Tidewell Robotics

Twenty January 2027

The Machinery Regulation applies on 20 January 2027 — a date the Official Journal first printed wrong. It puts machines whose safety functions learn onto a third-party route with no self-declaration. We found the bodies that can do that assessment and named them. What nobody has published is the standards list the route is built on.

Insight · 10 September 2026 · Updated 11 September 2026 · 13 min read · Tidewell Article Crew, edited by Timothy Mo

The Machinery Regulation does not apply on 14 January 2027. The Official Journal says it does. Regulation (EU) 2023/1230 was published in OJ L 165 on 29 June 2023, and Article 54, second paragraph, as printed there, reads:

It shall apply from 14 January 2027.

Five days later OJ L 169 of 4 July 2023 carried a corrigendum correcting fourteen dates. Item 10:

On page 39, Article 54, second paragraph: for: 14 January 2027, read: 20 January 2027.

The Commission's own machinery page, read on 11 September 2026, calls it "a clerical error as regards the application dates in the original version". We open on a typographical error on purpose. Everything below is a claim about a document, and a reader who checks the first one we cite will find it saying something else.

On 20 January 2027 Directive 2006/42/EC is repealed, under Article 51(2) as corrected by item 5 of the same corrigendum. The transitional provision is narrower than it is usually described: Article 52(1) protects only products "placed on the market in conformity with Directive 2006/42/EC" before that date, and Article 52(2) leaves EC type-examination certificates valid until they expire. No sentence grants a grace period for new placements and none refuses one — only a repeal, and a grandfather clause reaching backwards.

This piece is about what the Regulation does to machines whose safety functions learn. The route exists, the assessors exist, the requirements exist, and the measuring stick does not. The last of those is what a buyer should be asking about, and it is not what the industry is discussing. That last clause is a measurement rather than an impression, and the piece closes on it.

This is a reading of published instruments by an engineering company. It is not legal advice.

What the Regulation says about machines that learn

Annex I lists the categories of machinery routed to the procedures in Article 25(2) and (3). Part A is the half routed to 25(2). Items 5 and 6:

5. Safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions.

6. Machinery that has embedded systems with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions that have not been placed independently on the market, in respect only of those systems.

Two items, not one: item 5 is the component sold on its own, item 6 the same thing embedded and never sold separately. Recital 55 narrows both — the provisions "should not apply to software incapable of learning or evolving, and programmed only to execute certain automated functions". A learned planner is not caught by learning. It is caught by learning and ensuring a safety function.

Article 25(2) is what Part A costs. A Part A manufacturer applies one of exactly three procedures: EU type-examination (module B) plus conformity to type (module C); full quality assurance (module H); unit verification (module G). All three require a notified body. Module A — internal production control, the self-declaration route that carries most machinery onto the market — appears nowhere in 25(2). It is in 25(3), for Part B, and in 25(4) for anything Annex I does not list.

Article 25(3) does something the debate about this Regulation has largely missed. For a Part B product, module A is available only where the manufacturer designs "in accordance with the harmonised standards or common specifications specific to that category […] covering all the relevant essential health and safety requirements". Where the design does not, 25(3) sends that manufacturer to a notified body anyway. An absent harmonised standard does not leave a hole in a safety file; it closes the self-declaration route. A sibling piece sets the relevant scope statements side by side, and a legged robot working around the public in a hospital falls outside all of them: that argument is there, and this piece assumes it. Article 25(3) turns it into a conformity route.

One admission belongs here rather than at the end. Until somebody here read the Official Journal on 11 September 2026, our own files carried three different renderings of the clause above. Each partly right, none of them the text.

The assessors exist, and here is how to check

The register of notified bodies is called NANDO. Its old address now redirects to the Single Market Compliance Space, where every path returns the same 151,613-byte shell: the interface is JavaScript, and an automated request gets no data. It defeated three attempts here before one got through.

It is readable, and the detail that makes it readable is small enough to print. The shell's own bundle names its backend — the Europa Search API — and carries, compiled into it, the public key and the datasource name the register answers on. The call is a multipart POST; a GET returns HTTP 500, which is probably why nobody bothers. What stopped the first three attempts is smaller again: the query has to be sent as a file part typed application/json, not as an ordinary form field. Sent as a field it comes back Invalid Query format, which reads like a malformed query and is not one. Past that, the register answers with full notification records as JSON.

Every notification in the register whose indexed text contains "self-evolving" — 2,720 of them — was retrieved on 11 September 2026 and filtered to Regulation (EU) 2023/1230, and on that day three notified bodies held current designations covering Annex I Part A item 5, two of them item 6 as well:

Notified bodyCountryPart A itemsModules
NB 2261 — TUV CYPRUS LTDCyprus5 and 6B, G, H
NB 1073 — Danish Technological Institute Dancert A/SDenmark5 and 6B, G
NB 2957 — Intercert Global Sp. z o.o.Poland5 onlyB, G

The register's product-category strings reproduce the Annex text word for word, prefixed by part and item number. That is what makes the sweep exact rather than approximate: the phrase we searched is the Annex's own, so a designation for item 5 cannot fail to match it. It is also a second Commission system confirming our transcription of the first — corroboration, not independence, since both are the Union's own. The earliest approval on the record is 25 March 2025, on a version since superseded and renewed; the earliest designation current on the day we read it was approved on 1 December 2025. Not an accident: Article 54's third paragraph brought Articles 26 to 42, the notification chapter, into application on 20 January 2024, three years before the rest.

Two limits, in the same breath as the finding. Three is the count on one day and not a standing fact: what bounds it is the register's own currency rather than our search, and a body notified on the twelfth would not appear in a sweep run on the eleventh. And a designation is a scope, not an activity — nothing there says any of them has issued a certificate for a self-evolving safety component. It says they are permitted to try.

Three bodies for a Union of twenty-seven is a small number, and one body offering module H is a smaller one. Neither is the point. The assessors are the half of this that is in working order: a manufacturer needing module B, G or H for a safety component that learns can name who to call today, and check the name in an afternoon.

The requirements exist too, and one of them is our own rule

Annex III carries the essential health and safety requirements, and section 1.2.1, on control systems, already contains a paragraph addressed to nothing but machines that learn. It binds on 20 January 2027 whatever else is or is not published:

Control systems of machinery or related products with fully or partially self-evolving behaviour or logic that are designed to operate with varying levels of autonomy shall be designed and constructed in such a way that: (a) they shall not cause the machinery or related product to perform actions beyond its defined task and movement space; (b) recording of data on the safety related decision-making process for software based safety systems ensuring safety function […] is enabled and that such data is retained for one year after its collection […]; (c) it shall be possible at all times to correct the machinery or related product in order to maintain its inherent safety.

The first list in the same section, at point (f), adds a second clock: the tracing log of safety-software versions uploaded after placing on the market runs five years from upload.

Limb (a) is, in one sentence, the boundary our architecture draws. The Brain page states why, and the reason is latency. The standards assume local safety, and measured 5G e-stop paths show tails of 100 to 150 ms, so the learned layers sit strictly above a deterministic spine they cannot reach past. The Regulation drew the same line in 2023, for conformity.

That is convergence, and convergence is not conformity. The Regulation does not bless this architecture. An essential requirement is something a manufacturer demonstrates against a standard, in a file an assessor reads, and none of that has happened here. What is true is narrower: a constraint we adopted for a radio-latency reason and a legal requirement written for another landed on the same sentence. Anyone reading limb (a) as a certificate is reading it wrong, ourselves included.

  1. The layers that learn — strictly above the line

    Task planner and verifier30 to 70B model, on the site server, 0.5 to 3 s per call
    Local planner7 to 8B model, on the robot, 40 to 80 tokens per second
    Manipulation policy3B-class VLA, on the robot, 10 to 25 Hz
    Cleanliness scoringOn the robot, on a sealed depth channel and a wrist channel — fixture geometry and cleanliness, never occupancy or people detection

    Every one of them can change behaviour after the machine is sold. None of them ensures a safety function, which is the whole reason the line sits where it does.

  2. The line — Annex I Part A, items 5 and 6A safety component, or an embedded system never placed on the market on its own, with "fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions". What crossing it costs is Article 25(2): EU type-examination (module B) with conformity to type (module C), or full quality assurance (module H), or unit verification (module G). A notified body on all three. No module A.
  3. The deterministic spine — below the line

    Safety controllerDesigned to PL d, independent of the compute above it
    Safety lidarIEC 61496 Type 3
    Protective stopE-stop, geofence, speed and separation, on the robot, 100 Hz, under 10 ms

    Fixed logic, nothing learned anywhere in it, and nothing above the line reaching into it. That is our rule for where the boundary goes; whether it is also the legal boundary is settled by the clause and not by this drawing.

The layers above propose. The spine below disposes, and nothing above the line can reach past it.

  • Our compute — everything in this group learns
  • The legal line, and the safety domain beneath it
  • The deterministic chain — no model output reaches it
Where we drew the line, and where the Regulation draws one. The position is our design rule, published on the Brain page for a latency reason — the standards assume local safety, and measured 5G e-stop paths show tails of 100 to 150 ms — so nothing that learns is permitted to ensure a safety function. The legal line is the clause quoted above, Annex I Part A items 5 and 6 of Regulation (EU) 2023/1230, OJ L 165, 29.6.2023, and not this drawing: the drawing is an architecture, the clause is the test. Convergence is not conformity. Nothing in this figure has been assessed by anyone, and the Regulation does not certify this architecture. Layer names, rates and the safety-monitor budget are as published on the Brain page; the modules are Article 25(2).

The Regulation has a second edge for anyone bolting new compute onto a machine somebody else certified. Article 3(16) defines substantial modification as a modification

by physical or digital means after that machinery or related product has been placed on the market or put into service, which is not foreseen or planned by the manufacturer, and which affects the safety of that machinery or related product, by creating a new hazard, or by increasing an existing risk, which requires: (a) the addition of guards or protective devices to that machinery or related product the processing of which necessitates the modification of the existing safety control system; or (b) the adoption of additional protective measures to ensure the stability or mechanical strength of that machinery or related product;

That is a closed four-part test, and all four limbs have to be met. Article 18 supplies the consequence: whoever carries out a substantial modification "shall be considered to be a manufacturer for the purposes of this Regulation" and "shall apply the relevant conformity assessment procedure as provided in Article 25(2), (3) and (4)" — back to the same three-way choice as the original manufacturer, Part A included.

Brain Kit is a retrofit kit: our compute and an independent safety controller mounted on a third-party body the customer already owns. Against the test rather than a paraphrase, the position is conditional in both directions. A retrofit the base manufacturer neither foresaw nor planned, that increases risk, and that needs protective devices whose processing necessitates modifying the existing safety control system, is substantial. Whoever fits one becomes the manufacturer of a new machine. One the manufacturer foresaw and planned for is not substantial at all. Which of the two any given kit on any given body is depends on that body's documentation.

What is missing, and what a buyer should ask

The Commission publishes harmonised standards for machinery by implementing decision. The current one is Implementing Decision (EU) 2023/1586 of 26 July 2023, drafted in support of Directive 2006/42/EC and amended seven times, most recently on 4 September 2026. That is one week before we read the page, and it still supports the instrument that dies in four months. Implementing decisions citing harmonised standards drafted in support of Regulation (EU) 2023/1230: zero on that page, read on 11 September 2026 — the Commission's own harmonised-standards list for machinery, and not a sweep of the Official Journal's L series [single source]. Article 25(3) is why that zero is the story and not a footnote.

The second absence is the AI-specific one. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published on 24 July 2026 and entered into force on 27 July 2026. Its Article 1(41) moves Regulation (EU) 2023/1230 from Section A to Section B of Annex I to the AI Act. Recital 42 adds a qualifier: the AI Act's application to those machines "should be limited to the provisions referred to in Article 2(2) of that Regulation". The Omnibus relocates that substance into the Machinery Regulation rather than removing it, and the Commission must adopt delegated acts amending Machinery Annex III to carry the AI Act's high-risk requirements across. That duty is enacted, not merely recited: Article 3(1) of the Omnibus writes it into Machinery Article 8 and closes it with a date — "Those delegated acts shall apply by 2 August 2028." That is eighteen months after the obligation they belong to begins [inference, arithmetic on two published dates]. No proposal for one appears in the Commission's consultation register as read on 11 September 2026 [single source]; that register covers initiatives at planning or feedback stage, so one in internal preparation need not appear. A bounded negative, and it should be read as one.

The Omnibus did notice the gap. It inserts a new Article 20(10) into the Machinery Regulation:

Until harmonised standards or common specifications are referenced or adopted pursuant to this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards referenced, or common specifications adopted pursuant to Articles 40 and, respectively, 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III to this Regulation as regards high-risk AI systems.

Two things about that provision we could not establish, and we will not characterise it without them. Whether AI Act harmonised standards exist to be relied on, we could not verify. And the presumption attaches to Annex III "as regards high-risk AI systems" — requirements the delegated act has not yet written — which reads either as a bridge to a destination that does not exist, or as the bridge a manufacturer will need the day it appears. It leaves the rest of the machinery essential requirements alone, and that is where the missing list actually bites. Neither a rescue nor a dead letter.

In force on 20 January 2027

  • The route — Annex I Part A items 5 and 6, then Article 25(2)Module B with module C, or module H, or module G — a notified body on each, and module A, self-declaration, on none of them. Article 25(3) reaches further than Part A: for a Part B product module A is open only where the design follows harmonised standards "covering all the relevant essential health and safety requirements".
  • The requirements — Annex III 1.2.1Binding on the same date, delegated act or no delegated act. A self-evolving control system "shall not cause the machinery or related product to perform actions beyond its defined task and movement space"; data on the safety related decision-making process is retained one year; the tracing log of safety-software versions uploaded after placing on the market runs five years.
  • The assessors — three notified bodiesCurrent designations under Regulation (EU) 2023/1230 covering Annex I Part A item 5, read from the register on 11 September 2026: NB 2261 in Cyprus, NB 1073 in Denmark, NB 2957 in Poland. Two of them, NB 2261 and NB 1073, cover item 6 as well, and NB 2261 alone offers module H. The earliest approval on the record is 25 March 2025, on a version since superseded.

Not published, read on 11 September 2026

  • Harmonised standards under Regulation (EU) 2023/1230Zero implementing decisions. The list that exists, Implementing Decision (EU) 2023/1586, is drafted in support of Directive 2006/42/EC and was amended for the seventh time on 4 September 2026 — supporting the instrument that is repealed on 20 January 2027.
  • The delegated act carrying the AI requirements into Annex IIIDue to apply by 2 August 2028 under Regulation (EU) 2026/1744, against an obligation that begins on 20 January 2027. No proposal for it appears in the Commission's consultation register.
  • In force on 20 January 2027, and checkable today
  • Not published as of 11 September 2026
The asymmetry is the argument. On 20 January 2027 a machine whose safety functions learn has a route, a set of requirements and a choice of assessors — and no published document to be assessed against. The first lane's count is a sweep and not a floor: every notification in the register whose indexed text contains "self-evolving" was retrieved through the Europa Search API on 11 September 2026 and filtered to this Regulation, and because the Annex item's own words are the phrase searched, a designation for item 5 cannot fail to match. Three bodies on that day, and what bounds that is the register's currency rather than our search. A designation is also a scope and not an activity — nothing in the register says any of these bodies has assessed a safety component that learns; it says they are permitted to. In the second lane, "no proposal in the consultation register" is a bounded negative: that register covers initiatives at planning or feedback stage, so a delegated act in internal preparation would not appear in it, and the reading is a single source. Sources: Regulation (EU) 2023/1230, OJ L 165, 29.6.2023; Regulation (EU) 2026/1744, OJ L, 24.7.2026; NANDO and the Commission's harmonised-standards page for machinery, both read 11 September 2026.

None of this stands alone, and the wiring is the legislature's rather than our reading. Recital 53 of the Cyber Resilience Act, Regulation (EU) 2024/2847, names Machinery Annex III sections 1.1.9 and 1.2.1 by number as requirements its own cybersecurity essentials help satisfy. Its Article 14 reporting duties — a 24-hour early warning, a 72-hour vulnerability notification — have applied since 11 September 2026, and Article 69(3) extends them to products already on the market.

From 9 December 2026 the new Product Liability Directive, Directive (EU) 2024/2853, applies. Its Article 11(2) closes four after-sale escapes: the defence that the defectiveness "came into being after that moment" fails where the defectiveness is due to a related service, to software including updates or upgrades, to a lack of safety updates, or to a substantial modification — in each case "provided that it is within the manufacturer's control". Substantial modification there is Article 4(18), which hands the threshold back to the product-safety rules: for machinery, the four-part test above.

A buyer signing a robot contract in 2027 can ask three questions with checkable answers: which instrument the vendor declares under, which notified body, under which modules. The register holding those answers can be read by anyone willing to POST to the right endpoint. The fourth question has no published answer today, and it is the one to listen hard to: against which standard.

One last measurement, for anyone who thinks this is a solved topic. A whole-forum search of the ROS community's own Discourse for "safety certification machine learning policy", re-run on 11 September 2026, returns exactly one result: a post from 27 March 2019 whose content is a meeting's attendee list. The one thread describing this boundary as a working system is Julio Chinchilla's, 20 August 2026, in which "the model proposes intents; a deterministic layer validates each one against the device's declared capabilities before anything reaches the hardware, and the device's own safety function runs underneath, independent of the model". It had three posts and 155 views when we read it three weeks later.

One hundred and fifty-five views is the size of the audience currently reading about the thing that binds in four months.