Extended Reality (XR) and Artificial Intelligence (AI) are increasingly finding their way into industrial environments. From immersive training and remote maintenance to AI-assisted guidance and personalised learning, these technologies offer significant opportunities for the factories and workplaces of the future. Yet their adoption also raises an important question: how can organisations ensure that innovation develops in line with European requirements on data protection, cybersecurity and trustworthy AI?
Within the XR5.0 project, we have been exploring this question through a compliance-by-design approach. The underlying idea is relatively simple: legal and ethical requirements should not be considered only once a technology has been developed. They should influence the way technologies are designed from the beginning. This builds on the principle of data protection by design contained in Article 25 of the General Data Protection Regulation (GDPR), but extends the same logic to cybersecurity, AI governance and broader ethical considerations.
Compliance starts with design
The European regulatory landscape surrounding XR and AI has become increasingly complex. Depending on the application, organisations may need to consider not only the GDPR, but also the NIS2 Directive, the Cybersecurity Act, the Cyber Resilience Act and, increasingly, the EU AI Act. These frameworks are often discussed separately. In practice, however, many of their requirements overlap, particularly when XR platforms combine personal data, industrial information, cloud infrastructure and AI-enabled functionalities.
The XR5.0 Training Platform provides a useful example. It is a cloud-based system that hosts, manages and streams immersive training applications to workers using different XR devices. Although the platform is not itself a standalone AI system, it incorporates AI-enabled functionalities, including local large language model processing, an AI-assisted chat function and adaptive personalisation tools. Rather than addressing privacy, security and AI governance as separate compliance exercises, the platform attempts to translate these requirements into concrete architectural choices.
Protecting data and systems through architecture
XR environments can potentially generate large amounts of personal and operational data. This makes data minimisation particularly important. The XR5.0 Training Platform deliberately limits the personal information it processes. Another important design choice is pixel streaming: XR applications are rendered in the cloud and streamed to users as encoded video, meaning that sensitive industrial information does not need to be stored locally on XR headsets. Personal data processed by the platform are also stored within the European Economic Area. These choices reflect a broader approach to data protection and security by design.
The same principle applies to cybersecurity. The platform uses several layers of protection, including session-token authentication, encrypted communications, role-based access controls and tenant isolation. System access and user actions are logged, supporting both security monitoring and accountability. This illustrates one of the main advantages of compliance by design: a single technical measure can often serve several regulatory objectives. Audit logging, for example, can help investigate cybersecurity incidents while also providing the traceability expected under AI governance frameworks. Similarly, cloud-based rendering can improve system performance while reducing local data exposure and protecting AI components from certain forms of attack.
Keeping humans in control
Human oversight becomes particularly important when AI is introduced into workplace training. In XR5.0, training programmes remain under the control of human administrators. AI may assist with tasks such as structuring training material or suggesting personalised learning paths, but it does not independently determine what workers should learn. Administrators define programmes, assign skill levels and approve training materials. They can also monitor active XR sessions and stop applications when necessary. Even where AI-driven personalisation is used, final training assignments remain subject to human control. This approach reflects the human-oversight principles underpinning the AI Act and the broader human-centric philosophy of Industry 5.0.
Transparency is equally important. Where workers interact with the XR-AI Assistant, AI-generated responses are identified as such so that users know when content comes from an AI-enabled functionality rather than human-authored training material. These measures also reflect the seven requirements of the European Commission’s Assessment List for Trustworthy Artificial Intelligence (ALTAI): human agency and oversight, technical robustness and safety, privacy and data governance, transparency, diversity and fairness, societal and environmental wellbeing, and accountability. In XR5.0, these principles are not treated simply as abstract ethical aspirations; they are translated into platform features and governance mechanisms.
From compliance checklist to engineering principle
Perhaps the most important lesson from XR5.0 is that compliance should not be treated as a checklist applied at the end of technological development. Many legal and ethical requirements actually point towards the same good design choices. Data minimisation can improve privacy while reducing security risks. Human oversight can support regulatory compliance while improving training quality. Audit logs can contribute simultaneously to cybersecurity, transparency and accountability. In this sense, compliance by design requires lawyers, engineers, developers and other stakeholders to work together early enough for legal and ethical requirements to influence technological choices.
As XR and AI become increasingly integrated into industrial workplaces, compliance will remain a moving target. Technologies evolve, use cases change and regulatory obligations continue to develop. Building compliance into the architecture from the outset does not eliminate this challenge, but it provides a much stronger foundation for adapting responsibly. The broader lesson from XR5.0 is therefore that regulation and innovation do not necessarily need to pull in opposite directions. When legal, ethical and technical considerations are aligned from the beginning, compliance can become part of good engineering rather than an obstacle added at the end.
By Marcelo Corrales Compagnucci
Authors: Emanuele Fagnano, Davide Matteri, Vincenzo Cutrona, Elias Montini. SUPSI, SPS lab
[1] Montini, E., Bonomi, N., Daniele, F., Bettoni, A., Pedrazzoli, P., Carpanzano, E., & Rocco, P. (2021). The human-digital twin in the manufacturing industry: Current perspectives and a glimpse of future. Trusted artificial intelligence in manufacturing: A review of the emerging wave of ethical and human centric AI technologies for smart production, 132-147.
[2] Montini, E., Cutrona, V., Dell’Oca, S., Landolfi, G., Bettoni, A., Rocco, P., & Carpanzano, E. (2023). A framework for human-aware collaborative robotics systems development. Procedia CIRP, 120, 1083-1088.
[3] Christen, S., Yang, W., Pérez-D’Arpino, C., Hilliges, O., Fox, D., & Chao, Y. (2023). Learning Human-to-Robot Handovers from Point Clouds. CVPR 2023.
[4] Sampieri, A., D’Amely, G., Avogaro, A., Cunico, F., Skenderi, G., Setti, F., Cristani, M., & Galasso, F (2022). Pose Forecasting in Industrial Human-Robot Collaboration. ECCV 2022.
[5] Greci L. (2022). XR for Industrial Training & Maintenance. Chapter 13 – Roadmapping Extended Reality: [6] Montini, E., Cutrona, V., Bonomi, N., Landolfi, G., Bettoni, A., Rocco, P., & Carpanzano, E. (2022). An iiot platform for human-aware factory digital twins. Procedia CIRP, 107, 661-667.
