(Photo: © LIFTjournal/Dirk Müller/KI-assistiert mit Firefly und ChatGPT)

From conveyance device to digital system

News

The lift has undergone a fundamental change in recent years. What used to be primarily a mechanical-electrical conveyance device is now a networked, data-generating and in part self- optimising system.

Condition monitoring, predictive maintenance, cloud connections, API interfaces and AI-supported functions are now reality. Consequently, the lift has become part of a digital ecosystem and simultaneously part of the European regulation framework.

BY TIM EBELING

This environment is in particular characterised by four central legal instruments: the Data Act, the Artificial Intelligence Act (AI Act), the Cyber Resilience Act and the NIS 2 Directive. Each of these legal instruments addresses a different aspect of digitalisation. But together they form a closely-meshed regulatory framework that directly affects the lift sector.

Data Act – who do the lift data belong to?

Tim Ebeling Photo: © LIFTjournal/Bernd LorenzTim Ebeling Photo: © LIFTjournal/Bernd Lorenz

The Data Act represents a change particularly relevant in this respect. Since 12 September 2025, users of a product are entitled to access to its raw operating data and this at no charge, in the same quality and at the same speed as they are available to the manufacturer.

The user in this regard is not the passenger but the person or company with a property or usage right to the lift. Depending on the constellation, this could also be a tenant.

This shifts the balance of power in the after-sales market. Data which used to effectively remain with the manufacturer now also have to be made available on request to third parties, such as competing maintenance companies. This is deliberately intended to increase competition in the service business.

This means two things for manufacturers: operating data may only still be used by them on a contractual basis. At the same time, products must be technically configured to ensure that data access is possible and described. New products must permit direct access to users from September 2026 at the latest.

As things stand, it remains unclear what exactly is to be understood under "raw data" and who counts as the manufacturer bound to provide data in the case of modernisations or retrofitted IoT solutions. The need for additional clarification will probably arise here in future.

AI Act – how is AI in lifts regulated?

Parallel to this, the AI Act regulates the deployment of Artificial intelligence. The decisive point here is not whether AI is deployed but what risk it represents.

Many applications in the field of lifts belong to the category of minimal risk, such as predictive maintenance, energy optimisation or traffic management. These systems are not subject to any special authorisation obligations. But since February 2025, companies must ensure that their personnel have adequate AI competence.

It is something else if AI assumes safety-relevant functions or is deployed in critical infrastructures. For example, where AI adaptively controls brake parameters or automates evacuation strategies, a high-risk rating might exist.

In this case, comprehensive requirements, such as risk management, technical documentation, CE labelling, registration, human supervision and reporting obligations in the event of incidents would apply. Operators would also be responsible here, since they have to ensure proper use.

Cyber Resilience Act – cyber security as product requirement

Whereas the Data Act regulates access to data and the AI Act addresses intelligence in the system, the Cyber Resilience Act focuses on digital product safety.

It applies to all products with digital elements and as a result also to lifts. The goals are the principles "security by design" and "security by default". This means that products may not be supplied in an unsafe configuration (security by default) but rather have to possess suitable protective mechanisms (security by design), their weak points have to be managed systematically and they have to receive security updates during their service life.

"New products must permit direct access to users from September 2026 at the latest."

Tim Ebeling

For long service systems like lifts, the minimum requirement for the provision of updates for five years will clearly be inadequate.

The technical documentation, including risk evaluation, also has to be kept available over the long term. From the end of 2027, the conformity assessment under the Cyber Resilience Act will be part of CE conformity.

In most cases, the lift as an overall product will probably be assigned to the standard risk class. However, individual components, such as routers as part of emergency call systems, may be subject to stricter test requirements as "important products". Standards like ISO 8102-20 on cyber security for lifts will play an important role here if they are then available in a harmonised form.

NIS-2/BSI Act – IT security of companies

The NIS-2 Directive is less concerned with the product itself than with the organisation behind it. Manufacturers of lifts and components are often covered by its provisions once they have reached a certain size.

Among other things, structured IT risk management systems, incident reporting processes, secure supply chains, encryption strategies and clear responsibilities are required.

A particularly important aspect here is that unlike many technical standards, the responsibility here lies expressly with the management. IT security thus becomes a management task.

Summary

A clear picture arises when one examines these four legal instruments together: today, the lift is no longer just a technical product but rather a digital platform with data flows, algorithms and network connections.

It is a data source in the meaning of the Data Act, a potential AI user in the meaning of the AI Act, a digital product in the meaning of the Cyber Resilience Act and part of a security-relevant value added chain in the meaning of the NIS-2 Directive.

The technical networking of these systems thus has its regulatory counterpart. This means additional effort for the sector, especially with regard to documentation, IT security and organisational structures.

At the same time, new opportunities are arising thanks to data-based business models and innovative service concepts. Consequently, the modern lift not only transports people between floors but also data, algorithms and regulatory requirements within the digital internal market of the European Union.

The author is the managing director of Henning GmbH, member in the Board of Directors of the VFA-Interlift, of the Committee for Digitalisation and Cyber Security of the European Lift Association and is a member of the advisory board of LIFTjournal.