← Journal
MOD-01 · Field notes

The regulation was the soft part

Research

The date the internet had circled for factory humanoids — 2 August 2026, when the EU AI Act's high-risk obligations were said to bite — moved. On 27 July the Digital Omnibus entered into force and pushed those obligations to December 2027, and machinery-embedded AI to August 2028. Meanwhile Apollo is already moving parts on a Mercedes-Benz line in Berlin, the safety standard written for robots that fall over when power is cut is still a working draft, and the instrument that actually decides whether a humanoid can work in an EU plant does not arrive until January 2027. A field note on why the law is the softest layer in the stack, what governs a deployed humanoid today, and why the moat is the certification evidence, not the deadline.

2026-08-01 · Field notes · 6 min read · By

Ten days ago the trade press was full of one date. On 2 August 2026, the story went, the EU AI Act's obligations for high-risk systems would apply, and humanoid robots on factory floors would be squarely inside them. Then, five days before the deadline, the EU moved it. This is a note about what that tells you — not about the law itself so much as about where it sits relative to the machines it is meant to govern.

The event

The date the internet circled moved

Deferred, not deleted

The Digital Omnibus on AI — the first set of amendments to the AI Act since it was adopted in 2024 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It defers the obligations for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, a sixteen-month slip. For AI embedded in products already regulated under Annex I — machinery, medical devices, vehicles — the date moves from 2 August 2027 to 2 August 2028. The Commission's stated aim was to simplify and to relieve implementation pressure the sector said it could not meet in time.

Two things did not move. The prohibitions on unacceptable-risk practices remain in force, as they have been since February 2025. And 2 August 2026 is still a live date: the transparency duties for AI-generated and manipulated content under Article 50, the penalty powers for general-purpose models, and the market-surveillance machinery all switch on as planned. What did not switch on is the part everyone attached to humanoids — the conformity, risk-management, logging, and human-oversight obligations that a robot arm classed as high-risk would have to satisfy. That is now a 2027 and 2028 problem.

The stack

Three clocks, running at different speeds

It helps to see the three layers as three clocks. The fastest is deployment. Apptronik's Apollo is already inside Mercedes-Benz's Digital Factory Campus in Berlin-Marienfelde and its plant in Kecskemét, moving components to the line and running early quality checks, with Mercedes taking an equity stake and pushing the units toward autonomous operation. Figure has forty units of its Figure 03 working at BMW in Spartanburg, and BMW has said it will bring humanoids into production in Germany. None of these waited for a rulebook.

The second clock: standards

The industrial-robot safety standards were rewritten last year. ISO 10218-1 and 10218-2, both published in 2025 after roughly eight years of work, folded the old collaborative-robot specification ISO/TS 15066 into the main series and added explicit cybersecurity and functional-safety requirements. But they were written for fixed-base, statically stable robots — machines that do not topple when power is removed. A walking humanoid violates that assumption at rest. The standard written for exactly this case, ISO 25785-1 for dynamically stable industrial mobile robots, is still a working draft with no confirmed publication date. This is the same gap this journal flagged in You cannot certify a fall — and it has not closed.

The third clock: regulation — and it is the one that just slipped

The AI Act was the slowest and, it turns out, the softest. A standard, once balloted and published, is a fixed target; a deployment, once running, is a fact on the floor. But a compliance date is a political variable, and this one moved under industry pressure with five days to spare. That ordering is the point. The machines are ahead of the standards, the standards are ahead of the horizontal AI law, and the law is the layer most willing to bend. Anyone who planned around 2 August 2026 as a hard wall built on the softest part of the stack.

The real floor

What actually governs a humanoid on a line today

Strip away the headline date and a humanoid working in a European plant this week is governed by something older and less negotiable: product-safety law. The instrument that matters is Regulation (EU) 2023/1230 on machinery, which replaces the 2006 Machinery Directive. It entered into force in July 2023 and becomes mandatory for machines placed on the market from 20 January 2027. As a regulation rather than a directive it is directly applicable in every member state, no national transposition required, and it was drafted precisely to reach the new cases — autonomous mobile machinery, connected equipment, and AI that performs safety functions or evolves its own behaviour, plus a duty to protect safety functions against corruption.

Between now and then, a deployed humanoid is certified the only way it can be: ISO 10218:2025 applied as far as it reaches, supplemented by a documented, robot-specific risk assessment covering the hazards the standard assumes away — the fall, the active balancing, the shared workspace. That is not a loophole. It is what conformity looks like before the dedicated standard exists: a defensible file, built case by case, that says which robot did which task under which safeguards, and shows the evidence. When the AI Act's high-risk obligations do arrive, they route the machinery cases through this same product-safety scaffolding rather than around it. The scaffolding is the durable thing. The date on top of it is not.

The lesson

The moat is the evidence, not the deadline

This is the thesis stated by a real-world example. Moduloa's wager is that the durable value in physical AI is not the robot but the framework around it — the standards, the data, the certification, the routing that lets a task be placed on a certified cell and proven after the fact. A deferred deadline is a gift to exactly that layer. If the wall had held on 2 August, the scarce thing would have been a paperwork sprint to a fixed line. Because it moved, the scarce thing is what it always was underneath: the ability to produce, on demand, the evidence that a given machine did a given job safely — a file that holds whether the official floor sets in December 2027, January 2027, August 2028, or slips again.

Deadlines reward whoever can be ready by a date. Evidence rewards whoever can answer a question — what did this robot do, under what safeguards, with what proof — on any date. The first is a sprint; the second is an asset. The register on the predictions page holds our dated, falsifiable bets on how this unfolds; this note scores none of them, it only observes that the regulatory calendar is behaving as a system with three clocks would predict. The factory OS is where that certification evidence is meant to live, and the thesis is why we think it is the moat.

The honest limits

What this note does not settle

Three limits are worth stating. First, the Omnibus is a deferral of dates and a simplification of some obligations, not a repeal — the high-risk regime still arrives, and reading a sixteen-month slip as a reprieve rather than a delay is a mistake. Second, this note makes no claim that any specific deployed robot is or is not compliant today; classification depends on the exact system, its safety role, and how the integrator documents it, and we have not audited any single installation. Third, the deployments cited are early — pilots and first production tasks measured in dozens of units and thousands of hours, not fleets — so they establish that the machines run ahead of the rulebook, not that the economics are settled. The claim here is narrow and, we think, well supported: in the stack of deployment, standards, and law, the law proved this month to be the layer most willing to move, and the value accrues to whoever builds on the layer that does not.

Sources

Where these facts came from

Discussion

Add to this

Corrections, evidence, and disagreement are welcome — this is knowledge in the open. Anyone can read; sign in with GitHub only to post or react, and it appears here instantly.

Field notes are research, not decisions — dated, sourced, and open to correction. Republish this in full or in part under CC BY 4.0, with credit and a link back. · All journal entries →