What EU AI Act and Cyber Resilience Act - Dual Compliance for Connected AI Products requires
Providers of AI systems embedded in connected products face dual compliance obligations under Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2024/2847 (EU Cyber Resilience Act, CRA); the CRA applies to products with digital elements (PDEs) that are directly or indirectly connected to a network - including IoT devices, industrial control systems, smart home products, medical devices (software as a medical device), and connected vehicles; where a connected product contains an AI system that is: (a) a safety component of a product covered by EU AI Act Annex II (e.g., Machinery Regulation, Medical Devices Regulation) - the AI system is automatically high-risk under EU AI Act Article 6(1); (b) within a CRA-covered product - the product must also comply with CRA essential cybersecurity requirements; the key dual compliance obligations are: (1) conformity assessment - both the EU AI Act conformity assessment (for high-risk AI systems) and the CRA conformity assessment (for products with digital elements) must be completed before CE marking; for some products, a single integrated conformity assessment covers both instruments; (2) vulnerability management - CRA Article 13 requires providers to address known vulnerabilities throughout the product lifecycle; EU AI Act Article 15 requires robustness against adversarial inputs and cybersecurity for high-risk AI systems; (3) incident reporting - CRA Article 14 requires notification of actively exploited vulnerabilities and security incidents to ENISA; EU AI Act Article 73 requires notification of serious incidents affecting high-risk AI systems to market surveillance authorities; (4) documentation - CRA requires technical documentation under CRA Annex V; EU AI Act Article 11 requires separate technical documentation - both must be maintained; the CRA applies from December 11, 2027 (with an 18-month transition for essential requirements); the EU AI Act high-risk provisions apply from August 2, 2026.
Pillar: AI Governance & Law · Authority: European Parliament and Council of the EU · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
SHA-256 integrity: 1e3f39ae96b52280767a09757c493298264dbc12d41657f8cf1841e2097a6673
Primary Citations — 5 traced to source
- Regulation (EU) 2024/1689 - EU AI Act: Article 6 - High-Risk Classification for Safety Components of Annex II Products
- Regulation (EU) 2024/2847 - Cyber Resilience Act: Article 13 - Vulnerability Management Obligations
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-ai-act-cyber-resilience-act-intersection.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-ai-act-cyber-resilience-act-intersection.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-ai-act-cyber-resilience-act-intersection
- Back to registry: Browse all 10,099 compliance nodes