EU Machinery Regulation 2023/1230: What Changed from the Machinery Directive
If you place machinery on the EU market — or operate it — the rules you have followed for nearly two decades are being replaced. Directive 2006/42/EC will no longer govern machinery placed on the market from 20 January 2027. In its place comes Regulation (EU) 2023/1230, a directly applicable law that changes how machinery is classified, certified, documented, and modified.
This is not a cosmetic update. The shift from a Directive to a Regulation, the new treatment of artificial intelligence, the rules on digital documentation, and the redefinition of who counts as a manufacturer all carry concrete compliance obligations. If your conformity assessment, technical files, and modification controls were built around the old Directive, parts of that work need to change before the application date.
Track machinery compliance findings to closure with WhyTrace Plus. When an audit or design review surfaces a gap against 2023/1230 — a missing risk assessment for an AI safety function, an undocumented modification, an incomplete technical file — WhyTrace Plus turns it into a tracked action with a named owner, a due date, and a required effectiveness check. See how WhyTrace Plus manages compliance actions →
From Directive to Regulation: Why the Legal Form Matters
A Directive sets goals that each EU member state transposes into its own national law. A Regulation applies directly and identically across all member states without national transposition. Regulation (EU) 2023/1230 was adopted on 14 June 2023 and applies from 20 January 2027, repealing and replacing Directive 2006/42/EC on that date.
This change in legal instrument is more than procedural. Under the old Machinery Directive, each country implemented its own transposing legislation, which created small but real divergences in how requirements were interpreted and enforced across borders. As of 2026, the move to a Regulation eliminates that layer.
What this means in practice:
- One text, one interpretation. The same legal wording binds manufacturers in every member state. You no longer reconcile 27 national transpositions of the same requirement.
- No transposition delay or gap. The Regulation's obligations take effect on the application date everywhere at once, rather than rolling out as each country amends its statutes.
- Direct enforceability. National authorities enforce the Regulation text itself, not a domestic copy of it.
The transition is hard-dated rather than gradual. Machinery placed on the EU market before 20 January 2027 may continue to comply with Directive 2006/42/EC. Machinery placed on the market from that date must comply with Regulation (EU) 2023/1230. There is no extended dual-compliance window for products entering the market after the application date, which makes the design and documentation work something you schedule against a fixed deadline.
What Changed: A Side-by-Side View of the New Requirements
The core architecture — essential health and safety requirements, conformity assessment, CE marking, technical documentation — carries over from the Directive. The substance inside that architecture is what shifts. The table below summarizes the changes that most often require action.
| Area | Directive 2006/42/EC | Regulation (EU) 2023/1230 |
|---|---|---|
| Legal form | Directive (transposed into national law) | Regulation (directly applicable EU-wide) |
| Application date | In force since 2009 | Applies from 20 January 2027 |
| Artificial intelligence | Not specifically addressed | Self-evolving and embedded AI safety functions explicitly covered |
| High-risk list | Annex IV | Annex I, restructured with new AI categories |
| Documentation | Paper instructions required | Digital instructions permitted under conditions |
| Substantial modification | Limited explicit treatment | Defined; modifier can become the manufacturer |
| Cybersecurity | Not a standalone requirement | Protection against corruption and unauthorized interference addressed |
Several of these deserve closer treatment because they change the work your engineering, quality, and compliance teams do — not just the paperwork they file. The AI provisions, the documentation rules, and the substantial modification definition are the three that most frequently catch organizations off guard, and they are covered in detail below.
How the Regulation Treats Artificial Intelligence and High-Risk Machinery
Artificial intelligence is the most genuinely new area in the Regulation. The old Directive predates the deployment of machine-learning safety functions and says nothing about them. Regulation (EU) 2023/1230 addresses them directly, and the consequence is a more demanding conformity path for AI-enabled machinery.
If an AI system performs a safety function, the machine is treated as high-risk. The Regulation's high-risk list (Annex I) was restructured to add categories specifically for AI-enabled machinery: safety components that use machine learning with fully or partially self-evolving behaviour, and machinery with embedded AI systems that ensure safety functions.
The practical effects for high-risk classification:
- Mandatory third-party assessment. High-risk machinery loses the self-certification option. A notified body must be involved in the conformity assessment. (Notified-body rules under the Regulation began applying earlier, on 20 January 2024, so the bodies are in place ahead of the main application date.)
- Risk assessment must account for behavioural evolution. For self-learning or self-evolving systems, the risk assessment cannot stop at the machine's behaviour at the moment of placing on the market. It must consider how the AI's behaviour may change over the machine's operational life.
- Documentation covers future operational states. Safety proofs and technical documentation must address possible future states the system could reach, not only its initial configuration.
- Safe fallback is required. AI-based safety functions need fallback modes that let an operator override the AI or bring the machine to a safe stop.
There is also an interaction with the EU Artificial Intelligence Act to plan for. A machine can fall under both the Machinery Regulation and the AI Act, which means your conformity work may need to satisfy two overlapping frameworks rather than one. Treat AI safety functions as a distinct workstream in your compliance plan rather than folding them into general machinery design review.
Turn AI-safety risk assessments into trackable actions. A risk assessment that flags "AI behaviour may evolve" only prevents harm if the resulting controls get implemented and verified. WhyTrace Plus links each identified risk to an owner, a corrective action, and a scheduled effectiveness review — so the analysis your team did against 2023/1230 produces closed-loop results, not a filed document. Explore WhyTrace Plus →
Digital Documentation and Cybersecurity: The New Compliance Surface
The Regulation modernizes two areas the Directive treated lightly or not at all: how instructions are delivered, and how machinery resists tampering with its safety functions.
Digital instructions. Under the Directive, instructions for use generally had to be provided on paper. The Regulation permits instructions and information to be provided in digital form, subject to conditions. This reduces the cost and friction of distributing documentation, but it does not remove obligations — it adds them.
Conditions you should plan for when moving to digital documentation:
- Customers and authorities must be able to access the information, and the manufacturer typically must provide a paper version on request.
- The information has to remain accessible for the expected lifetime of the machinery, which means durable hosting and version control, not a link that breaks after a product refresh.
- Safety-critical information may still need to be supplied in a directly available form rather than behind a download.
Cybersecurity and protection against corruption. The Regulation introduces requirements aimed at protecting machinery — particularly its safety functions — against corruption and unauthorized interference, including remote and software-based attacks. This is a category the 2006 Directive did not address as a standalone requirement. For connected machinery, software-controlled safety functions, and remotely updatable systems, you now demonstrate that a malicious or accidental alteration cannot defeat a safety function.
The combined effect is a wider compliance surface. Documentation control and cybersecurity assurance become part of the technical file and the risk assessment, alongside the mechanical and electrical hazards that the Directive already covered.
Substantial Modification: When the Operator Becomes the Manufacturer
A substantial modification is a change — physical or digital — that introduces a new hazard or increases an existing risk in a way not anticipated by the original manufacturer's risk assessment. This concept existed informally before, but the Regulation gives it explicit treatment, and the consequence is significant for anyone who alters machinery already in service.
Under Regulation (EU) 2023/1230, a party that makes a substantial modification can legally become the manufacturer of the modified machinery. That party — often the operator or a system integrator, not the original equipment maker — then bears the manufacturer's obligations: performing a new conformity assessment, compiling technical documentation, and affixing CE marking for the modified machine.
What counts and what this changes:
- Both hardware and software modifications are in scope. A software change that alters a safety function can be a substantial modification just as a mechanical retrofit can.
- The trigger is increased or new risk. Routine maintenance, like-for-like part replacement, and changes the original manufacturer already covered in the risk assessment are generally not substantial modifications. A change that creates a hazard the original assessment did not address is.
- Liability transfers to the modifier. If you reconfigure a production line, integrate a new robot into an existing cell, or push a software update that changes how a safety function behaves, you may have assumed manufacturer-level responsibility — and the conformity and documentation obligations that come with it.
For operators and integrators, this makes modification control a compliance discipline, not just an engineering one. Before changing machinery in service, assess whether the change is substantial. If it is, plan for a new conformity assessment and the technical file that supports it. Documenting that assessment — including the decision that a change was not substantial — is the evidence you will need if an authority asks why a modified machine still carries its original CE marking.
Building Your Compliance Plan Before the Application Date
The application date is fixed, and the work scales with how much machinery you place on the market or modify. A practical sequencing that works backward from 20 January 2027:
- Inventory. Identify which products you will place on the EU market from the application date, and which deployed machines you may modify. Products placed on the market before that date under the Directive are not automatically caught.
- Gap analysis against the Regulation text. Compare each product's current conformity basis against 2023/1230 — paying particular attention to AI safety functions, high-risk classification, digital documentation conditions, and cybersecurity.
- Reclassify high-risk machinery. Confirm whether any product now falls into a high-risk Annex I category and therefore requires notified-body involvement. Engage a notified body early; capacity is finite.
- Update risk assessments. Extend assessments to cover AI behavioural evolution, cybersecurity threats, and foreseeable future operational states where relevant.
- Rework the technical file. Align documentation with the Regulation, including any move to digital instructions and the conditions attached to it.
- Establish modification controls. Put a documented process in place for deciding whether a change is a substantial modification — before changes are made, not after.
Each gap that this process surfaces is an action that needs an owner, a deadline, and a verification step. The failure mode is not usually a missing requirement; it is a known gap that no one closed before the deadline.
Run your 2023/1230 readiness as tracked corrective actions. WhyTrace Plus takes the gaps from your readiness review and manages them to closure — named owners, severity-tiered due dates, automated escalation when items slip, and a required effectiveness check before anything is marked complete. You see open, overdue, and verified items on one dashboard instead of reconstructing status from a spreadsheet. Request a WhyTrace Plus demo →
Frequently Asked Questions
Q. When does EU Machinery Regulation 2023/1230 apply?
The Regulation applies from 20 January 2027, when it repeals and replaces Directive 2006/42/EC. Some provisions — notably the rules for notified bodies — applied earlier, from 20 January 2024. Machinery placed on the EU market before 20 January 2027 may continue to comply with the old Directive.
Q. Does the Machinery Regulation replace the Machinery Directive completely?
Yes. Regulation (EU) 2023/1230 repeals Directive 2006/42/EC as of 20 January 2027. Machinery placed on the market from that date must comply with the Regulation. Because it is a Regulation rather than a Directive, it applies directly across all EU member states without national transposition.
Q. How does the Regulation treat AI-enabled machinery?
Machinery whose AI system performs a safety function is treated as high-risk. The high-risk list (Annex I) adds categories for self-evolving machine-learning safety components and machinery with embedded AI safety systems. High-risk machinery requires notified-body involvement instead of self-certification, and the risk assessment must account for how AI behaviour may evolve over the machine's life.
Q. What is a substantial modification under the new Regulation?
A substantial modification is a physical or digital change that introduces a new hazard or increases an existing risk beyond what the original manufacturer's risk assessment covered. The party making such a modification can legally become the manufacturer of the modified machinery, taking on the obligations to perform a new conformity assessment and affix CE marking.
Q. Can machinery instructions now be provided digitally?
Yes, the Regulation permits digital instructions subject to conditions — including that users can access the information for the machine's expected lifetime, that a paper version is available on request, and that safety-critical information remains readily available. This is a change from the Directive, which generally required paper instructions.
Key Takeaways
- Regulation (EU) 2023/1230 applies from 20 January 2027 and repeals Directive 2006/42/EC; as a Regulation, it applies directly EU-wide with no national transposition.
- Machinery placed on the market before the application date may follow the old Directive; machinery placed on the market from 20 January 2027 must follow the Regulation, with no extended dual-compliance window.
- AI safety functions trigger high-risk classification, mandatory notified-body assessment, risk assessment covering behavioural evolution, and required safe fallback modes.
- Digital instructions are now permitted under conditions, and cybersecurity protection of safety functions becomes an explicit requirement — both widening the technical-file and risk-assessment scope.
- A substantial modification can make the operator or integrator the legal manufacturer, transferring conformity assessment and CE-marking obligations; modification control becomes a documented compliance discipline.
Related Resources
| Resource | Description | Best For |
|---|---|---|
| ISO 45001 Incident Investigation: Requirements and Best Practices | Clause 10.2 investigation obligations and audit-readiness practices | Connecting machinery safety findings to a structured investigation and CAPA process |
| Corrective Action Management: Stop Losing Track of Your CAPA Items | How to close compliance findings on time with named owners and effectiveness verification | Turning Regulation 2023/1230 gaps into tracked, closed-loop actions |
| Safety Management Trends 2026: AI, IoT, and Regulatory Changes | The broader shift toward AI, connected machinery, and tightening regulation | EHS leaders putting the Machinery Regulation in context with other 2026 changes |