The AI Act and robots: what autonomous systems mean for after-sales liability
The AI Act and robots: what autonomous systems mean for after-sales liability
When a robot with an AI-based safety component fails, who is liable? The EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689) does not answer that question directly, but it reshapes the obligations of every actor in the value chain—including after-sales providers. For a service network being set up to support Chinese robotics manufacturers in Europe, the practical consequence is that liability is no longer a simple contract matter. It is now a regulatory matter with concrete technical and documentation requirements.
How the AI Act classifies robots
The AI Act applies to ‘AI systems’ as defined in Article 3(1): software that can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations, or decisions influencing the environments they interact with. Robots that use machine learning for perception, navigation, or decision-making fall squarely within this definition. Even a robot that uses only rules-based logic may be caught if it adapts its behaviour from data.
The Act does not treat all robots equally. It creates a four-tier risk pyramid: unacceptable risk (prohibited), high risk (strict obligations), limited risk (transparency duties), and minimal risk (no additional obligations). Most industrial and service robots with AI will fall into the high-risk category, because they are safety components of machinery under the Machinery Directive (2006/42/EC) or because they perform tasks in critical infrastructure, education, or employment contexts.
High-risk obligations in practice
For a high-risk AI system, the provider (often the manufacturer) must establish a risk management system, use training data that is relevant and representative, create technical documentation, and enable automatic logging of events. The system must be designed for human oversight, and it must achieve an appropriate level of accuracy, robustness, and cybersecurity. After-sales providers are not directly named as duty holders, but they inherit obligations indirectly: if a robot is modified or maintained improperly, the provider’s conformity assessment may be invalidated, and the after-sales actor could be considered a ‘provider’ in their own right under Article 28 if they substantially modify the system.
After-sales liability: where the AI Act meets product liability
The AI Act does not replace product liability law. Instead, it complements it. The EU’s Product Liability Directive (85/374/EEC) holds producers liable for damage caused by defective products. A robot with an AI system could be defective if it fails to provide the safety that a person is entitled to expect, considering its presentation and reasonably foreseeable use. The AI Act’s requirements become a benchmark for what is ‘reasonably expected’. If a robot does not meet the Act’s standards, that can be used as evidence of defectiveness.
For after-sales providers, the key shift is that liability can attach to those who place the product on the market or put it into service. A service network that installs, updates, or repairs an AI robot may be considered a ‘putting into service’ actor if it makes the robot available for use in the EU. This is particularly relevant for Chinese manufacturers who sell through a local distributor or service partner. The service network becomes the face of the manufacturer in the EU, and its actions can create liability for both itself and the manufacturer.
Practical implications for maintenance and updates
Under the AI Act, the provider must monitor the system’s performance after it is placed on the market and report serious incidents to the national authority. This monitoring duty is often delegated to the after-sales network. If a robot’s AI software is updated remotely, the network must ensure that the update does not change the system’s risk classification or introduce new hazards. If the update is substantial, the network may be required to re-run the conformity assessment.
Maintenance logs become legal documents. The Act requires automatic logging of events for high-risk systems, and these logs must be kept for a period appropriate to the system’s intended use. After-sales providers must be able to produce these logs to authorities on request. This means that a service network must have the technical capability to access and interpret the logs, and to document any changes made during maintenance.
Comparison table: AI risk categories and obligations
| Risk category | Examples in robotics | Key obligations | After-sales relevance |
|---|---|---|---|
| Unacceptable risk | Social scoring robots, subliminal manipulation | Prohibited | None; cannot be placed on market |
| High risk | Industrial robots with safety functions, medical robots, autonomous vehicles | Risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, registration in EU database | Must maintain logs, report incidents, manage updates, ensure continued conformity |
| Limited risk | Chatbots, emotion recognition systems | Transparency: users must be informed they are interacting with AI | Ensure user information is provided and maintained |
| Minimal risk | AI in inventory management, simple pattern recognition | None (voluntary codes of conduct) | No specific obligations |
What this means for a service network being set up
For a local service network being set up to support Chinese robotics manufacturers, the AI Act creates both challenges and opportunities. On the challenge side, the network must invest in technical expertise to handle AI systems, including the ability to access and interpret logs, perform software updates safely, and document all changes. It must also establish clear contractual agreements with manufacturers about who is responsible for each obligation under the Act. On the opportunity side, a network that can demonstrate compliance with the AI Act becomes a valuable partner for manufacturers who lack EU presence.
Contractual allocation of responsibilities
It is essential to define in the service contract which party is the ‘provider’ under the AI Act. If the manufacturer is the provider, the service network acts as an ‘authorised representative’ or ‘importer’ under certain conditions. The contract should specify who is responsible for post-market monitoring, incident reporting, and conformity assessment. It should also address what happens if the network makes a modification that changes the robot’s risk profile.
Technical requirements for the network
The network must have staff trained in AI system basics, including how to interpret model outputs and identify potential biases. It must have secure access to the robot’s logging system, and it must be able to produce logs in a readable format for authorities. It must also have a process for handling serious incidents, including immediate reporting to the manufacturer and, if required, to the national authority.
Geographic variations and verification
The AI Act is a regulation, so it applies uniformly across the EU. However, enforcement is carried out by national authorities, and each member state may have different procedures for reporting incidents and conducting market surveillance. The Act also allows for ‘notified bodies’ to be designated by member states, and the availability of these bodies may vary. Therefore, it is important to verify the specific national requirements in each country where the network operates.
Conclusion
The AI Act does not create a new liability regime, but it raises the bar for what is considered safe and compliant. For after-sales providers, the message is clear: you are part of the regulatory ecosystem. Your actions can make or break a manufacturer’s compliance. By investing in AI-specific capabilities and contractual clarity, a service network can turn this regulatory complexity into a competitive advantage.
Sources
- EUR-Lex — Regulation (EU) 2024/1689 (AI Act) — https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed 2026-05-13)
- European Commission — AI Act — https://digital-strategy.ec.europa.eu/ (accessed 2026-05-13)
