Technical Insight

GAR INSIGHT
AI Inside Your Product? Understanding EU AI Act Conformity Assessment

Artificial intelligence is rapidly moving from standalone software into physical products. Machines, medical devices, industrial equipment, robots, vehicles, safety systems and connected products increasingly use AI to detect, predict, control, classify or make decisions.

Under the EU Artificial Intelligence Act — Regulation (EU) 2024/1689, that development creates an important regulatory question for manufacturers:

If artificial intelligence performs a safety-related function inside your product, could the AI system itself become subject to EU high-risk AI conformity requirements?

For some products, the answer is yes.

The AI Act creates a direct connection between artificial-intelligence governance and the established European product-conformity framework. Manufacturers may therefore need to consider AI risk management, technical documentation, data governance, human oversight, cybersecurity and post-market monitoring alongside the product-safety requirements they already manage.

The shift is significant: Artificial intelligence embedded in a regulated product can move from being a software feature to becoming part of the product’s formal conformity-assessment and market-access obligations.

When Does AI Inside a Product Become High-Risk?

The EU AI Act establishes several categories of high-risk AI systems.

One particularly important category for manufacturers concerns AI systems associated with products covered by existing European product legislation.

Under Article 6(1) of the AI Act, an AI system can be classified as high-risk where two conditions are met:

Condition 1 — Safety Function

The AI system is intended to be used as a safety component of a product, or the AI system itself constitutes a product covered by relevant EU harmonisation legislation.

Condition 2 — Third-Party Assessment

The product, or AI system as a product, is required to undergo third-party conformity assessment before being placed on the EU market or put into service.

When both conditions are satisfied, the AI system is considered high-risk under the AI Act.

Why this matters:

Manufacturers cannot determine AI Act applicability simply by asking whether a product contains artificial intelligence. The intended function of the AI, its relationship to product safety and the underlying EU product legislation all need to be examined together.

Which Products Could Be Affected?

AI-enabled products are expanding rapidly across industrial and consumer markets.

Depending on the applicable sector legislation and the role performed by the AI system, potentially relevant product categories can include:

The European Commission has specifically highlighted product-related examples such as AI systems operating robots, drones and medical devices when explaining the high-risk classification framework. :contentReference[oaicite:1]{index=1}

Not Every AI Feature Makes a Product High-Risk

The presence of artificial intelligence inside a product does not automatically mean that the product falls into the high-risk AI category.

The regulatory assessment depends on the intended purpose of the AI system and the role it performs.

LOWER REGULATORY SIGNIFICANCE Convenience or Non-Safety AI

AI may optimize settings, provide recommendations, personalize user experience or perform functions that do not materially influence product safety.

POTENTIAL HIGH-RISK SCENARIO AI Performing a Safety Function

AI influences or performs a function whose failure could affect the health or safety of persons and the associated product is subject to the relevant third-party conformity-assessment regime.

The Product’s Intended Purpose Becomes Critical

One of the central principles of EU conformity assessment is the manufacturer’s definition of the product’s intended purpose.

The same principle becomes particularly important when artificial intelligence is incorporated into a product.

Manufacturers need to understand:

  • what function the AI system performs;
  • whether the AI function influences product safety;
  • how the AI interacts with users, operators and other systems;
  • what decisions or outputs the AI can generate;
  • what happens if the AI behaves incorrectly;
  • whether human intervention remains possible;
  • what underlying EU product legislation applies; and
  • whether that legislation requires third-party conformity assessment.

AI Conformity Assessment Becomes Part of Product Conformity

One of the most important features of the AI Act is its attempt to avoid creating unnecessary duplicate conformity-assessment systems.

Where a high-risk AI system is incorporated into a product covered by relevant Union harmonisation legislation, the AI Act requirements are incorporated into the conformity-assessment procedure required for that product. :contentReference[oaicite:2]{index=2}

This means manufacturers may increasingly need to demonstrate compliance with both:

PRODUCT LEGISLATION Traditional Product Requirements

Safety, performance, mechanical, electrical, functional or other sector-specific requirements established under applicable EU product legislation.

AI ACT High-Risk AI Requirements

Risk management, data governance, technical documentation, records, transparency, human oversight, accuracy, robustness and cybersecurity.

For manufacturers, this changes the conformity-assessment conversation. Product engineering, regulatory affairs, software development, AI governance, cybersecurity, quality management and conformity assessment increasingly need to work together.

What Must High-Risk AI Systems Demonstrate?

High-risk AI systems are subject to a structured set of requirements designed to support trustworthy and controlled use of artificial intelligence.

Before such a system is placed on the EU market or put into service, the provider must ensure that the applicable requirements have been addressed and that the relevant conformity-assessment procedure has been completed. :contentReference[oaicite:3]{index=3}

Risk Management

Establish and maintain a systematic process for identifying, evaluating, controlling and monitoring AI-related risks.

Data Governance

Ensure appropriate governance and quality controls for training, validation and testing data where relevant.

Technical Documentation

Maintain documentation capable of demonstrating system design, intended purpose, operation and compliance.

Record Keeping

Enable appropriate logging and traceability of AI-system operation where required.

Transparency

Provide sufficient information to enable deployers to understand and appropriately use the system.

Human Oversight

Design appropriate mechanisms allowing humans to supervise, interpret or intervene in system operation.

Accuracy & Robustness

Establish appropriate levels of performance, consistency, resilience and fault tolerance.

Cybersecurity

Protect the high-risk AI system against relevant cybersecurity threats and manipulation.

Risk Management Becomes a Lifecycle Process

AI risk management cannot be treated as a single document prepared immediately before certification.

Under the AI Act, risk management is intended to operate as a continuous and iterative process throughout the lifecycle of the high-risk AI system.

Manufacturers and AI providers should therefore consider how risks are identified during development, how they are controlled before market placement and how new risks are detected once products are in use.

The practical question changes from “Has the AI been tested?” to “Is the AI system governed throughout its lifecycle?” Testing remains important, but conformity increasingly depends on the complete system of risk management, technical controls, documentation, monitoring and corrective action surrounding the AI.

Data Quality Can Become a Product-Conformity Issue

Traditional product conformity has generally focused on the characteristics and performance of the physical product.

Artificial intelligence introduces another dimension: the data used to develop, validate and test the system can influence how reliably the product performs.

For high-risk AI systems, data governance therefore becomes part of the regulatory framework.

Manufacturers integrating externally developed AI systems may therefore need considerably more information from software developers and technology suppliers than they traditionally required from component suppliers.

Human Oversight Must Be Designed Into the Product

High-risk AI systems need appropriate human-oversight arrangements.

The appropriate level of oversight will depend on the intended use, level of automation, associated risks and the ability of users or operators to understand and influence system behaviour.

Manufacturers may need to consider:
  • whether operators can understand AI outputs;
  • whether warnings or limitations are clearly communicated;
  • whether humans can override or stop the AI function;
  • whether over-reliance on automated outputs could create risk;
  • what competence operators require; and
  • how oversight mechanisms are validated during product testing.

Cybersecurity and AI Safety Are Increasingly Connected

AI-enabled products can create cybersecurity risks that directly affect product behaviour.

Manipulation of input data, interference with models, unauthorized system access or compromised software components could potentially alter AI outputs and therefore affect safety or performance.

The AI Act consequently includes cybersecurity among the mandatory requirements for high-risk AI systems.

Cybersecurity certification or conformity statements issued under certain EU cybersecurity schemes may also create a presumption of conformity with corresponding AI Act cybersecurity requirements where those requirements are covered. :contentReference[oaicite:4]{index=4}

Technical Documentation Must Explain the AI

Technical documentation becomes particularly important because authorities and conformity-assessment bodies need to understand how the AI system has been designed, validated and controlled.

Depending on the system and applicable requirements, documentation may need to address areas such as:

This requires close coordination between AI developers and the manufacturer responsible for placing the final product on the market.

Quality Management Systems Become Part of AI Compliance

Providers of high-risk AI systems are required to establish a quality management system supporting compliance with the AI Act. :contentReference[oaicite:5]{index=5}

This is particularly relevant for manufacturers already operating established management systems because AI governance may need to be integrated into existing design, development, supplier, verification, corrective-action and post-market processes.

Design & Development

Integrate AI requirements into product-development and change-control processes.

Supplier Control

Define technical and compliance requirements for externally developed AI systems, models and software.

Verification & Validation

Establish evidence that AI functionality performs as intended under appropriate conditions.

Document Control

Maintain technical, risk, testing and compliance records supporting the conformity assessment.

Corrective Action

Manage deficiencies, incidents and nonconformities identified during development or post-market operation.

Lifecycle Monitoring

Monitor system performance and emerging risks after the product has entered service.

When Is a Notified Body Involved?

Not all high-risk AI systems follow the same conformity-assessment route.

For high-risk AI systems connected with products covered by Union harmonisation legislation listed in Annex I of the AI Act, the conformity-assessment procedure follows the procedure required under the applicable product legislation. AI Act requirements become part of that assessment. :contentReference[oaicite:6]{index=6}

Where the underlying product legislation requires involvement of a notified body, the relevant AI requirements can therefore become part of that third-party conformity assessment.

PRODUCT WITHOUT APPLICABLE HIGH-RISK AI Existing Product Conformity Route

The manufacturer follows the conformity-assessment procedure established by the relevant EU product legislation.

PRODUCT WITH HIGH-RISK AI Integrated Product + AI Assessment

The same conformity framework incorporates applicable AI Act requirements relating to the high-risk AI system.

CE Marking Connects the Two Regulatory Worlds

Providers of high-risk AI systems subject to the AI Act must complete the applicable conformity assessment and draw up an EU Declaration of Conformity before market placement.

For product-related high-risk AI, this framework interfaces with the established European CE-marking system.

The result is an increasingly integrated conformity model in which the manufacturer may need to demonstrate both traditional product compliance and AI-system compliance within one overall market-access strategy.

The question is no longer simply whether a machine or device complies with European product-safety requirements. Manufacturers increasingly need to understand whether the intelligence controlling that product also creates regulatory obligations of its own.

Substantial Modification Can Trigger Reassessment

Artificial intelligence systems can evolve rapidly.

Software updates, model changes, retraining, modified datasets or changes to intended purpose can potentially alter system behaviour.

Under the AI Act, a substantial modification can require renewed conformity assessment before the modified system is placed on the market or put into service. :contentReference[oaicite:7]{index=7}

This makes change control particularly important. Manufacturers need processes capable of distinguishing routine software maintenance from changes that materially affect AI performance, risk or intended purpose.

The Supply Chain Becomes More Complex

Many manufacturers will not develop every AI system internally.

Products may incorporate third-party models, externally developed software, AI-enabled components, cloud services or systems supplied by specialist technology companies.

This creates new supply-chain questions.

Manufacturers may need to determine:
  • who legally acts as the AI provider;
  • who controls the intended purpose of the AI system;
  • what technical information must be supplied by the AI developer;
  • what rights the manufacturer has to review or audit the AI technology;
  • how model or software changes are communicated;
  • who manages incidents and corrective action;
  • how cybersecurity responsibilities are allocated; and
  • how conformity evidence is maintained throughout the supply chain.

What Manufacturers Should Be Doing Now

Manufacturers integrating artificial intelligence into products should begin by understanding exactly where AI exists within their product portfolio and what role it performs.

Map AI Functions

Identify products containing AI and document the functions those systems perform.

Determine Product Legislation

Identify the EU harmonisation legislation applicable to each AI-enabled product.

Assess High-Risk Classification

Determine whether the AI performs a safety function and whether the product requires third-party conformity assessment.

Perform an AI Compliance Gap Assessment

Compare existing development, testing, risk and quality controls against applicable AI Act requirements.

Review Technical Documentation

Ensure AI design, intended purpose, data, risk management, validation and oversight arrangements can be demonstrated.

Review Supplier Agreements

Establish access to the technical information and change notifications needed from AI technology suppliers.

Integrate AI Into the QMS

Connect AI governance with design control, supplier management, verification, corrective action and post-market monitoring.

Plan Conformity Assessment

Determine how AI Act requirements integrate with the existing product certification and notified-body pathway.

High-Risk Classification Is Becoming a Critical Decision

Correct classification is one of the most important early decisions under the AI Act.

In May 2026, the European Commission published draft guidelines intended to help providers, deployers and authorities determine whether AI systems fall within the high-risk categories established by Article 6. The guidance specifically addresses both AI incorporated into regulated products and AI systems falling within Annex III use cases. :contentReference[oaicite:8]{index=8}

Manufacturers should therefore avoid relying solely on informal descriptions such as “AI-enabled” or “smart product.”

Classification needs to be based on the AI Act, the intended purpose of the system, applicable product legislation and the actual role of the AI within the product.

From Product Safety to Intelligent Product Assurance

The EU AI Act represents an important evolution in product conformity.

Traditional product regulation has concentrated primarily on physical, mechanical, electrical and functional characteristics.

AI-enabled products introduce another layer: manufacturers may increasingly need to demonstrate that the decision-making technology inside the product is also appropriately governed, tested, documented and monitored.

This creates a new intersection between product certification, software assurance, artificial-intelligence governance, cybersecurity, quality management and market access.

When AI becomes part of the product, AI governance can become part of product conformity. The next generation of CE-marked products may need to demonstrate not only that the product is safe — but that the intelligence inside it is trustworthy as well.

Is the AI Inside Your Product Ready for Conformity Assessment?

Manufacturers should not wait until the final certification stage to determine whether an embedded AI system creates additional regulatory obligations.

An early review can clarify high-risk classification, applicable product legislation, AI documentation requirements, testing needs, supplier responsibilities and the appropriate conformity-assessment route.

The most difficult AI Act question for many manufacturers may not be whether they use artificial intelligence. It will be determining when that intelligence becomes part of the regulated safety architecture of the product.
Regulatory context: Regulation (EU) 2024/1689 establishes harmonised rules for artificial intelligence. High-risk classification can apply where an AI system is used as a safety component of a product, or constitutes such a product itself, under Union harmonisation legislation listed in Annex I and the product is subject to third-party conformity assessment. High-risk providers must complete the applicable conformity-assessment procedure before market placement or putting into service. The European Commission has also published draft guidance on high-risk classification. Manufacturers should verify the legislation, implementation dates, harmonised standards, Commission guidance and conformity-assessment requirements applicable to their specific product before making compliance decisions.
GLOBAL ALLIANCE REGISTER

How Global Alliance Register Can Support You

Global Alliance Register supports manufacturers, suppliers and responsible economic operators with independent technical-assurance services relevant to EU AI Act within the digital and AI context. Based on the article's emphasis on conformity assessment, technical-documentation review and risk assessment, GAR can coordinate competent specialists, laboratories, inspectors, auditors and accredited conformity-assessment resources as appropriate to the actual technical need. Within the context of this article, Global Alliance Register can support you in the following areas:

01

Review test records, inspection evidence, calculations, reports and other technical documentation relating to EU AI Act for completeness, consistency and traceability.

02

Determine the applicable conformity-assessment route for EU AI Act, coordinate the required technical evidence and support independent third-party or Notified Body involvement where the governing framework requires it.

03

Coordinate specialist engineering review of design assumptions, calculations, specifications, risks and other technical features that materially affect EU AI Act.

04

Integrate test results, inspection reports, audit evidence and certification outcomes relating to EU AI Act into a coherent assurance process with clear responsibilities and traceability.

05

Review the applicable regulatory, technical and scope requirements for EU AI Act and define the responsibilities, classifications and assurance pathway relevant to the product or equipment.

Scroll to Top