The framework
- Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC.
- It introduces essential health and safety requirements covering protection against corruption and the safety-relevant behaviour of machinery with evolving or autonomous behaviour.
- Software that performs a safety function, and machinery with fully or partially self-evolving behaviour, are explicitly addressed.
- Two adjacent points in Annex I, Part A name the machine-learning cases, verbatim from CELEX 32023R1230. Point 5: "Safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions" - the ML safety component placed on the market on its own. Point 6 covers the embedded case: machinery having embedded systems with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions.
- Which point applies is a determination about what you place on the market, not about the policy. An integrator shipping a whole robot - a humanoid, an AMR - is placing machinery with an embedded ML safety system, so point 6 is the row its file is routed under; a supplier selling the safety component alone is under point 5. Both route to the same third-party procedure of Article 25(2) via Article 6(1), and provael certify emits both rows rather than answering the question for you.
- Annex I Part B point 19 is the Article 25(3) sibling and is NOT interchangeable with either. Substituting it routes the file down a different conformity procedure.
Where a red-team result fits
Protection against corruption
Safety components must be protected against accidental or intentional corruption; a hijackable policy driving a safety function is a corruption pathway.
Autonomous behaviour
Machinery with self-evolving behaviour must remain safe - which requires testing what the policy does under adversarial conditions.
Annex I, Part A, point 5
"Safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions" (CELEX 32023R1230). Point 6 is the embedded-system variant, for machinery placed on the market with the ML safety system inside it. Both are subject to the third-party conformity assessment of Article 25(2) via Article 6(1).
Evidence produced
- Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation.
- A measured keep-out-zone violation rate under an adversarial instruction, with its confidence interval. A paired harmless-variation arm separates it from mere rewording — a semantics-preserving reword fired on 1 of 50 episodes against the attack’s 44 of 50 — but the predicate is uncalibrated, so this is an envelope-exit rate, not a certified hazard rate.
- A reproducible trace supporting the technical documentation for a machinery conformity assessment.
- The provael certify command builds a conformity-assessment evidence dossier (OSCAL assessment-results + print-to-PDF HTML) in two profiles: Annex I Part A (third-party route, Article 6(1) → Article 25(2), for self-evolving-behaviour safety components) and Annex III. The dossier cites Annex I Part A by point number - point 5 for the standalone safety component and point 6 for the embedded system - rather than deferring the clause.
- Standing-assurance / per-checkpoint regression maps to Annex III §1.1.9 (safe behaviour across updates).
provael certify - the conformity-assessment evidence dossier a notified body reviews for an ML-based safety component
- Two profiles: Annex I Part A - the third-party route via Article 6(1) → Article 25(2), for safety components with self-evolving behaviour - and Annex III.
- Emits OSCAL assessment-results plus a self-contained, print-to-PDF HTML dossier you can hand to an assessor.
- Standing-assurance and per-checkpoint regression map to Annex III §1.1.9 (safe behaviour across updates).
Evidence input to a conformity assessment - it is NOT a conformity assessment, it is NOT a certificate, and Provael is NOT a notified body.
Dates (verified 26 Jul 2026)
- Applies
- 20 January 2027Article 54, as corrected by the Corrigendum of 4 July 2023. Some secondary sources cite an incorrect January date; the correct application date is 20 January 2027.
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
What it is - and isn’t
- adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
- evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.