The implementation of European regulations such as the CRA, NIS2 and the AI Act, alongside the use of AI with its opportunities and cybersecurity risks, is anything but straightforward for industrial companies. But which technical and organisational measures can help maintain cybersecurity? Alexander Ingelheim, CEO and co-founder of Proliance, provides further insights.
What impact do EU regulations such as the AI Act, the Cyber Resilience Act (CRA) and NIS2 have on industrial companies? What requirements arise from these for the use of digital technologies in general?
Alexander Ingelheim: Industrial companies are facing a regulatory landscape of unprecedented density. NIS2 affects the manufacturing sector as an "important entity" from 50 employees onwards, while the CRA complements this with product-related obligations for connected machines and IoT. The AI Act, in turn, applies wherever AI is used in safety-critical contexts. The real challenge lies in the overlap: a connected industrial product with AI functionality may simultaneously be subject to CRA, AI Act and NIS2 requirements. For the use of digital technologies, this means that security and auditability must be built in from the outset—from the cloud platform right through to the edge device.
IT Regulation: An Overview of Legislation and Obligations
What organisational and strategic measures must small and medium-sized industrial enterprises in particular adopt to implement and comply with regulatory requirements?
Alexander Ingelheim: The first step is a clear-eyed assessment of applicability. For NIS2, this requires nothing more than consulting the annexes of the transposition legislation in conjunction with the size criteria; for the AI Act, it involves an inventory of all AI systems, including their risk classification; and for the CRA, the key question is whether products contain digital elements. Strategically, an integrated approach has proven effective—one that does not treat data protection, information security and compliance as separate silos. Those who implement NIS2 with ISO 27001 as a reference framework create a foundation that largely also covers CRA requirements relating to vulnerability management and incident response. At executive level, the personal accountability of senior management must be addressed. NIS2 explicitly imposes training obligations and personal liability in this regard, which cannot be delegated.
Implementing CRA requirements using SBOMs
How can companies assess and manage dependencies on cloud, software and cybersecurity providers?
Alexander Ingelheim: A prerequisite for any robust assessment is a complete asset register. Without clarity on which software, which cloud services and which service providers are embedded in which processes, dependencies cannot be managed. These dependencies can be evaluated along several dimensions, such as their criticality to business operations, data categories, jurisdiction and auditability. Management measures include standardised supplier questionnaires, reliable assurances such as SOC 2 (Service Organization Control 2) reports and ISO 27001 certifications, contractual clauses on data locations, and exit plans for particularly critical dependencies. In any case, NIS2 makes supply chain management a formal obligation under Article 21 and should serve as a prompt to structurally incorporate a vendor risk component into procurement processes.
How can industrial companies deploy AI in production, quality control or process optimisation without incurring compliance and governance risks?
Alexander Ingelheim: In production contexts, the regulatory requirements for AI are often more demanding than anticipated. Companies using an AI system to control safety-relevant machine functions or to inspect safety-critical components could, until recently, quickly find themselves classified under the AI Act’s high-risk category. A practical approach begins with an inventory of AI systems and their risk classification in line with the categories defined by the regulation. Only then can it be determined which obligations actually apply. Most AI applications in production fall into the limited or minimal risk category, which significantly reduces the scope of requirements. One practice companies should avoid is mixing pilot operations with live deployment without documented approval, as this is difficult to justify during an audit.
For the mechanical engineering sector in particular, the Digital Omnibus on AI introduces an important course correction despite its complexity. The Machinery Regulation (EU) 2023/1230 is explicitly excluded from the immediate scope of the AI Regulation, thereby eliminating the previously feared dual regulation for AI embedded in machinery. In practical terms, this means that companies integrating artificial intelligence into their machines—for example, for control functions or predictive maintenance—no longer have to comply with two regulatory frameworks simultaneously. Instead of the full high-risk regime, only the limited provisions pursuant to Article 2(2) of the AI Regulation apply; the comprehensive set of obligations under the AI Act is no longer the default for such systems.
However, this does not amount to a carte blanche. Individual AI requirements may still apply where the relevant sector-specific regulations do not ensure an equivalent level of protection for health, safety or fundamental rights. In addition, overarching requirements—such as those relating to transparency, documentation and the development of AI competence—continue to apply to mechanical engineering firms.
What organisational structures, risk assessments and documentation processes are required to ensure that AI systems are used in a compliant and auditable manner?
Alexander Ingelheim: At its core, this requires AI governance that is firmly embedded within the organisation and does not merely exist as a policy document on paper. A central function—often an extension of the Data Protection Officer’s remit or a dedicated AI Officer—coordinates the inventory, risk classification and approval processes. Risk assessments are guided by the AI Act’s classification scheme but must be refined in the context of the specific use case. Wherever personal data is processed, the data protection impact assessment (DPIA) forms a second layer of evaluation. Another key aspect is the obligation, set out in Article 4 of the AI Act, to ensure AI competence among all employees working with AI. In practice, this AI literacy requirement is still widely underestimated.
What are the implications of the increasing convergence of OT and IT, as well as the growing interconnectivity of supply chains, for cybersecurity?
Alexander Ingelheim: The convergence of OT and IT is creating attack surfaces that many industrial companies have historically not considered. Production facilities that operated for decades in isolated plant networks are now connected to the internet via cloud services and remote maintenance. Added to this is the supply chain dimension. A compromised software supplier can cascade malicious code into thousands of end-customer environments, as recent incidents have shown. Security therefore no longer stops at a company’s own firewall. Required measures include a comprehensive inventory of all OT and IT assets, segmented networks, robust identity and access management—particularly for external maintenance access—and supplier risk management that is underpinned both contractually and through auditability.
OT Security: Secure critical infrastructure – before attacks turn physical
What opportunities and risks do AI and machine learning present for the cybersecurity of industrial companies?
Alexander Ingelheim: The opportunities are significant. AI-driven anomaly detection can reveal irregularities in OT networks that signature-based methods overlook. In endpoint and network monitoring, machine learning facilitates the triage of incidents and relieves overburdened security teams. At the same time, there are tangible risks. Attackers are already routinely using generative AI for phishing campaigns whose linguistic quality undermines traditional indicators. Voice cloning turns social engineering at executive level into a major threat, and prompt injection in agent-based systems creates attack vectors that many companies have yet to incorporate into their risk models. We recommend a pragmatic middle ground: deploy AI where the added value is measurable and where data quality is assured.
Go to the AI & IT Security page
The questions were posed by Andreas Knoll.
