
An STS3215 at 7.4 V makes about 1.6 N.m. That is not what decides whether CE marking applies. Placing on the market and putting into service are, and here is where the line falls.
What you need to know
- •Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC on 20 January 2027. Machinery placed on the EU market before that date follows the old Directive. Nothing about a desk arm changes on that date by itself.
- •The trigger is not danger, it is a transaction or a workplace. Under EU law the duties attach to placing on the market or putting into service. A private build used at home by the person who built it does neither in any way a market surveillance authority pursues.
- •The moment an employee touches it, a different body of law applies: Directive 2009/104/EC on the use of work equipment, and in Germany the BetrSichV, which requires a documented hazard assessment before first use.
- •Annex I Part A of the Machinery Regulation names safety components with self-evolving machine learning behaviour ensuring safety functions. A policy that moves the arm is a control function, not a safety function, so that clause usually does not catch a VLA-driven arm.
- •ISO 10218-1:2025 and ISO 10218-2:2025 apply to industrial robots. ISO 13482 applies to personal care and service robots and explicitly excludes industrial robots and robot toys. A hobby arm on a desk sits between them, and no harmonised standard fits it cleanly.
- •The physics is mild. An STS3215 at 7.4 V is quoted at 16.5 kg.cm stall torque at 6 V, about 1.6 N.m, which is roughly 8 N at 20 cm from the joint. The gripper and the trapped-finger case are the real hazards, not blunt impact.
- •In LeRobot, the joint-travel clamp max_relative_target defaults to None, meaning no clamp. The only torque limits written at connect time are on the gripper, and they exist to stop the servo burning out, not to protect your hand.
Who is asking decides which rules apply
The most common way people get this question wrong is to start from the arm. They look at a printed thing with six bus servos sitting on a desk, decide it is obviously harmless, and stop. Then they look at the same arm in a company, decide it is obviously a machine, and panic. Both readings are wrong, because EU product law does not classify objects by how dangerous they look. It classifies events: placing a product on the market, and putting it into service.
So the first question is not what the arm is. It is who is holding it, who paid for it, and who else is in the room. An SO-100 you printed and drive yourself at your kitchen table, an identical SO-100 on a bench in a company where a colleague walks past, and an SO-100 you assemble and sell for 400 EUR are three different legal situations with the same bill of materials. Nothing about the servos changed. What changed is that in the second case there is an employer and a worker, and in the third there is a supply.
In Great Britain, machinery runs through the Supply of Machinery (Safety) Regulations 2008, and government guidance confirms CE marking is recognised alongside UKCA. In the United States there is no CE equivalent for machinery, but OSH Act section 5(a)(1) requires an employer to furnish a workplace free from recognised hazards that are likely to cause death or serious physical harm. Different instrument, same practical conclusion: private use is unregulated, the workplace is not.
This is also why the answers you find online are so unhelpful. Somebody asks whether their hobby arm needs CE marking and gets two confident replies: no, because it is a toy, and yes, because it is machinery. Both are answering a question about the object. The useful answer starts from what the person intends to do with it, and for most readers it is short. The table below is what I would tell a colleague before they read a single article number, and for a lot of people the first row is the entire answer.
| Situation | EU machinery law | Workplace law | What you actually have to do |
|---|---|---|---|
| You build it, you use it at home, nobody else touches it | Not placed on the market. No CE marking obligation in practice. | Does not apply. You are not an employer and not a worker. | Nothing formal. Common sense, a reachable power switch, and do not let a child near the gripper. |
| You build it, an employee uses it at work | Built for own use is still putting into service. The employer is treated as the manufacturer. | Directive 2009/104/EC applies. In Germany, BetrSichV section 3 requires a documented hazard assessment before first use. | Risk assessment, protective measures, instructions, training. CE marking and an EU declaration of conformity are the formal end of that process. |
| A university or company lab, staff only, research task | Article 2(2)(m) excludes machinery specially designed and constructed for research purposes for temporary use in laboratories. | Still applies in full. Researchers are workers. | The product-law exclusion does not exempt you from workplace duties. Do the hazard assessment anyway. |
| You sell assembled arms or kits | Placing on the market. Full manufacturer obligations under Regulation (EU) 2023/1230. | Your buyer's problem, but your instructions shape it. | Risk assessment, technical file kept 10 years, instructions, EU declaration of conformity, CE marking. |
What the Machinery Regulation actually says
Regulation (EU) 2023/1230 was adopted on 14 June 2023 and applies on a mandatory basis from 20 January 2027, replacing Directive 2006/42/EC. The European Commission is explicit that machinery placed on the EU market before 20 January 2027 must comply with the old Directive. That is worth internalising, because a lot of writing on this implies the Regulation retroactively changes what is already on a bench. It does not. If you are working through a build right now, the SO-100 hub and the complete SO-100 setup guide are the practical companions to this page; what follows is only the part about who is allowed to do what.
| Provision | Where | What it means for a small arm |
|---|---|---|
| Definition of machinery | Article 3(1) | An assembly with a drive system other than human or animal effort, with linked moving parts, for a specific application. Six powered servos and linked links qualify. The arm is machinery. |
| Placing on the market | Article 3(12) | The first making available on the Union market. Supply in the course of a commercial activity, paid or free. |
| Putting into service | Article 3(13) | The first use, for its intended purpose, in the Union. This is the clause that catches machines built for own use in a business. |
| Substantial modification | Article 3(16) | A physical or digital change after market placement that the manufacturer did not foresee and that creates a new hazard or increases a risk. Whoever makes it takes on manufacturer duties. |
| Manufacturer obligations | Article 10 | Risk assessment, technical documentation kept at least 10 years, instructions in an accessible language. |
| CE marking | Articles 21 and 24 | You draw up an EU declaration of conformity stating which legislation the machine meets, then affix the CE marking. It is the visible end of the process, not the start of it. |
| High-risk categories | Article 6 and Annex I | Six categories where a notified body must be involved. Two of them are about machine learning. |
20 January 2027 is when Regulation (EU) 2023/1230 becomes mandatory for machinery placed on the EU market. It is not a date on which your existing desk arm becomes illegal, and it is not a date by which hobbyists must do anything. Where it does bite: if you sell arms or kits, everything you place on the market from that day is assessed against the Regulation, and the technical file you built against the 2006 Directive needs reworking. Start that in 2026, not in December of that year.
Placing on the market is not the same as putting into service
This distinction is the whole game for anyone building their own arm, and it is where most confident internet answers fall apart. Making available on the market is defined as supply in the course of a commercial activity, which a private build clearly is not. Putting into service carries no such qualifier: it is simply the first use for its intended purpose in the Union. The European Commission's guidance on the Machinery Directive has long been read to mean that a person who builds a machine for their own use has not placed it on the market but has put it into service, and therefore carries the manufacturer's obligations.
Read literally, that would sweep in every hobbyist. In practice it does not, because market surveillance under EU product law is aimed at economic operators, and because the enforcement hook for own-use machinery in every member state I have looked at runs through workplace legislation rather than product legislation. The honest formulation is this: the risk of a compliance problem is essentially zero while the arm stays private, and becomes real the moment it is at a place of work. Do not build a business plan on the first half of that sentence.
- Private, own use, own home: no realistic obligation. Nobody is coming.
- Own build, own company, your own employees use it: you are the manufacturer for the purposes of putting into service, and you are also the employer under Directive 2009/104/EC. The second duty is the one with inspectors attached.
- Bought as a kit, assembled per instructions: assembling per instructions is not a substantial modification. You are a user.
- Bought as a kit, then you bolted on a bigger gripper and a 12 V supply: that is exactly the shape of a substantial modification under Article 3(16), and it moves manufacturer duties to you.
- Sold to someone else, even at cost, even to a friend: supply in the course of a commercial activity is read broadly, and free of charge is explicitly included.
Article 2(2)(m) excludes machinery or related products specially designed and constructed for research purposes for temporary use in laboratories. Three conditions, all of them load-bearing: specially designed for research, temporary, and in a laboratory. An arm you keep on a desk for two years while you collect LeRobot datasets is not temporary, and a desk is not a laboratory. Even where the exclusion does apply, it only removes the product-law duties. Your workplace duties are untouched.
The machine-learning clause that everyone misreads
The headline change in the Machinery Regulation for anyone running a policy on hardware is in Annex I Part A. Two of the six high-risk categories that require a notified body concern machine learning: safety components with fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions, and machinery that embeds such components. This gets quoted constantly as proof that AI-driven machines now need third-party assessment. That reading skips the most important five words in the sentence.
- Ensuring safety functions. The clause is about software that performs a safety function: stopping the machine, blocking access, limiting speed. A vision-language-action model that decides where to move the gripper is a control function. It is what the machine is for, not what keeps it safe.
- Self-evolving. A checkpoint you trained once and froze does not evolve in the field. It produces different outputs on different inputs, which is not the same thing. Continual on-robot learning is a different conversation.
- Both conditions of the AI Act must be met. Article 6(1) of Regulation (EU) 2024/1689 classifies an AI system as high-risk only if it is a safety component of a product covered by Annex I legislation and that product must undergo third-party conformity assessment. Fail either limb and you are out.
- The hobbyist exemptions are broad. AI Act Article 2(8) excludes research, testing and development activity prior to placing on the market or putting into service, though not testing in real world conditions. Article 2(10) excludes natural persons using AI systems in a purely personal non-professional activity. Article 2(6) excludes systems developed solely for scientific research and development.
So the practical answer for someone fine-tuning ACT or SmolVLA on their own recordings is that the AI Act does not reach them, and the machine-learning clauses of the Machinery Regulation do not either. The checkpoint is the productive part of the machine. It decides where the gripper goes, well or badly, and when it decides badly the remedy is a better dataset, not a notified body.
Where it does change is if you build a safety layer out of a model. A vision model that decides whether a person is close enough to stop the arm is a safety component in the literal sense the Regulation means: it is ensuring a safety function, and if it keeps learning in the field it is self-evolving as well. That is the case that pulls you into Annex I Part A and third-party assessment, and it is also the case where the AI Act's two-limb test in Article 6(1) is finally satisfied on both limbs. The engineering advice is blunt: do not build that. Use a light curtain, a two-hand control, an interlocked enclosure or a switch. They are cheap, boring, assessable, and nobody has to argue about a detector's confidence threshold after an incident.

The standards, and why none of them quite fit
Once you accept that some duty applies, the next instinct is to reach for a standard. This is where a small arm gets awkward, because the robotics standards were written for two worlds and a desk arm belongs to neither. The table is the map.
| Standard | Status | Scope | Does it fit a desk arm? |
|---|---|---|---|
| ISO 12100 | Type A, general | Risk assessment and risk reduction methodology for machinery | Yes. This is the one to actually use. It is method, not thresholds. |
| ISO 10218-1:2025 | Published 2025, first revision since 2011 | Design, manufacture, remanufacture and rebuild of industrial robots | No. Industrial robots only, explicitly not service or household applications. |
| ISO 10218-2:2025 | Published 2025 | Industrial robot applications, cells, integration, safeguarding | No, for the same reason. Useful to read for how the profession thinks. |
| ISO/TS 15066:2016 | Content consolidated into the 2025 ISO 10218 revision | Power and force limiting for collaborative applications | Not directly, but its biomechanical framing is the right mental model for contact. |
| ISO 13482:2014 | Under revision as ISO/FDIS 13482, retitled for service robots | Personal care robots, earthbound, below 20 km/h | Closer in spirit, but it excludes industrial robots and robot toys, and a desk arm reads as neither. |
| ISO 13849-1 | Type B, functional safety | Performance levels for safety-related parts of control systems | Only if you build a safety function. Do not, unless you must. |
ISO 10218-1:2025 and ISO 10218-2:2025 were published in 2025 after roughly eight years of work, the first major revision since 2011, and they fold the collaborative-application content of ISO/TS 15066 into the main series alongside new functional safety, robot classification and cybersecurity requirements. If you have a 2016 reference to ISO/TS 15066 in a document, date it and note that the 2025 series is now the reference for industrial collaborative applications. Roberta Nelson Shea convened the ISO/TC 299 working group behind the revision.
The practical consequence of that table is worth stating plainly, because it surprises people who expect a standard to exist for every product. There is no harmonised standard written for a sub-2 N.m desk manipulator, and there probably never will be, because the category is too small and too heterogeneous to justify one. That is not a loophole and it is not a gap you can hide in. Where a duty applies, the absence of a type C standard means you carry the risk assessment yourself under ISO 12100 rather than presuming conformity by following a checklist. In exchange, nobody can tell you your end effector fails clause 5.10.3 of a standard that was written for a 200 kg industrial arm behind a fence.
The physics: what 1.6 newton metres can actually do
Compliance arguments are more useful when you know the numbers. The SO-ARM100 build repository states that the 7.4 V STS3215 used in an SO-100 follower has a stall torque of 16.5 kg.cm at 6 V, and that a 12 V variant of the same part number exists at 30 kg.cm. Converting the 7.4 V figure: 16.5 kg.cm is about 1.6 N.m. At 20 cm from the joint axis that is roughly 8 N, about the weight of a 800 g object. At 30 cm it is closer to 5 N. Stall torque is a brief peak, not something the servo sustains, and the SO-100 follower uses six identical 1/345 gear servos, so no joint is dramatically stronger than another. The SO-101 uses the same 7.4 V servos with mixed gear ratios, and the SO-100 against SO-101 comparison sets the two side by side. A Koch v1.1 is a different electrical animal, with 5 V and 12 V rails, and its numbers do not carry over.
That is genuinely low. It is not enough to break a finger by blunt impact, and it is well below the biomechanical thresholds that collaborative-robot work concerns itself with. Stall torque is also the wrong number for impact: what injures is force concentrated over a small area, and this arm funnels its modest torque into a gripper jaw a few millimetres wide. Pressure, not force, is why the gripper is the hazard on this machine and the links are not.
| Quantity | Value | Where it comes from |
|---|---|---|
| STS3215 7.4 V stall torque | 16.5 kg.cm at 6 V | Stated in the SO-ARM100 build repository |
| Same figure in SI | about 1.6 N.m | Arithmetic: 16.5 kg.cm times 0.0981 |
| Tip force at 20 cm | about 8 N | Torque divided by lever arm. Roughly the weight of 800 g |
| Tip force at 30 cm | about 5 N | Same calculation, longer lever |
| 12 V variant of the same part | 30 kg.cm stall | Also in the repository, and the reason the 12 V mix-up happens |
| Follower joint count | 6 identical 1/345 gear servos | SO-100 follower bill of materials |
Low force is not the same as no hazard, and the hazards that recur on this hardware are not the ones people brace for. The swinging link is not the problem. The recurring incidents are a finger in the gripper because somebody reached in to reseat an object mid-episode, a cable dragged off the bench by an unclamped base, and an arm going limp while holding something over a laptop. All three are workspace problems. All three are solved with clamps and habits, not with law, and none of them appear anywhere in a conformity assessment.
| Hazard | Why it is real on a 7.4 V arm | Cheapest effective control |
|---|---|---|
| Gripper pinch | Small jaws, high local pressure, and the gripper closes on whatever is between them. Skin, a cable, a fingertip. | Physical jaw travel stop, or a compliant TPU finger. Keep hands out of the closing path. |
| Trapping against a fixture | 8 N is nothing in free air and quite a lot when a finger is between the link and a bench clamp. | Clear the workspace. Nothing rigid within the reach envelope. |
| Uncommanded drop | LeRobot disables torque on disconnect by default. Kill the process and the arm falls under gravity, gripper and payload with it. | Never stand something breakable, or a hand, under a raised arm. |
| Tipping and dragging | Table clamps are in the bill of materials for a reason. An unclamped base walks when the arm accelerates. | Clamp the base. Both clamps, every time. |
| Hot servo | A stalled servo draws current and heats. Printed PLA mounts soften long before anything electrical fails. | Do not leave a stalled arm powered. Watch for a policy that holds against a hard stop. |
| Wiring and the mains supply | The arm at 7.4 V is below the Low Voltage Directive's 75 V DC floor, so the arm is not LVD equipment. The mains power supply is, and it needs to be a compliant one. | Use a CE marked supply from a real vendor. Do not build your own mains PSU. |
The STS3215 ships in a 7.4 V and a 12 V variant under the same part number. An SO-100, SO-101 and the LeKiwi arm all use the 7.4 V servos; feeding them 12 V destroys them. The LeKiwi has a 12 V base, and a Koch v1.1 has both 5 V and 12 V rails, so if you own more than one arm there is a 12 V barrel jack on your desk that fits a 7.4 V arm perfectly. Label your supplies. This is the single most expensive avoidable error on this hardware, and it is not a safety issue so much as a 150 EUR one.
The three software limits you actually have
LeRobot gives you three mechanisms that behave like safety measures, and it is worth knowing exactly what they do and what their defaults are, because two of the three are off unless you turn them on. These come from calibration and from the follower robot config, read from the LeRobot main branch on 2026-08-24. If you have not calibrated an arm yet, the SO-100 getting started walkthrough and the teleoperation documentation cover the mechanics; this section is only about which of those knobs behave like limits.
- 1Cap how far a joint can move in one step
max_relative_target clamps the difference between the commanded position and the measured present position, per motor. It defaults to
None, which means no clamp at all. Set it to a float for all joints or a dict per joint. The cost is real: enabling it forces an extra sync_read of the follower every step, and the source comment says to expect slower fps.bash# clamp every joint to 5 units of travel per control step lerobot-teleoperate \ --robot.type=so100_follower \ --robot.port=/dev/tty.usbmodem58760431551 \ --robot.id=my_follower \ --robot.max_relative_target=5 \ --teleop.type=so100_leader \ --teleop.port=/dev/tty.usbmodem58760431552 \ --teleop.id=my_leader - 2Let calibration set the joint travel limits
Calibration records range_min and range_max for each motor and writes them to the servo. This is the only limit that is on by default, and it is the reason a badly calibrated arm can drive a link into a hard stop. If a joint stops short of where you expect, that is calibration, not the policy.
bashlerobot-calibrate \ --robot.type=so100_follower \ --robot.port=/dev/tty.usbmodem58760431551 \ --robot.id=my_follower # move to mid-range, press ENTER, then sweep every joint # except wrist_roll through its full travel - 3Know which torque limits are written, and why
At connect time LeRobot writes PID gains to every motor and torque limits to exactly one: the gripper. The comments in the source say these exist to avoid burnout. They are motor protection, not human protection. The five arm joints run at the servo's own defaults.
python# lerobot/robots/so_follower/so_follower.py, configure() self.bus.write("P_Coefficient", motor, 16) self.bus.write("I_Coefficient", motor, 0) self.bus.write("D_Coefficient", motor, 32) if motor == "gripper": self.bus.write("Max_Torque_Limit", motor, 500) # 50% of max torque self.bus.write("Protection_Current", motor, 250) # 50% of max current self.bus.write("Overload_Torque", motor, 25) # 25% when overloaded
disable_torque_on_disconnect defaults to True in the SO follower config. That is the right default for the servos and the wrong mental model for you: when your script exits, crashes, or you hit Ctrl-C, the arm goes limp and falls. If it is holding a payload over a keyboard, the payload lands on the keyboard. There is no controlled stop, no brake and no hold. Plan your workspace around gravity, and see arm twitches then sags for the related failure mode.
Beyond that, the Feetech register table LeRobot uses exposes limits you can write yourself if you want a harder ceiling than the defaults. These are servo registers, not LeRobot features, so nothing in the stack manages them for you and nothing resets them when you unplug.
# Registers exposed in lerobot/motors/feetech/tables.py (STS3215)
Min_Position_Limit addr 9 joint travel floor
Max_Position_Limit addr 11 joint travel ceiling
Max_Temperature_Limit addr 13 thermal cutoff
Max_Voltage_Limit addr 14 over-voltage guard
Min_Voltage_Limit addr 15 under-voltage guard
Max_Torque_Limit addr 16 ceiling written to gripper only (500)
Protection_Current addr 28 written to gripper only (250)
Overload_Torque addr 36 written to gripper only (25)
Torque_Limit addr 48 runtime torque scaling
Present_Temperature addr 63 read-only, watch this one
Present_Current addr 69 read-onlyYou own the arm, so you own every duty attached to it. That is fine and it is what most people should do. The work is not hard, it is just work, and almost all of it is the risk assessment rather than the paperwork.
- Write down the limits of use: reach envelope, payload, who operates it, where it stands, what is nearby. ISO 12100 calls this determining the limits of the machinery and it is the step people skip.
- List the hazards. Use the table above as a starting point and add your own gripper and your own bench.
- Reduce by design first: clamp the base, clear the envelope, fit a jaw stop, put the power switch where a startled person's hand goes.
- Then guarding, then information. A laminated card that says
do not reach in while the light is onis information, and it is the weakest of the three, which is why it comes last. - If an employee will use it, document the assessment before first use. In Germany that is BetrSichV section 3, and the documentation duty is explicit.
- If you will sell it, add the technical file, the instructions, the EU declaration of conformity and the CE marking, and keep the file 10 years.
A risk assessment for a 1.6 N.m desk arm is two sides of paper. Consultants are worth it when you have a cell, an interlock chain and a performance level to justify. They are not worth it to tell you to clamp the base. Spend the money on a light curtain if you genuinely need one.
The platform does not do compliance and will not pretend to. What it does change is where the moving machine is. If you drive a hosted arm over teleoperation and train in the cloud, the machinery duties sit with whoever owns and operates that arm, not with you. That is a real reduction in obligation, not a paperwork trick.
- /live streams a physical arm with no signup, queue-based. Nothing moves on your desk, so nothing on your desk is machinery.
- Training runs on rented cloud GPUs, so there is no hardware in your building to assess. See pricing for what a run costs.
- Inference pods carry an idle watchdog and destroy themselves after an idle period, which is a billing safeguard rather than a safety one, but it is the same instinct.
- Operators work on arms that are built, clamped and maintained centrally by people whose job that is.
- The moment you plug your own arm in, every duty in the left-hand tab is back, unchanged. The platform has no visibility into your bench.
Teleoperating an arm you cannot see has its own failure mode: you are not there to catch it. Inference on this platform runs at 20 ms per action step for ACT up to 485 ms for Pi0.5, and adding public-internet round trips on top turns a working policy into a hesitant one. For a fast reactive task, remote inference is the wrong architecture regardless of who is liable. See inference latency.
When it stops being a toy
There is no line in any regulation that says a robot arm becomes serious at a given mass or torque. But there are thresholds in practice, and every one of them is about context rather than the machine. Here is the list I would actually use. It is the same instinct as the one behind collecting high-quality training data: the thing that changes the answer is almost never the hardware.
- Somebody who did not build it operates it. Your tacit knowledge of where the arm swings is not transferable. This is the single biggest step change.
- It runs unattended. A policy executing rollouts while you make coffee is a different machine from one you are watching.
- It leaves the bench. A mobile base changes the reach envelope from fixed to unbounded. A LeKiwi is not a desk arm.
- The payload gets heavier or sharper. Force at the gripper is force at the gripper. What it is holding decides the consequence.
- It is at a place of work. Employer duties do not scale with machine size, and an inspector does not care that it cost 130 EUR.
- You sell one. The transaction is the trigger, not the price.
- You bolt on a bigger gripper, a 12 V supply, or a second arm. Look again at Article 3(16) on substantial modification.

- The risk assessment doubles as an operating procedure. Half the value is that you finally write down the reach envelope.
- If the project ever moves into a company, the file already exists and you are not reconstructing it from memory two years later.
- It forces the boring physical controls that actually work: clamped base, cleared envelope, reachable switch.
- Selling a kit or a service later stops being a rewrite and becomes an extension.
- A documented assessment is what an insurer or an employer will ask for, and neither will accept an argument about newton metres.
- For a genuinely private build it is pure overhead. Nobody will ever ask to see it.
- It tempts people into buying certification they do not need. A notified body for a 1.6 N.m desk arm is not proportionate.
- The standards do not fit, so you will spend time deciding which one to not apply. That time buys nothing.
- It can make you complacent about the two hazards that actually recur here, which are the gripper and the limp arm on disconnect.
- Formal safety work has an opportunity cost, and for most readers the better use of that day is recording another 20 episodes.
Liability does not wait for CE marking
Everything above is product law and workplace law: rules about whether you may put a thing on the market or into use. There is a third body of law that people forget entirely, and it is the one most likely to matter to a hobbyist, because it attaches to harm rather than to paperwork. Directive (EU) 2024/2853 on liability for defective products has to be transposed into national law by 9 December 2026 and replaces the 1985 directive that has governed this since before any of us were writing robot code.
Two changes in it are directly relevant to anyone running a policy on hardware. First, the definition of product now explicitly covers software, standalone or in combination with another product. A trained checkpoint is software. Second, free and open-source software is carved out of scope when it is not supplied in the course of a business activity, and that carve-out disappears if there is a chargeable service, or a service supplied in exchange for personal data.
| What you do with the arm or the checkpoint | Product law duty | Liability exposure |
|---|---|---|
| Keep both private | None in practice | Ordinary civil liability only. No product-liability route, because nothing was supplied. |
| Publish a checkpoint on a model hub for free, no service attached | None | Within the open-source carve-out, provided it is genuinely not a business activity. |
| Publish the same checkpoint and charge for support, or take personal data for it | None from machinery law | The carve-out falls away. Software is a product again. |
| Sell an assembled arm | Full manufacturer obligations under Regulation (EU) 2023/1230 | Both routes live at once. This is the case that needs a real review. |
The line that matters is business activity, and it is the same line that runs through the Machinery Regulation's definition of making available on the market. Keep the arm and the checkpoint outside commercial supply and both regimes leave you alone. Take money, or take data in place of money, and both wake up. Note the dates are different: the machinery rules bite on 20 January 2027, the liability transposition deadline is 9 December 2026, and national transposition may land earlier or with local variation. Check your own member state rather than this page.
A risk assessment you can finish in an afternoon
If you decided a duty applies, this is the work. It is not a certification exercise and it does not need a template from a consultancy. ISO 12100 is the type A standard that describes the method, and the method is four moves: determine the limits of the machinery, identify the hazards, estimate and evaluate the risk, then reduce it in a fixed order. The fixed order is the part people get wrong. Inherently safe design beats guarding, guarding beats a warning label, and a warning label on its own is almost never an adequate answer to a hazard you could have designed out with a clamp.
- 1Fix the limits of use in writing
Reach envelope in centimetres, maximum payload, operating hours, who may operate. Take a photo of the bench and mark the envelope on it. If you cannot draw the envelope, you do not know it.
- 2Walk the hazards physically
Power the arm, drive it slowly through its full travel with the leader arm, and watch what it comes near. Do this once with the bench as it actually is, not as you tidied it for the photo. Add anything you find to the hazard list.
- 3Apply the three-step method in order
Inherently safe design first, then guarding and protective devices, then information for use. Clamping the base is step one. A warning sticker is step three, and a step-three control alone is almost never enough.
- 4Test the stop you actually have
Confirm what happens on Ctrl-C, on unplugging USB, and on cutting power. On a stock LeRobot config, all three end in a limp arm. Decide whether that is acceptable at every height the arm reaches, and if it is not, do not let it reach that high with a payload.
- 5Write the two-page record
Hazards, controls, residual risk, who checked and when. That is the whole document. If an employee uses the arm, this is not optional and it must exist before first use.
textSO-100 bench arm, hazard record, 2026-08-24 Limits reach 35 cm radius, payload under 200 g, operator: named individuals only Hazards gripper pinch; trap against clamp; limp drop on disconnect; hot servo on stall Controls base clamped x2; envelope cleared 40 cm; nothing breakable under raised arm; switched power strip within arm's reach of the operator; TPU compliant fingers fitted Residual limp drop cannot be eliminated: no brake exists. Height limited by procedure. Review on any gripper or payload change
Where AY-Robots does not help
This platform records LeRobot datasets, fine-tunes five policies on rented GPUs and serves the result back to an arm. None of that is a compliance product. It cannot CE mark anything, it does not know what is on your bench, and there is no emergency stop in the stack because there is no hardware in the stack that belongs to it. A policy that fails safely is a property of your wiring and your workspace, not of the checkpoint.

Three things, and it is worth being precise. First, hosted arms move the machinery duty off your desk entirely. Second, the failure-mode pages catalogue behaviours like policy freezes mid-motion and joint stops early, which are exactly the surprises you do not want an operator to meet first. Third, the security documentation covers how sessions and devices are authorised, which is the cybersecurity limb the 2025 ISO 10218 revision added. None of that is a substitute for a risk assessment.
One more honest limit. Nothing on this page is legal advice, and the reason it can be this specific is that the underlying question is usually simpler than people fear. If your arm is private, you are fine. If it is at work, do the hazard assessment, and do it before the first person who is not you presses go. If you sell arms, get a real compliance review, because from 20 January 2027 the file you are building is against a Regulation and not a Directive. Everything between those three cases is detail. And if none of this appeals, start without owning an arm and let the machinery duty stay with somebody who already has a risk assessment on file.
The failure modes worth understanding before someone else drives
A joint that stops early, an arm that twitches then sags, a policy that freezes mid-motion. Each of these is a documented cause and a fix, and each is a surprise you do not want a new operator to meet on their first session.
Read the failure-mode indexDoes my self-built SO-100 need a CE marking?▾
If you built it and use it privately at home, no. You have not placed it on the market, and no realistic enforcement route exists. If you built it and an employee uses it at work, then yes in principle: building for own use still counts as putting into service, which carries the manufacturer's obligations. In that case the workplace duty under Directive 2009/104/EC arrives first and matters more, because that is the one with inspectors attached. If you sell arms or kits, full manufacturer obligations apply.
Does the EU AI Act apply to a policy I fine-tuned myself?▾
Almost certainly not. Article 2(8) excludes research, testing and development activity prior to placing on the market or putting into service, with the caveat that testing in real world conditions is not covered by that exclusion. Article 2(10) excludes natural persons using AI systems in a purely personal non-professional activity. And the high-risk route via Article 6(1) needs two conditions together: the AI must be a safety component of a product covered by Annex I legislation, and that product must require third-party conformity assessment. A policy that moves a gripper is a control function, not a safety component.
Which safety standard should I actually read?▾
ISO 12100. It is the type A standard for risk assessment and risk reduction, it is method rather than thresholds, and it applies to any machinery. ISO 10218-1:2025 and ISO 10218-2:2025 cover industrial robots and explicitly not service or household applications, so they do not apply to a desk arm, though reading them tells you how the profession thinks about contact. ISO 13482 covers personal care robots and excludes industrial robots and robot toys, so a hobby arm falls between the two.
What changes on 20 January 2027?▾
Regulation (EU) 2023/1230 becomes mandatory for machinery placed on the EU market, replacing Directive 2006/42/EC. Machinery placed on the market before that date continues to follow the Directive. For a hobbyist nothing changes. For anyone selling arms or kits, the technical file, the conformity assessment route and the declaration of conformity all need reworking against the Regulation, and the two Annex I categories concerning machine learning safety components become live.
Is the arm safe enough to leave running unattended?▾
The force is low: an STS3215 at 7.4 V is quoted at 16.5 kg.cm stall torque at 6 V, about 1.6 N.m, or roughly 8 N at 20 cm from the joint. The problem with unattended running is not force, it is the failure modes. LeRobot disables torque on disconnect by default, so any crash drops the arm and whatever it holds. A stalled servo heats up and printed mounts soften. Nothing in the stack notices either. If you must run unattended, clear everything under the arm, keep the payload light, and put the whole thing on a switched strip you can kill.
Sources
- Regulation (EU) 2023/1230 on machinery, full text on EUR-Lex
- European Commission: machinery, mandatory from 20 January 2027
- EU-OSHA: Directive 2009/104/EC on the use of work equipment by workers
- AI Act Article 2: scope and the research and personal-use exclusions
- AI Act Article 6(1): the two cumulative conditions for high-risk
- ISO 10218:2025 revision, and what happened to ISO/TS 15066
- TheRobotStudio/SO-ARM100: 16.5 kg.cm at 6 V, 7.4 V against 12 V servos
- LeRobot SO follower config: max_relative_target defaults to None
- LeRobot SO follower: gripper-only torque limits written at connect
- BetrSichV section 3: documented hazard assessment before first use
- OSH Act section 5(a)(1): the US general duty clause
- UK guidance: CE marking recognised in Great Britain alongside UKCA
- IBA: liability for software under Directive (EU) 2024/2853
Sources
- Regulation (EU) 2023/1230 of 14 June 2023 on machinery
- European Commission: Machinery, mandatory application from 20 January 2027
- EU-OSHA: Regulation 2023/1230/EU on machinery
- EU-OSHA: Directive 2009/104/EC, use of work equipment by workers
- AI Act Article 2: scope, research and personal non-professional use
- AI Act Article 6: classification rules for high-risk AI systems
- AI Act Annex I: Union harmonisation legislation, Section A
- ISO 10218 industrial robot safety standard receives major overhaul
- TheRobotStudio/SO-ARM100: build repository, servo variants and stall torque
- LeRobot SO follower config: max_relative_target, disable_torque_on_disconnect
- LeRobot SO follower: configure() writes gripper torque and current limits
- LeRobot Feetech register table: STS3215 torque, current and temperature limits
- BetrSichV section 3: Gefaehrdungsbeurteilung, documented before first use
- UK government guidance on using the UKCA marking and CE recognition
- International Bar Association on Directive (EU) 2024/2853: software as a product, 9 December 2026
Ready for high-quality robotics data?
AY-Robots connects your robots to skilled operators worldwide.
Get Started