1. OT/IT convergence risks: The integration of operational technology and IT opens new attack vectors. NIS2 mandates board-level cybersecurity accountability that most automation businesses have not established. IEC 62443 is becoming the standard.
2. Triple compliance: EU AI Act + Machinery Regulation + sector-specific safety standards (ISO 10218, IEC 62443). Three regulatory frameworks, one product. Most product teams lack the expertise to navigate this in an integrated way.
3. Physical AI governance gap: The market recognises five autonomy levels for industrial AI. Most companies operate at levels 1–2 but have no governance framework for the transition to levels 3–5 — where AI operates autonomously.
4. Customer education: End customers have limited AI literacy. Automation providers must bridge the gap between technical capabilities and safe, responsible deployment — including EU AI Act obligations for their customers.