Zurück zu allen Beiträgen
·8 Min. Lesezeit

Sie haben einen Roboterhund nachgerüstet. Nach EU-Recht sind Sie jetzt womöglich sein Hersteller.

Here's a project we see constantly. A company buys an off-the-shelf quadruped. They bolt a pan-tilt-zoom camera and a LiDAR mast onto it, replace the vendor's teleoperation app with their own ROS 2 autonomy stack, and add a docking station so it can charge itself between inspection rounds. Six months later they have a robot that walks the plant on its own every night. It's a great result, and it's exactly what we help clients build.

From 20 January 2027, that same project may also have quietly turned the company into the robot's legal manufacturer.

That's the day the EU Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC, which has governed machine safety in Europe since 2009. There's no transition period. Until 19 January 2027 the Directive applies; from 20 January only the Regulation does. Most of the coverage focuses on what changes for OEMs. Far less attention goes to the people modifying machines after they've shipped. In robotics, that's a lot of people.

This post reflects our engineering reading of the Regulation, not legal advice. For a specific product, talk to your conformity-assessment body or legal counsel.

The rule: modify it substantially, and you're the manufacturer

Article 18 of the Regulation is short. Anyone other than the manufacturer who carries out a substantial modification of a machine "shall be considered to be a manufacturer". They take on the manufacturer's obligations for the part of the machine affected by the change, or for the whole machine if the change affects its overall safety.

In practice, those obligations are the full conformity package:

  • a risk assessment
  • technical documentation
  • a conformity-assessment procedure
  • an EU declaration of conformity
  • CE marking
  • instructions for use

The bar isn't lowered because you "only" changed one thing. And it isn't limited to companies that resell the robot. Putting a substantially modified machine into service for your own use counts too.

The old Directive had no explicit rule on this. Practice was patched together from national guidance, such as Germany's interpretation paper on substantial modification. The Regulation writes it into EU law and adds two words that matter enormously for robotics: "or digital".

What counts as "substantial"

Article 3(16) defines a substantial modification as a change to a machine after it has been placed on the market or put into service that meets three conditions:

  1. It's made by physical or digital means. Software counts. A new autonomy stack, a new motion controller, or a reflashed safety configuration all qualify.
  2. The original manufacturer didn't foresee or plan it. This is the most useful condition for integrators, and we'll come back to it.
  3. It affects safety by creating a new hazard or increasing an existing risk in a way that requires new guards or protective devices (and with them, changes to the safety control system), or extra measures to keep the machine stable or mechanically sound.

So the test isn't "did you touch it". It's: did you do something the OEM didn't plan for, which created a hazard serious enough to need new protective measures? That's still a judgement call. But it's a judgement call you now have to make deliberately and document.

A worked example: four changes to one quadruped

Take the inspection robot from the opening and go through it one change at a time. This is roughly the scope of our own PUMA quadruped project.

1. A camera on the vendor's payload rail. The OEM sells a payload interface, publishes a maximum payload mass, and documents the mounting points. If you stay inside that envelope, the modification was foreseen by the manufacturer, and it's very likely not substantial. Keep the datasheet and your mass calculation anyway.

2. A heavier PTZ head and a LiDAR mast. Now you're raising the centre of mass on a machine whose stability depends on an active balance controller. If you're outside the published payload envelope, or inside it on paper but with a geometry the OEM never tested, you're getting close to condition 3, "additional measures to ensure stability". This is where a modification starts becoming substantial.

3. Replacing teleoperation with your own autonomy stack. This is the change most teams underestimate. A teleoperated robot has a human in the loop for every movement. An autonomous one plans its own path through spaces where people work. That's a new hazard almost by definition, and covering it usually means new protective measures:

  • people detection
  • speed limits near people
  • defined operating zones
  • a stop function that works without the operator's tablet

It's a purely digital change, and it's exactly what Article 3(16) now covers.

4. Autonomous docking and charging. The robot now drives itself, unsupervised, to a charging station, possibly at night and possibly through occupied areas. The Regulation has a specific requirement for this (see below).

Changes 1 and 2 are mechanical questions most engineers already know how to ask. Changes 3 and 4 are where the new regulation bites, and they're the changes that make these robots worth deploying in the first place.

What you inherit: the new rules for autonomous mobile machines

If you become the manufacturer of an autonomous mobile robot, you don't just inherit the Directive-era obligations. You inherit the essential health and safety requirements in Annex III, which now address autonomy directly:

  • Supervisory function (3.2.4). Autonomous mobile machinery needs a supervisory function that lets a supervisor stop and restart it remotely. Those commands may only be allowed when the supervisor can see the machine, directly or indirectly. A fleet dashboard with a "go" button is not enough on its own.
  • Safety functions on board (3.3). The machine's control system must perform its safety functions by itself, even though a remote supervisor exists. Stopping when a person steps into its path can't depend on a Wi-Fi link to a control room.
  • Defined operating areas (3.3.3, 3.6.3.3). Depending on the risk assessment, the machine may have to operate in an enclosed zone with a peripheral protection system. Either way, the instructions must describe its intended travel paths, working areas and danger zones.
  • Automatic charging (3.5.1). Batteries with automatic charging must be designed to avoid electrical and moving-part hazards, including collisions with people or other machines while the robot moves itself to the charger.
  • Sharing space with people (1.3.7). Contact risks and the psychological stress of working near a moving machine must be addressed, both for coexistence in a shared space and for direct interaction. A 50 kg quadruped coming round a blind corner at night is exactly the case this was written for.
  • Protection against corruption (1.1.9). Software and data that are critical for compliance must be protected against accidental or intentional corruption. If you can push a new navigation build to the fleet over the air, you need to show the safety-relevant parts can't be silently altered.

One more trap for teams working with learned policies. Under Annex I Part A, safety components and machines with fully or partially self-evolving behaviour based on machine learning need third-party conformity assessment by a notified body. If your autonomy update puts a learned model in charge of a safety function, the self-certification route is closed.

Two laws, two tests

The Machinery Regulation isn't the only EU law with a "substantial modification" rule. The Cyber Resilience Act (CRA) has one too, and it's a different test.

Under the CRA, a substantial modification is a change after the product is placed on the market that affects its compliance with the essential cybersecurity requirements, or changes its intended purpose. Anyone other than the manufacturer who makes such a change and then makes the product available on the market is treated as its manufacturer (Article 22).

That gives you two separate questions for every change:

  • The Machinery Regulation asks: does it create a new hazard that needs new protective measures? This applies even to machines you only use yourself.
  • The CRA asks: does it affect the cybersecurity posture or the intended purpose? This bites when you put the product on the market: selling it, renting it out, or deploying it for clients.

Adding remote fleet access, a cloud connection or an over-the-air update channel to a robot dog can easily be substantial under the CRA while being harmless under the Machinery Regulation, and the reverse is just as possible. The CRA's vulnerability-reporting duties have applied since 11 September 2026, and its main obligations follow on 11 December 2027. Integrators who make products available should be assessing both laws already.

A checklist before you modify a fleet

Here's what we now do before touching a client's platform:

  • Start from the OEM's envelope. Collect the payload limits, mounting interfaces, SDK documentation and intended-use statement. Every change you can keep inside what the manufacturer foresaw is a change that probably isn't substantial.
  • Run the risk assessment per change, not per project. Run it for the camera, the mast, the autonomy stack and the charger separately. That makes it obvious which change crosses the line, and it gives you the paper trail if anyone asks.
  • Write down the decision either way. "Not substantial, because…" is a document worth having on 21 January 2027.
  • Design the safety chain so the OEM's certified functions stay in charge. If your autonomy stack only ever requests motion through the vendor's safety-rated interfaces, you've changed much less than if it bypasses them.
  • Keep learned models out of safety functions unless you're prepared for a notified body.
  • Check the CRA separately, especially if the robot gets new network access or you deliver it to someone else.
  • Talk to the OEM early. Some vendors will document a payload or software configuration as foreseen use, which is the cleanest way to stay on the right side of Article 3(16).
  • Mind the date. A modification you finish in December 2026 is judged under the Directive. The same modification in February 2027 is judged under the Regulation.

Why this matters

None of this should stop anyone from adapting robots. Adapting a capable off-the-shelf platform is still the fastest and cheapest way to put autonomy into a real plant, and it's a large part of what we do. But from 2027, platform adaptation is also a compliance decision, and it's far cheaper to design with that in mind than to discover it during an audit or after an incident.

If you're planning to adapt quadrupeds, AMRs or humanoids for real deployments and want to work out where your changes land, get in touch. We'd much rather have that conversation before the first bracket is bolted on.

Sources: Regulation (EU) 2023/1230, EUR-Lex (Articles 3(16), 18, 54; Annex I Part A; Annex III sections 1.1.9, 1.3.7, 3.2.4, 3.3, 3.5.1); BAuA on the new Machinery Regulation; Regulation (EU) 2024/2847, the Cyber Resilience Act, EUR-Lex.