Artificial intelligence is rapidly moving from standalone software into physical products. Machines, medical devices, industrial equipment, robots, vehicles, safety systems and connected products increasingly use AI to detect, predict, control, classify or make decisions.
Under the EU Artificial Intelligence Act — Regulation (EU) 2024/1689, that development creates an important regulatory question for manufacturers:
If artificial intelligence performs a safety-related function inside your product, could the AI system itself become subject to EU high-risk AI conformity requirements?
For some products, the answer is yes.
The AI Act creates a direct connection between artificial-intelligence governance and the established European product-conformity framework. Manufacturers may therefore need to consider AI risk management, technical documentation, data governance, human oversight, cybersecurity and post-market monitoring alongside the product-safety requirements they already manage.
When Does AI Inside a Product Become High-Risk?
The EU AI Act establishes several categories of high-risk AI systems.
One particularly important category for manufacturers concerns AI systems associated with products covered by existing European product legislation.
Under Article 6(1) of the AI Act, an AI system can be classified as high-risk where two conditions are met:
The AI system is intended to be used as a safety component of a product, or the AI system itself constitutes a product covered by relevant EU harmonisation legislation.
The product, or AI system as a product, is required to undergo third-party conformity assessment before being placed on the EU market or put into service.
When both conditions are satisfied, the AI system is considered high-risk under the AI Act.
Manufacturers cannot determine AI Act applicability simply by asking whether a product contains artificial intelligence. The intended function of the AI, its relationship to product safety and the underlying EU product legislation all need to be examined together.
Which Products Could Be Affected?
AI-enabled products are expanding rapidly across industrial and consumer markets.
Depending on the applicable sector legislation and the role performed by the AI system, potentially relevant product categories can include:
The European Commission has specifically highlighted product-related examples such as AI systems operating robots, drones and medical devices when explaining the high-risk classification framework. :contentReference[oaicite:1]{index=1}
Not Every AI Feature Makes a Product High-Risk
The presence of artificial intelligence inside a product does not automatically mean that the product falls into the high-risk AI category.
The regulatory assessment depends on the intended purpose of the AI system and the role it performs.
AI may optimize settings, provide recommendations, personalize user experience or perform functions that do not materially influence product safety.
AI influences or performs a function whose failure could affect the health or safety of persons and the associated product is subject to the relevant third-party conformity-assessment regime.
The Product’s Intended Purpose Becomes Critical
One of the central principles of EU conformity assessment is the manufacturer’s definition of the product’s intended purpose.
The same principle becomes particularly important when artificial intelligence is incorporated into a product.
Manufacturers need to understand:
- what function the AI system performs;
- whether the AI function influences product safety;
- how the AI interacts with users, operators and other systems;
- what decisions or outputs the AI can generate;
- what happens if the AI behaves incorrectly;
- whether human intervention remains possible;
- what underlying EU product legislation applies; and
- whether that legislation requires third-party conformity assessment.
AI Conformity Assessment Becomes Part of Product Conformity
One of the most important features of the AI Act is its attempt to avoid creating unnecessary duplicate conformity-assessment systems.
Where a high-risk AI system is incorporated into a product covered by relevant Union harmonisation legislation, the AI Act requirements are incorporated into the conformity-assessment procedure required for that product. :contentReference[oaicite:2]{index=2}
This means manufacturers may increasingly need to demonstrate compliance with both:
Safety, performance, mechanical, electrical, functional or other sector-specific requirements established under applicable EU product legislation.
Risk management, data governance, technical documentation, records, transparency, human oversight, accuracy, robustness and cybersecurity.
What Must High-Risk AI Systems Demonstrate?
High-risk AI systems are subject to a structured set of requirements designed to support trustworthy and controlled use of artificial intelligence.
Before such a system is placed on the EU market or put into service, the provider must ensure that the applicable requirements have been addressed and that the relevant conformity-assessment procedure has been completed. :contentReference[oaicite:3]{index=3}
Establish and maintain a systematic process for identifying, evaluating, controlling and monitoring AI-related risks.
Ensure appropriate governance and quality controls for training, validation and testing data where relevant.
Maintain documentation capable of demonstrating system design, intended purpose, operation and compliance.
Enable appropriate logging and traceability of AI-system operation where required.
Provide sufficient information to enable deployers to understand and appropriately use the system.
Design appropriate mechanisms allowing humans to supervise, interpret or intervene in system operation.
Establish appropriate levels of performance, consistency, resilience and fault tolerance.
Protect the high-risk AI system against relevant cybersecurity threats and manipulation.
Risk Management Becomes a Lifecycle Process
AI risk management cannot be treated as a single document prepared immediately before certification.
Under the AI Act, risk management is intended to operate as a continuous and iterative process throughout the lifecycle of the high-risk AI system.
Manufacturers and AI providers should therefore consider how risks are identified during development, how they are controlled before market placement and how new risks are detected once products are in use.
Data Quality Can Become a Product-Conformity Issue
Traditional product conformity has generally focused on the characteristics and performance of the physical product.
Artificial intelligence introduces another dimension: the data used to develop, validate and test the system can influence how reliably the product performs.
For high-risk AI systems, data governance therefore becomes part of the regulatory framework.
Manufacturers integrating externally developed AI systems may therefore need considerably more information from software developers and technology suppliers than they traditionally required from component suppliers.
Human Oversight Must Be Designed Into the Product
High-risk AI systems need appropriate human-oversight arrangements.
The appropriate level of oversight will depend on the intended use, level of automation, associated risks and the ability of users or operators to understand and influence system behaviour.
- whether operators can understand AI outputs;
- whether warnings or limitations are clearly communicated;
- whether humans can override or stop the AI function;
- whether over-reliance on automated outputs could create risk;
- what competence operators require; and
- how oversight mechanisms are validated during product testing.
Cybersecurity and AI Safety Are Increasingly Connected
AI-enabled products can create cybersecurity risks that directly affect product behaviour.
Manipulation of input data, interference with models, unauthorized system access or compromised software components could potentially alter AI outputs and therefore affect safety or performance.
The AI Act consequently includes cybersecurity among the mandatory requirements for high-risk AI systems.
Cybersecurity certification or conformity statements issued under certain EU cybersecurity schemes may also create a presumption of conformity with corresponding AI Act cybersecurity requirements where those requirements are covered. :contentReference[oaicite:4]{index=4}
Technical Documentation Must Explain the AI
Technical documentation becomes particularly important because authorities and conformity-assessment bodies need to understand how the AI system has been designed, validated and controlled.
Depending on the system and applicable requirements, documentation may need to address areas such as:
This requires close coordination between AI developers and the manufacturer responsible for placing the final product on the market.
Quality Management Systems Become Part of AI Compliance
Providers of high-risk AI systems are required to establish a quality management system supporting compliance with the AI Act. :contentReference[oaicite:5]{index=5}
This is particularly relevant for manufacturers already operating established management systems because AI governance may need to be integrated into existing design, development, supplier, verification, corrective-action and post-market processes.
Integrate AI requirements into product-development and change-control processes.
Define technical and compliance requirements for externally developed AI systems, models and software.
Establish evidence that AI functionality performs as intended under appropriate conditions.
Maintain technical, risk, testing and compliance records supporting the conformity assessment.
Manage deficiencies, incidents and nonconformities identified during development or post-market operation.
Monitor system performance and emerging risks after the product has entered service.
When Is a Notified Body Involved?
Not all high-risk AI systems follow the same conformity-assessment route.
For high-risk AI systems connected with products covered by Union harmonisation legislation listed in Annex I of the AI Act, the conformity-assessment procedure follows the procedure required under the applicable product legislation. AI Act requirements become part of that assessment. :contentReference[oaicite:6]{index=6}
Where the underlying product legislation requires involvement of a notified body, the relevant AI requirements can therefore become part of that third-party conformity assessment.
The manufacturer follows the conformity-assessment procedure established by the relevant EU product legislation.
The same conformity framework incorporates applicable AI Act requirements relating to the high-risk AI system.
CE Marking Connects the Two Regulatory Worlds
Providers of high-risk AI systems subject to the AI Act must complete the applicable conformity assessment and draw up an EU Declaration of Conformity before market placement.
For product-related high-risk AI, this framework interfaces with the established European CE-marking system.
The result is an increasingly integrated conformity model in which the manufacturer may need to demonstrate both traditional product compliance and AI-system compliance within one overall market-access strategy.
The question is no longer simply whether a machine or device complies with European product-safety requirements. Manufacturers increasingly need to understand whether the intelligence controlling that product also creates regulatory obligations of its own.
Substantial Modification Can Trigger Reassessment
Artificial intelligence systems can evolve rapidly.
Software updates, model changes, retraining, modified datasets or changes to intended purpose can potentially alter system behaviour.
Under the AI Act, a substantial modification can require renewed conformity assessment before the modified system is placed on the market or put into service. :contentReference[oaicite:7]{index=7}
The Supply Chain Becomes More Complex
Many manufacturers will not develop every AI system internally.
Products may incorporate third-party models, externally developed software, AI-enabled components, cloud services or systems supplied by specialist technology companies.
This creates new supply-chain questions.
- who legally acts as the AI provider;
- who controls the intended purpose of the AI system;
- what technical information must be supplied by the AI developer;
- what rights the manufacturer has to review or audit the AI technology;
- how model or software changes are communicated;
- who manages incidents and corrective action;
- how cybersecurity responsibilities are allocated; and
- how conformity evidence is maintained throughout the supply chain.
What Manufacturers Should Be Doing Now
Manufacturers integrating artificial intelligence into products should begin by understanding exactly where AI exists within their product portfolio and what role it performs.
Identify products containing AI and document the functions those systems perform.
Identify the EU harmonisation legislation applicable to each AI-enabled product.
Determine whether the AI performs a safety function and whether the product requires third-party conformity assessment.
Compare existing development, testing, risk and quality controls against applicable AI Act requirements.
Ensure AI design, intended purpose, data, risk management, validation and oversight arrangements can be demonstrated.
Establish access to the technical information and change notifications needed from AI technology suppliers.
Connect AI governance with design control, supplier management, verification, corrective action and post-market monitoring.
Determine how AI Act requirements integrate with the existing product certification and notified-body pathway.
High-Risk Classification Is Becoming a Critical Decision
Correct classification is one of the most important early decisions under the AI Act.
In May 2026, the European Commission published draft guidelines intended to help providers, deployers and authorities determine whether AI systems fall within the high-risk categories established by Article 6. The guidance specifically addresses both AI incorporated into regulated products and AI systems falling within Annex III use cases. :contentReference[oaicite:8]{index=8}
Manufacturers should therefore avoid relying solely on informal descriptions such as “AI-enabled” or “smart product.”
Classification needs to be based on the AI Act, the intended purpose of the system, applicable product legislation and the actual role of the AI within the product.
From Product Safety to Intelligent Product Assurance
The EU AI Act represents an important evolution in product conformity.
Traditional product regulation has concentrated primarily on physical, mechanical, electrical and functional characteristics.
AI-enabled products introduce another layer: manufacturers may increasingly need to demonstrate that the decision-making technology inside the product is also appropriately governed, tested, documented and monitored.
This creates a new intersection between product certification, software assurance, artificial-intelligence governance, cybersecurity, quality management and market access.
Is the AI Inside Your Product Ready for Conformity Assessment?
Manufacturers should not wait until the final certification stage to determine whether an embedded AI system creates additional regulatory obligations.
An early review can clarify high-risk classification, applicable product legislation, AI documentation requirements, testing needs, supplier responsibilities and the appropriate conformity-assessment route.
The most difficult AI Act question for many manufacturers may not be whether they use artificial intelligence. It will be determining when that intelligence becomes part of the regulated safety architecture of the product.