ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
Regulation (EU) 2023/1230

EU Machinery Regulation 2023/1230

The Machinery Regulation modernises EU machinery safety law and, for the first time, brings cybersecurity and AI-enabled safety functions squarely into scope. Where a robot policy performs a safety function, its resilience to manipulation becomes a machinery-safety concern.

Applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).Evidence, not certification.
What it is

The framework

  • Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC.
  • It introduces essential health and safety requirements covering protection against corruption and the safety-relevant behaviour of machinery with evolving or autonomous behaviour.
  • Software that performs a safety function, and machinery with fully or partially self-evolving behaviour, are explicitly addressed.
The hook

Where a red-team result fits

Protection against corruption

Safety components must be protected against accidental or intentional corruption; a hijackable policy driving a safety function is a corruption pathway.

Autonomous behaviour

Machinery with self-evolving behaviour must remain safe — which requires testing what the policy does under adversarial conditions.

What Provael maps to it

Evidence produced

  • Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation.
  • A measured redirection rate toward a simulated keep-out-zone violation, with its confidence interval.
  • A reproducible trace supporting the technical documentation for a machinery conformity assessment.
  • The provael certify command builds a conformity-assessment evidence dossier (OSCAL assessment-results + print-to-PDF HTML) in two profiles: Annex I Part A (third-party route, Article 6(1) → Article 25(2), for self-evolving-behaviour safety components) and Annex III.
  • Standing-assurance / per-checkpoint regression maps to Annex III §1.1.9 (safe behaviour across updates).
Flagship capability · v0.18

provael certify — the conformity-assessment evidence dossier a notified body reviews for an ML-based safety component

  • Two profiles: Annex I Part A — the third-party route via Article 6(1) → Article 25(2), for safety components with self-evolving behaviour — and Annex III.
  • Emits OSCAL assessment-results plus a self-contained, print-to-PDF HTML dossier you can hand to an assessor.
  • Standing-assurance and per-checkpoint regression map to Annex III §1.1.9 (safe behaviour across updates).
Read this

Evidence input to a conformity assessment — it is NOT a conformity assessment, it is NOT a certificate, and Provael is NOT a notified body.

Timing

Dates (verified 6 Jul 2026)

Applies
20 January 2027
Article 54, as corrected by the Corrigendum of 4 July 2023. Some secondary sources cite an incorrect January date; the correct application date is 20 January 2027.
How to read this mapping

What it is — and isn’t

  • adversarial-only — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
  • evidence-not-certification — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.