Skip to content
Confir.
Industries

EU AI Act for Agriculture & Agritech: What's Actually High-Risk (2026)

Industry Guide4 August 2026· 15 min read

Most agritech AI — yield prediction, disease detection, livestock monitoring — is minimal-risk. The line that bites: AI as a farm-machinery safety component.

Probably not. Run your yield model, your crop-disease vision, your livestock-health tracker through the EU AI Act under Regulation (EU) 2024/1689 and almost all of it lands at minimal-risk — no compliance stack, no conformity assessment, nothing mandatory beyond a transparency label. The one line that bites is narrow and specific: AI that performs a safety function inside a farm machine. This guide routes each system in an agritech estate, because the route follows the product, not the company — and one equipment maker can run a dozen systems on different clocks.


The honest headline: most agritech AI is not high-risk

Start by deflating the fear. Precision-farming engines, yield and harvest prediction, crop and disease detection from drone or satellite imagery, livestock health and behaviour monitoring, irrigation and fertiliser optimisation, and supply-and-demand forecasting are almost all minimal-risk under the Regulation. They sit outside the Article 5 prohibitions, outside the Annex III high-risk list, and outside the Annex I product-safety route.

Minimal-risk carries no mandatory compliance stack. The only baseline duties are Article 50 transparency — label an agronomy advisory chatbot as artificial, and machine-readably mark any synthetic imagery your tools generate — and the absolute duty to avoid the Article 5 prohibited practices. There is no risk-management system to build, no technical file to file, no notified body to engage.

Treat this whole guide as a routing exercise, not a verdict on your organisation. The job is to route each system one at a time. A single farm-equipment maker can run yield models (minimal-risk), an autonomous-tractor stack (product route), and a seasonal-labour screening tool (Annex III) simultaneously — three classifications, three clocks, one company. The rest of this guide unpacks the single line that does bite: AI as a safety component of agricultural machinery and autonomous tractors.


Where the line bites: AI as a safety component takes the Annex I product route

Article 6(1) makes an AI system high-risk when it is a safety component of a product covered by the Union harmonisation legislation listed in Annex I, and that product is required to undergo third-party conformity assessment under that legislation. This is the product route — distinct from the stand-alone Annex III use-case route.

The safety-component test is functional: would failure or malfunction of the AI directly create a risk to the health and safety of persons? An autonomous tractor's obstacle-detection-and-stop logic, an automated steering or headland-turn system that could run over a bystander, a power-take-off or implement guard governed by AI — yes, all safety components. A yield map, an irrigation-scheduling model, a soil-nutrient predictor — no. They optimise an outcome; they do not protect a person.

One critical clarification distinguishes agriculture from the simpler sibling sectors. The Annex I product route does not mean the full high-risk stack (Articles 8 to 15, 16, and 43) applies directly to these products as free-standing duties. Article 2(2) governs how the Act actually binds product-embedded AI — and agriculture is unusual because it splits across both halves of Annex I. The next section is the core of this guide.

For the detailed test, see what counts as a safety component; for the default classification of most agritech, see the minimal-risk tier and its (lack of) obligations.


The agriculture twist: one machine, two Annex I sections

This is the part no other industry guide on this site touches. Farm machinery does not route through one product law — it splits across both sections of Annex I.

Agricultural vehicles route via Annex I Section B — Regulation (EU) 167/2013

Agricultural and forestry vehicles are type-approved under Regulation (EU) 167/2013, which sits in Annex I Section B. AI safety components in the vehicle body therefore take the Section B route. Under Article 2(2), only Article 6(1), Articles 102 to 109, and Article 112 apply directly; the substantive AI requirements are carried into the type-approval framework rather than imposed as standalone duties. Never apply Articles 8 to 15, 16, or 43 to the vehicle as free-standing obligations — that is the most common routing error.

Mounted and attached machinery routes via Annex I Section A — Regulation (EU) 2023/1230

Mounted, towed, or attached machinery and the broader machinery context fall under the Machinery Regulation (EU) 2023/1230, which sits in Annex I Section A. For Section A, Article 43(3) routes the AI conformity assessment through the sectoral act rather than through the full standalone Article 43 procedure.

One tractor can straddle both

So a single autonomous tractor pulling an AI-guided implement can land on both routes at once: the self-driving vehicle body on the Section B path (Regulation (EU) 167/2013) and the implement's safety AI on the Section A path (Regulation (EU) 2023/1230). Two mechanisms, two different sets of provisions binding directly. The General Safety and agricultural-vehicle framework sits underneath type-approval, but it is the type-approval requirement itself that triggers Article 6(1).

The trap to avoid: treating all farm-machine AI as one classification, or applying the full high-risk stack uniformly across the machine. The route follows the product instrument, not the farm. This is exactly why the Section B vehicle type-approval route and the machinery and robotics AI compliance (Section A) guides each cover only one half — agriculture is the sector that lives in both.


The Annex III pieces that still catch agritech businesses

Even though core field AI is either the product route or minimal-risk, stand-alone Annex III can still catch back-office and workforce systems — on a different clock, and with the full direct stack.

Annex III point 4 covers employment. AI used to recruit or select seasonal and permanent farm, processing, or cooperative staff falls under point 4(a); AI for in-employment decisions — task allocation, performance evaluation, termination — falls under point 4(b). Either triggers the full high-risk stack directly, regardless of how the rest of the estate is classified.

Article 5(1)(f) goes further still. AI that infers the emotions of a person in the workplace is prohibited outright — not merely high-risk. A system inferring fatigue or emotional state of farm or packhouse workers, framed as wellbeing or safety monitoring, is banned, and that prohibition has been in force since 2 February 2025.

Annex III point 2 (critical infrastructure) can be relevant only where an agribusiness operates AI as a safety component in water supply or energy management. But the regulated party is usually the infrastructure operator: a farm that consumes irrigation water is not the provider of the water-management system.

Roles follow the build-versus-buy split. Where an agritech firm uses a vendor tool for an Annex III purpose, it is the deployer under Article 26 and the vendor is the provider. An in-house build makes the firm the provider under Article 16. And under Article 25, a deployer that puts its own name or trademark on a system, substantially modifies it, or changes its intended purpose to a high-risk one becomes the provider for the modified system.


The data-governance layer agriculture can't ignore: agronomic and environmental data

This layer is genuinely agriculture-specific and absent from the sibling guides. For any agritech AI that does land in high-risk, Article 10 data governance requires training, validation, and test data to be relevant and sufficiently representative. For crop, soil, and disease models that means coverage across the regions, soil types, crop varieties, climates, and seasons of the EU markets you serve — not one geography overfitted and shipped everywhere.

Distribution shift is acute in agriculture. A disease-detection model validated in one climate or growing season can degrade badly when deployed in another. For a high-risk safety AI, that is an Article 9 risk-management concern and an Article 15 accuracy-and-robustness concern, not a footnote — failure modes have to be anticipated, measured, and documented across conditions.

Keep the frameworks separate. GDPR governs personal data and EU agricultural data-sharing initiatives govern data rights, but these are distinct regimes. The AI Act adds data-governance duties only where a system is high-risk; for minimal-risk agritech it adds no data-governance mandate at all. Be honest about scope: most agronomic-data models are minimal-risk, so the Article 10 obligations attach only to the narrow high-risk safety-component or Annex III subset.


Routing table: common agritech systems and where they land

Each row cites the exact Article or Annex, so the routing is auditable rather than asserted.

Agritech systemRouteGoverning instrumentProvisions that applyClock
Autonomous-tractor obstacle detection / stopHigh-risk, productArticle 6(1) + Annex I Section B (Reg 167/2013)Art 6(1), 102-109, 112 directly, via type-approval2 Aug 2027 (statute)
AI safety control on mounted / attached machineryHigh-risk, productArticle 6(1) + Annex I Section A (Reg 2023/1230)Article 43(3) routes through the Machinery Regulation2 Aug 2027 (statute)
Yield / harvest predictionMinimal-riskRegulation (EU) 2024/1689Article 50 + Article 5 baseline onlyn/a
Crop / disease detection from imageryMinimal-riskRegulation (EU) 2024/1689Article 50 + Article 5 baseline onlyn/a
Livestock health / behaviour monitoringMinimal-riskRegulation (EU) 2024/1689Article 50 + Article 5 baseline onlyn/a
Irrigation / fertiliser optimisationMinimal-riskRegulation (EU) 2024/1689Article 50 + Article 5 baseline onlyn/a
Recruitment / seasonal-labour screeningHigh-risk, stand-aloneAnnex III point 4(a)Full high-risk stack directly2 Aug 2026 (statute)
In-employment task allocationHigh-risk, stand-aloneAnnex III point 4(b)Full high-risk stack directly2 Aug 2026 (statute)
Worker emotion / fatigue inferenceProhibitedArticle 5(1)(f)Banned outrightIn force 2 Feb 2025

Worked example: routing a named agritech firm's AI portfolio

Take TerraSenda Agritech, a fictional ~650-person Netherlands-based precision-farming and autonomous-machinery vendor running five systems on four routes.

System 1 — autonomous-tractor self-driving and obstacle-stop stack. This is a safety component of an agricultural vehicle type-approved under Regulation (EU) 167/2013, in Annex I Section B. Under Article 2(2), only Article 6(1), Articles 102 to 109, and Article 112 bind directly; the substance is delivered through the amended type-approval framework. There is no standalone Article 16 or Article 43 route for the vehicle body, and TerraSenda's engineers should resist building one.

System 2 — AI-controlled spray-boom and implement guard on a mounted machine. This routes via Annex I Section A under the Machinery Regulation (EU) 2023/1230, where Article 43(3) carries the conformity assessment through the sectoral act. Different half of Annex I, different mechanism — on the same tractor as System 1.

System 3 — crop-disease detection from drone and satellite imagery. Minimal-risk. Article 50 transparency (mark synthetic imagery) plus the Article 5 baseline, and nothing more. No technical file, no conformity assessment.

System 4 — seasonal-labour recruitment screening. Annex III point 4(a): the full high-risk stack applies directly, on the Annex III clock. A flag for TerraSenda's product team — an emotion- or fatigue-inference variant of this tool would not be high-risk but prohibited under Article 5(1)(f), and already unlawful.

System 5 — irrigation-scheduling optimiser. Minimal-risk; Article 50 plus Article 5 baseline only.

The relief caveat: at ~650 staff, TerraSenda exceeds the SME threshold, so it cannot rely on the Article 99(6) lower penalty cap reserved for genuine SMEs and start-ups. Its exposure is the full fine ceiling on every breach.


Deadlines, penalties, and what to do before each clock

Several clocks are already running. Article 5 prohibitions have applied since 2 February 2025 (with a new CSAM and nudifier prohibition, plus Article 50 content-marking duties, landing 2 December 2026). Article 4 AI literacy has applied since 2 February 2025. GPAI obligations under Articles 51 to 55 have applied since 2 August 2025.

The high-risk clocks, now settled. Stand-alone Annex III high-risk (Article 6(2), the workforce systems) — the statute reads 2 August 2026, deferred to 2 December 2027. Annex I product-embedded high-risk (Article 6(1), the machinery and vehicle safety AI) — the statute reads 2 August 2027, deferred to 2 August 2028. The caveat: the Digital Omnibus was adopted — the European Parliament passed it on 16 June 2026, the Council on 29 June 2026 — and only publication in the Official Journal, expected before 2 August 2026, remains outstanding, as a formality. Teams should plan against the adopted deferral dates. The standards-contingent "stop the clock" variant was rejected.

Penalties, stated exactly. Article 99(3) — prohibited practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Article 99(4) — high-risk and most obligation breaches: up to €15 million or 3%. Article 99(5) — incorrect, incomplete, or misleading information to authorities: up to €7.5 million or 1%. Article 99(6) — genuine SMEs and start-ups are capped at the lower of the fixed sum and the percentage.

Do not forget the parallel exposure. For Section B vehicles, market-surveillance action under Regulation (EU) 167/2013 type-approval can run alongside AI Act fines; for Section A machinery, action under the Machinery Regulation can do the same. In practice, recall risk is often the more immediate commercial threat than the headline fine.


How Confir helps

Confir routes an agritech estate the way this guide does — system by system, with the article each conclusion rests on written next to it. The classification engine is deterministic and rule-based — no model inference, no hallucination. Each system runs through the same questions: is it a safety component of a type-approved agricultural vehicle (Section B) or of machinery (Section A)? Is it Annex III via employment? Is it minimal-risk with only Article 50 duties? Same inputs, same output, every time.

Where a system is high-risk, Confir structures the Annex IV technical file and produces the Article 47 EU Declaration of Conformity, and tracks role (provider or deployer), classification, and deadline across a mixed portfolio in one register. The GPAI provider workflow under Articles 51 to 55 remains partial and on the roadmap, not marketed as complete.


Frequently asked questions

Is yield prediction or crop-disease detection AI high-risk under the EU AI Act? Generally no. Yield and harvest prediction, crop and disease detection from imagery, soil and irrigation optimisation, and livestock health monitoring are operational tools. They do not appear in the Annex III high-risk list and are not safety components of regulated products, so they are minimal-risk under Regulation (EU) 2024/1689 with no mandatory compliance stack. The only baseline duties are Article 50 transparency — labelling an advisory chatbot, marking synthetic imagery — and avoiding the Article 5 prohibited practices.

Is the AI in an autonomous tractor high-risk? Yes, where it is a safety component. Self-steering, obstacle-detection-and-stop, and similar functions whose malfunction could injure a person make the AI high-risk under Article 6(1), because agricultural and forestry vehicles are type-approved under Regulation (EU) 167/2013, listed in Annex I Section B. Under Article 2(2), only Article 6(1), Articles 102 to 109, and Article 112 apply directly; the substantive AI requirements are carried into the type-approval framework rather than assessed through a standalone Article 43 procedure.

Why does farm machinery split across two Annex I sections? Because two different product laws apply. The agricultural or forestry vehicle itself is type-approved under Regulation (EU) 167/2013, which sits in Annex I Section B, so the vehicle's safety AI takes the Section B route. Mounted, towed, or attached machinery falls under the Machinery Regulation (EU) 2023/1230, listed in Annex I Section A, where Article 43(3) routes conformity through that sectoral act. A single autonomous tractor pulling an AI-guided implement can therefore straddle both routes, with different provisions binding directly.

Which agritech AI still falls under Annex III? Mostly back-office and workforce systems. AI used to recruit or select seasonal and permanent staff falls under Annex III point 4(a), and AI for in-employment decisions such as task allocation, performance, or termination falls under point 4(b) — either triggers the full high-risk stack directly, regardless of the rest of the estate. Separately, AI that infers the emotions of workers is prohibited outright under Article 5(1)(f), not merely high-risk. Critical-infrastructure safety AI (Annex III point 2) usually binds the infrastructure operator, not the farm.

Does Article 10 data governance change how we handle agronomic data? Only for high-risk systems. For the narrow subset of agritech AI that is high-risk, Article 10 requires training, validation, and test data to be relevant and sufficiently representative — which for crop, soil, and disease models means coverage across the regions, varieties, climates, and seasons served, to manage distribution shift under Articles 9 and 15. The AI Act is separate from GDPR and EU agricultural-data initiatives, and for minimal-risk agritech it adds no data-governance mandate at all.

When do the EU AI Act deadlines hit agriculture, and what are the penalties? Article 5 prohibitions and Article 4 literacy have applied since 2 February 2025; GPAI duties since 2 August 2025. Stand-alone Annex III high-risk (workforce AI) statute reads 2 August 2026, deferred to 2 December 2027 under the now-adopted Digital Omnibus; Annex I product-embedded high-risk (machinery and vehicle safety AI) reads 2 August 2027, deferred to 2 August 2028. Plan against the adopted deferral dates. Penalties reach €35 million or 7% of turnover for prohibited practices (Article 99(3)), €15 million or 3% for high-risk breaches (Article 99(4)), and €7.5 million or 1% for misleading information (Article 99(5)).

Is the equipment maker or the farm the provider under the EU AI Act? It depends on who places the AI on the market under their own name. A manufacturer that builds and brands an autonomous-tractor or machinery AI system is the provider and carries the Article 16 obligations; the farm operating it is the deployer under Article 26. Under Article 25, a deployer or integrator that substantially modifies the system or changes its intended purpose can itself become the provider for the modified system, so the boundary should be settled contractually before integration rather than discovered at a recall.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →

Keep reading