AI Act audit for manufacturing
In manufacturing, very little is automatically high-risk. That changes once a system takes on a safety function or makes decisions about people.
Predictive maintenance, vision-based quality control and scheduling algorithms usually fall outside the high-risk category. The AI literacy obligation does apply, and has done since 2 February 2025.
Two things move a system into the heaviest tier. The first is a safety function. A system that stops a batch or shuts down a line falls under Annex I, alongside the existing machinery rules. The second is a judgement about people. Task allocation, performance monitoring and access to a workstation bring a system within Annex III.
In most plants that distinction sits inside the same MES or SAP environment. The classification does not follow from the model but from what is done with it.
Shop floor and machine control
We establish which systems have a control or blocking function and which only advise. That distinction determines whether the machinery rules apply to you.
We also look at whether human oversight exists in practice. Does the operator have the time and the information to reverse a decision, or does he press on because the line has to keep running?
Quality and traceability
We examine which inspection systems genuinely contribute to decisions and which only record. We then test what you could reconstruct after an incident. Are logs kept, are they retained, and are they sufficient to show afterwards how a decision was reached?
Your customers and your insurer often ask for this already.
Additional services
We establish where scheduling ends and assessment of staff begins.
Once a system falls into that second category, you have a duty to inform your staff and their representatives.
Systems that infer emotions in the workplace are prohibited outright.
Bought-in systems
Most AI in manufacturing arrives with a machine, an MES or an SAP module. We establish who in that chain is the provider and who is the deployer, because that determines which obligations fall to you.
Anyone who puts a system on the market under their own name, or changes its intended purpose, becomes a provider themselves, whatever the contract may suggest.
What you receive
An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.
We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.
After the audit,
Automation
The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us.
If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.
That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.