation

Regulation (EU) 2019/1020

Framework for market surveillance and enforcement of EU harmonisation legislation, including powers to require technical information and take corrective measures against non-compliant products.

Robotics relevance: conformity is not only documentation at launch. Authorities can inspect technical evidence and embedded software where necessary to assess compliance.

Official EU text →

The robot’s job changes the legal stack.

The following instruments are not universal to every robot, but become important when the deployment enters the corresponding sector or product category.

MEDICAL ROBOTS

Medical Device Regulation (MDR)

Regulation (EU) 2017/745

Surgical robots, rehabilitation robots and other medical-purpose systems can fall under the MDR. Software, lifecycle controls, risk management and post-market obligations become part of the medical-device conformity framework.

Official EU text →
EXPLOSIVE ATMOSPHERES

ATEX Product Directive

Directive 2014/34/EU

Applies to equipment and protective systems intended for use in potentially explosive atmospheres. Robots deployed in chemical, energy, mining or similar environments can require ATEX analysis.

Official EU text →
DRONES / AERIAL ROBOTS

EU UAS product rules

Delegated Regulation (EU) 2019/945

Product and technical requirements for unmanned aircraft systems and third-country UAS operators, relevant when the “robot” is an aerial system.

Official EU text →
DRONE OPERATIONS

EU UAS operating rules

Implementing Regulation (EU) 2019/947

Operational rules and procedures for unmanned aircraft. Cybersecurity architecture must coexist with aviation/operational constraints rather than replace them.

Official EU text →
ELECTRICAL / EMC WHEN APPLICABLE

EMC and Low Voltage frameworks

Directives 2014/30/EU and 2014/35/EU

Electromagnetic compatibility and electrical-safety rules can apply to robot components and equipment. These are not cybersecurity laws, but they remain part of product compliance and must not be conflated with cyber controls.

EMC →
Low Voltage →
WORKPLACE USE

Worker safety / work equipment rules

Directive 89/391/EEC · Directive 2009/104/EC

Employers have workplace safety and work-equipment duties. A CE-marked robot does not remove the operator’s obligations to assess deployment, workplace conditions and safe use.

OSH Framework →
Work Equipment →
Important:

This map is deliberately broad. Applicability is determined per product, intended purpose, sector, economic-operator role and deployment. It is not a declaration that every listed law applies to every robot.

Standards help turn legal requirements into engineering practice.

TTAN.IO keeps standards separate from legislation. A standard may be voluntary, contractual, sector-required or harmonised to support presumption of conformity under specific EU legislation. Its legal effect depends on context.

Compliance support is designed into the evidence chain.

01

Identity + provenance

Who or what requested the action, which software/provider context was involved and which trusted identity was presented.

02

Approved behavior

Per-robot baseline and controlled change help distinguish intended behavior from drift or unauthorized modification.

03

Exact authority

Authentication or connectivity alone never becomes permission for arbitrary physical action.

04

Runtime evidence

Requested, authorized, executed, observed and reconciled states remain distinguishable and attributable.

05

Human-first governance

HUMAN_REQUIRED and bounded approval preserve human decision points where risk or policy requires them.

06

Recovery without authority resurrection

Returning to a known-good software state does not automatically authorize renewed physical motion.

What TTAN.IO can claim — and what it does not claim.

We can sayWe do not claim
Built to support compliance with new EU robotics cybersecurity requirements.That TTAN.IO deployment automatically makes a robot legally compliant.
Architecture maps technical controls and evidence to applicable regulatory requirements.That a technical control is the same as a formal conformity assessment.
TTAN.IO preserves evidence useful for audit, incident reconstruction and compliance work.That TTAN.IO replaces a notified body, legal authority, safety assessor or manufacturer declaration.
TTAN.IO complements ROS/DDS, functional safety, OT security, PKI, secure boot and vendor controls.That TTAN.IO replaces certified functional-safety or product-safety systems.
Current TTAN.IO Compliance model:

Engineering readiness, technical evidence and framework mapping remain intentionally separate from formal compliance, certification, CE/conformity and market-authorisation decisions. Those formal claims require the appropriate human/legal/conformity authority.

← Back to Robotics Security Layer