These are the central EU legal instruments a modern connected or AI-enabled robot may need to consider. “Core” means broadly relevant to the TTAN.IO Robotics architecture; “when applicable” depends on the robot, economic-operator role and deployment.
CORE · CYBERSECURITYCyber Resilience Act (CRA)
Regulation (EU) 2024/2847
Horizontal cybersecurity requirements for products with digital elements. It addresses cybersecurity risk assessment, secure-by-design/default properties, vulnerability handling, support periods, documentation, conformity and reporting.
Robotics relevance: connected robot software, gateways, controllers and other digital products can fall within CRA scope. Article 14 reporting starts 11 September 2026; the Regulation applies generally from 11 December 2027.
Official EU text →
CORE · MACHINERYMachinery Regulation
Regulation (EU) 2023/1230
The next EU machinery framework, applicable from 20 January 2027. Annex III explicitly addresses protection against corruption of connected machinery, safety-critical hardware/software/data and evidence of legitimate or illegitimate intervention.
Robotics relevance: industrial robots, robot cells and machinery integrating connected or software-controlled functions. Cyber compromise that can create a hazardous situation becomes directly relevant to machinery compliance.
Official EU text →
TRANSITION · CURRENT MACHINERY LAWMachinery Directive
Directive 2006/42/EC
Still part of the current machinery conformity framework for products placed on the market before the Machinery Regulation transition. It is repealed with effect from 20 January 2027.
Robotics relevance: manufacturers and integrators must manage the 2026–2027 transition carefully rather than pretending the new Regulation already replaced every current conformity route.
Official EU text →
CORE WHEN AI APPLIESEU AI Act
Regulation (EU) 2024/1689
Risk-based rules for AI systems. The Regulation applies generally from 2 August 2026, with phased dates for certain high-risk requirements. AI used as a safety component of products covered by Annex I legislation can enter the high-risk product route.
Robotics relevance: AI-enabled manipulation, navigation, perception, decision support or safety-related functions may create AI Act obligations. Not every robot using AI is automatically high-risk.
Official EU text →
CORE WHEN ENTITY IN SCOPENIS2
Directive (EU) 2022/2555
Entity-level cybersecurity risk-management, governance, supply-chain and incident-reporting duties implemented through Member State law. It covers many essential/important sectors and includes certain manufacturing categories.
Robotics relevance: NIS2 usually regulates the organisation operating or manufacturing systems, not the individual robot as a product. TTAN.IO evidence can support operational cybersecurity and incident reconstruction.
Official EU text →
CONNECTED PRODUCTSEU Data Act
Regulation (EU) 2023/2854
Rules on access to and use of data generated by connected products and related services. It applies from 12 September 2025, with specific product-design/data-access obligations phased for connected products placed on the market after 12 September 2026.
Robotics relevance: industrial and service robots generate operational, sensor, maintenance and usage data. Security architecture must not confuse legitimate data access rights with command authority.
Official EU text →
PERSONAL DATA WHEN APPLICABLEGDPR
Regulation (EU) 2016/679
EU personal-data protection rules governing lawful processing, purpose limitation, data minimisation, security, rights and accountability.
Robotics relevance: cameras, microphones, biometrics, location, workforce telemetry, human-robot interaction and cloud analytics can process personal data. Robotics telemetry is not automatically “machine-only” data.
Official EU text →
LIABILITYProduct Liability Directive
Directive (EU) 2024/2853
Modernised strict product-liability framework that expressly recognises software as a product and addresses digital services/components relevant to product safety. Member States must transpose it by 9 December 2026; it applies to products placed on the market or put into service after that date.
Robotics relevance: software, AI and updates can contribute to product defects and damage. Evidence about versions, decisions, updates and observed outcomes becomes materially important.
Official EU text →
CONSUMER ROBOTS WHEN APPLICABLEGeneral Product Safety Regulation
Regulation (EU) 2023/988
General EU product-safety framework applicable since 13 December 2024, especially relevant where consumer products are not fully covered by more specific harmonisation rules.
Robotics relevance: consumer/service robots, connected domestic devices and other products sold to consumers can create GPSR duties alongside sector-specific rules.
Official EU text →
WIRELESS ROBOTS · TRANSITIONRadio Equipment Directive + cyber requirements
Directive 2014/53/EU · Delegated Regulation (EU) 2022/30 · Regulation (EU) 2026/339
Wireless/radio equipment can be subject to RED essential requirements. Cybersecurity requirements activated for specified radio-equipment categories from 1 August 2025 remain relevant during the transition. The 2022/30 delegated act is repealed from 11 December 2027 as the CRA takes over the horizontal product-cybersecurity role.
Robotics relevance: Wi-Fi, Bluetooth, cellular and other radio-enabled robots or accessories can trigger RED obligations independently of ROS/DDS security.
RED official text →
2026 transition act →
EU CYBER CERTIFICATION FRAMEWORKEU Cybersecurity Act
Regulation (EU) 2019/881
Establishes ENISA’s role and the EU framework for cybersecurity certification schemes for ICT products, services and processes.
Robotics relevance: not a generic “robot certification”, but an important part of the wider EU cybersecurity assurance landscape that can affect components and services used by robotics systems.
Official EU text →
MARKET ENFORCEMENTMarket Surveillance Regulation
Regulation (EU) 2019/1020
Framework for market surveillance and enforcement of EU harmonisation legislation, including powers to require technical information and take corrective measures against non-compliant products.
Robotics relevance: conformity is not only documentation at launch. Authorities can inspect technical evidence and embedded software where necessary to assess compliance.
Official EU text →