CE marking AI-enabled hardware — CRA + AI Act overlap
How CE marking works for hardware embedding AI under the AI Act (Regulation (EU) 2024/1689) and the CRA — Article 6 high-risk routing, Article 48 CE, Annex I integration.
By Vladimír Vician
A smart-home camera with on-device person detection, an industrial collaborative robot whose vision stack ranks pickup priority, a medical wearable that flags arrhythmia patterns, an EV charger that schedules grid drawdown by reinforcement learning — every one of these is hardware with an embedded AI system. Each may now need to clear three regulatory layers at once: the sectoral product directive (RED, Machinery, MDR, LVD), the Cyber Resilience Act, and — if the AI is "high-risk" — the AI Act.
The good news: the EU explicitly designed the AI Act to plug into the existing New Legislative Framework. The bad news: figuring out which Annex applies, which conformity assessment module to run, and which dates bind you requires reading three regulations in parallel. This guide walks through the routing.
The two new regimes in one sentence each
The AI Act (Regulation (EU) 2024/1689) regulates AI systems by risk tier: prohibited, high-risk (most product-safety obligations), limited-risk (transparency), and minimal-risk. CE marking obligations attach only to high-risk systems.
The Cyber Resilience Act (Regulation (EU) 2024/2847) regulates cybersecurity of all "products with digital elements" placed on the EU market. Every in-scope hardware product with software gets a CE mark for cybersecurity essentially requirements (Annex I), with extra requirements and assessment routing for "important" (Annex III) and "critical" (Annex IV) categories. See cra-annex-1-explained and cra-december-2027-readiness.
The sectoral directive (RED, MDR, Machinery Regulation, LVD, etc.) still applies on top — none of these acts replace it.
Is your AI system "high-risk" under the AI Act?
This is the gating question. The classification rules sit in Article 6 of the AI Act, with two independent routes.
Route 1 — Article 6(1): AI as a safety component of a regulated product
Per Article 6(1), an AI system is high-risk when both conditions hold:
- The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; and
- That product is required to undergo a third-party conformity assessment under the same Annex I act.
Annex I Section A lists 12 New Legislative Framework acts — Machinery (Directive 2006/42/EC and the successor Regulation (EU) 2023/1230), Toy Safety, Recreational Watercraft, Lifts, ATEX, Radio Equipment (Directive 2014/53/EU), Pressure Equipment, Cableways, PPE, Gas Appliances, Medical Devices (Regulation (EU) 2017/745), and IVDR. Section B lists sectoral acts like the Motor Vehicles Regulation, Civil Aviation, Marine Equipment, etc.
The "third-party conformity assessment required" qualifier is the trap: a simple Module A self-assessment under RED does not trigger Route 1 even if the radio is in Annex I. But a Class IIa medical device, a Category 2 PPE product, or a machine under Machinery Regulation Annex I that requires notified-body involvement → high-risk AI.
Route 2 — Article 6(2): Annex III use cases
Article 6(2) makes AI systems high-risk if they fall under one of the use cases listed in Annex III, independent of whether they sit inside a CE-marked product. Annex III categories include biometric identification, critical infrastructure management, education evaluation, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice.
Annex III matters for hardware mostly when the device performs biometric identification (smart locks with face recognition), runs in critical infrastructure (industrial controllers in energy grids), or filters access to essential services.
Article 6(3) exception
Article 6(3) carves out Annex III systems that "do not pose a significant risk of harm" — for example, where the system performs a narrow procedural task or improves a previously completed human activity. Profiling of natural persons is excluded from the carve-out. If a provider believes its Annex III system is not high-risk, Article 6(4) requires documenting the assessment before market placement.
Article 16 — the obligations that flow once high-risk
If your AI system is high-risk, Article 16 lists the provider's obligations verbatim:
(a) ensure that their high-risk AI systems are compliant with the requirements set out in Section 2; (b) indicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, as applicable, their name, registered trade name or registered trade mark, the address at which they can be contacted; (c) have a quality management system in place which complies with Article 17; (d) keep the documentation referred to in Article 18; (e) when under their control, keep the logs automatically generated by their high-risk AI systems as referred to in Article 19; (f) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43 [...] (g) draw up an EU declaration of conformity in accordance with Article 47; (h) affix the CE marking to the high-risk AI system [...] in accordance with Article 48;
Section 2 (Articles 8–15) sets the substantive essentials: risk management system, data governance, technical documentation per Annex IV, record-keeping, transparency to deployers, human oversight, accuracy, robustness, and cybersecurity.
The CE marking itself — Article 48
Article 48 of the AI Act defines the CE marking mechanics:
- The CE marking shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.
- For high-risk AI systems provided digitally, a digital CE marking shall be used [...]
- The CE marking shall be affixed visibly, legibly and indelibly for high-risk AI systems. Where that is not possible or not warranted on account of the nature of the high-risk AI system, it shall be affixed to the packaging or to the accompanying documentation [...]
- Where applicable, the CE marking shall be followed by the identification number of the notified body responsible for the conformity assessment procedures set out in Article 43.
- Where high-risk AI systems are subject to other Union law which also provides for the affixing of the CE marking, the CE marking shall indicate that the high-risk AI system also fulfil the requirements of that other law.
Paragraph 5 is the integration anchor: one CE mark, multiple regulations. The Declaration of Conformity must list each act. See declaration-of-conformity-101 for DoC structure and sample-doc-walkthrough for a worked example.
One email at launch · cancel any time
The CRA layer — cybersecurity on top of everything
The CRA applies to every product with digital elements, regardless of AI status. Where the AI Act asks "is the AI high-risk?", the CRA asks "does the product include software or data communication?" — and almost every connected device says yes.
CRA essential requirements (Annex I Part I) cover secure-by-design, attack-surface minimisation, identity and access management, confidentiality and integrity of stored/transmitted data, and vulnerability handling. Annex I Part II covers the vulnerability-handling process — including SBOM maintenance and timely security updates.
For an AI camera in the smart-home use case:
| Layer | Acts | What it requires |
|---|---|---|
| Sectoral | RED 2014/53/EU | Radio spectrum, EMC, electrical safety, EN 18031 cybersecurity essentials |
| Horizontal cyber | CRA 2024/2847 Annex I | Secure-by-design, SBOM, vuln handling, 5-year support period |
| AI (if high-risk) | AI Act 2024/1689 | Data governance, transparency, human oversight, robustness |
| Single output | One CE mark | One DoC listing all four |
Note that RED and CRA overlap on cybersecurity — the CRA largely supersedes the RED cybersecurity delegated act and EN 18031 once CRA applies. See red-cra-overlap-connected-radio for the transition.
Conformity assessment routing — one procedure or two?
Article 43 of the AI Act sets two procedures for high-risk systems: internal control (Module A, Annex VI) and notified-body assessment of quality management plus technical documentation (Annex VII). Article 43(3) makes the AI Act conformity assessment integrate with the sectoral procedure under Annex I Section A:
- For Machinery, Toys, Radio Equipment, etc., the notified body acting under the Annex I act also assesses AI Act conformity — single procedure, single notified body.
- For Medical Devices (MDR/IVDR), the AI Act assessment is performed by the medical-device notified body under the relevant MDR procedure.
For Annex III systems (Route 2 high-risk that aren't tied to an Annex I product), the AI Act conformity assessment is generally Annex VI (internal control), except for certain biometric systems where Annex VII (with notified body) applies — see Article 43(1) and (2).
The CRA layers separately. CRA Article 32 defines conformity-assessment modules for cybersecurity — internal control (Module A) for default products, plus EU-type examination (Module B+C) or full QMS (Module H) for Annex III important products and Annex IV critical products. See conformity-assessment-modules-a-to-h and cra-annex-3-important-products.
When does each obligation bite?
The phasing matters because some products will need to comply with CRA before the AI Act high-risk obligations kick in.
| Date | Regulation | What applies |
|---|---|---|
| 1 August 2024 | AI Act | Enters into force |
| 2 February 2025 | AI Act | Prohibitions (Article 5) apply |
| 11 December 2024 | CRA | Enters into force |
| 11 September 2026 | CRA | Article 14 incident reporting obligations apply |
| 2 August 2025 | AI Act | GPAI obligations, governance provisions apply |
| 2 August 2026 | AI Act | General application — Annex III high-risk obligations |
| 2 August 2027 | AI Act | Article 6(1) high-risk (Annex I products) obligations apply |
| 11 December 2027 | CRA | Main obligations apply to all PDEs |
Dates per Article 113 of the AI Act and Article 71 of the CRA. See cra-timeline-and-reporting-obligations for the CRA staging and cra-september-2026-reporting-checklist for the September 2026 milestone.
The combined effect: a robotics manufacturer shipping a new Annex IV Machinery product with vision AI in Q1 2027 must clear Machinery + AI Act Article 6(1) high-risk (deadline 2 August 2027 for the AI obligations) + CRA full obligations (11 December 2027). Plan technical documentation and notified-body engagement to cover all three concurrently.
Common mistakes
- Assuming any LLM inside means high-risk AI. The classification is risk-based, not technology-based. A smart speaker with on-device wake-word detection and a cloud LLM is not high-risk unless it falls under Annex I third-party-assessed products or Annex III use cases.
- Treating CRA and AI Act cybersecurity as duplicates. CRA covers product-level cyber essentials (Annex I — both Part I requirements and Part II vulnerability handling). AI Act Article 15 covers AI-specific robustness against data-poisoning, adversarial examples, and model-confidentiality attacks. They stack.
- Forgetting Annex I Section B. Aviation, automotive, and rail acts are listed in Annex I Section B. Article 2(2) of the AI Act restricts certain obligations for Section B, but the regulation is not a free pass — sectoral safety regulators retain primary authority.
- Missing the Article 6(4) self-assessment documentation. Providers who decide their Annex III system is not high-risk under Article 6(3) must document the reasoning before placing it on the market. Skipping this exposes the manufacturer to enforcement and the deployer to redress claims.
- One DoC per regulation. The CE marking system uses one DoC listing every applicable act — Article 48(5) AI Act, Article 28 CRA, and parallel provisions in RED/Machinery/MDR. Drafting separate DoCs for each regulation is wrong and creates an internal-consistency liability.
How Cenitia helps
Cenitia generates a single Technical File and Declaration of Conformity that handle the AI Act + CRA + sectoral stack as one coordinated artefact. The Express tier classifies your product against Article 6 of the AI Act (both routes), Annex I/III/IV of the CRA, and the relevant sectoral directive, then produces the EU DoC referencing every applicable act per Article 48(5) AI Act. Annex IV (AI Act technical documentation), Annex VII (CRA technical documentation), and the sectoral technical file chapters are produced from a single product data input.
The platform watches Regulation (EU) 2024/1689, Regulation (EU) 2024/2847, and the relevant sectoral acts continuously — when the Commission publishes Article 6(5) implementation guidelines or amends Annex I/III, your file is flagged for review.
One email at launch · cancel any time
Frequently asked questions
Does every AI-enabled hardware product need CE marking under the AI Act?
No. The AI Act only mandates CE marking for systems that meet its high-risk definition. Per Article 6, that means either (a) the AI system is a safety component of, or itself is, a product covered by Annex I Union harmonisation legislation requiring third-party conformity assessment, or (b) the system falls within one of the Annex III use cases. A consumer smart speaker without safety-critical AI functions does not become high-risk just by containing an LLM.
If my product already has CE under the Radio Equipment Directive and the CRA, what does the AI Act add?
If the AI inside is high-risk under Article 6(1), the AI Act adds requirements on data governance, transparency, human oversight, accuracy, robustness, technical documentation per Annex IV, and a single CE mark indicating conformity with all applicable Union acts (Article 48(5)). The conformity assessment may be combined with the underlying sectoral procedure — Recital 64 and Article 43(3) describe the integration with Annex I Section A acts.
When does the AI Act actually apply to hardware?
Per Article 113, the regulation entered into force 1 August 2024 and applies generally from 2 August 2026. However, obligations on high-risk AI systems that are safety components of Annex I products (Article 6(1) route) apply from 2 August 2027. GPAI model obligations apply from 2 August 2025 and prohibitions from 2 February 2025. Source: Regulation (EU) 2024/1689 Article 113.
Does the CRA cover AI-specific risks like model poisoning?
Indirectly. The CRA (Regulation (EU) 2024/2847) imposes essential cybersecurity requirements on all products with digital elements via Annex I, including secure-by-design, vulnerability handling, and SBOM obligations. AI-specific threats — data-poisoning, adversarial inputs, model-extraction — are addressed by Article 15 of the AI Act for high-risk systems. The two layers stack: CRA for the binary and supply chain, AI Act Article 15 for AI-specific robustness.
Can one CE mark cover the AI Act, CRA, RED, EMC, LVD, and Machinery all at once?
Yes — that is the design. Article 48(5) of the AI Act states the CE marking shall indicate that a high-risk AI system also fulfils the requirements of other Union law providing for CE marking. The Declaration of Conformity must list every applicable act. Practically, manufacturers prepare one technical file with sectoral chapters and one DoC referencing all directives and regulations applied.
What happens to an AI hardware product placed on the market before the AI Act applies?
Article 111 of the AI Act contains transitional provisions for high-risk systems already on the market. Significant design changes after the application date generally trigger the new requirements, but legacy stock is treated separately. For the CRA, Article 69 sets staged transitional provisions — most obligations apply from 11 December 2027. Manufacturers shipping new units after these dates must comply regardless of when the product line launched.
Related from the Library
- CE marking 101 — the process end to end — foundation for any CE topic
- CRA Annex I explained — the cybersecurity essentials that stack underneath the AI Act
- CRA December 2027 readiness — the CRA main application deadline
- RED + CRA overlap for connected radio — sectoral + horizontal cyber stacking
- Conformity assessment modules A to H — module selection for stacked procedures
Further reading
- Regulation (EU) 2024/1689 (AI Act) — full text — EUR-Lex
- Article 6 — Classification rules for high-risk AI systems — AI Act explorer
- Article 48 — CE marking — AI Act explorer
- Article 16 — Obligations of providers of high-risk AI systems — AI Act explorer
- Annex I — Union harmonisation legislation (NLF + Section B) — AI Act explorer
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — full text — EUR-Lex
- Commission policy hub — Regulatory framework on AI — DG CNECT
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
Does every AI-enabled hardware product need CE marking under the AI Act?
No. The AI Act only mandates CE marking for systems that meet its high-risk definition. Per Article 6, that means either (a) the AI system is a safety component of, or itself is, a product covered by Annex I Union harmonisation legislation requiring third-party conformity assessment, or (b) the system falls within one of the Annex III use cases. A consumer smart speaker without safety-critical AI functions does not become high-risk just by containing an LLM.
If my product already has CE under the Radio Equipment Directive and the CRA, what does the AI Act add?
If the AI inside is high-risk under Article 6(1), the AI Act adds requirements on data governance, transparency, human oversight, accuracy, robustness, technical documentation per Annex IV, and a single CE mark indicating conformity with all applicable Union acts (Article 48(5)). The conformity assessment may be combined with the underlying sectoral procedure — Recital 64 and Article 43(3) describe the integration with Annex I Section A acts.
When does the AI Act actually apply to hardware?
Per Article 113, the regulation entered into force 1 August 2024 and applies generally from 2 August 2026. However, obligations on high-risk AI systems that are safety components of Annex I products (Article 6(1) route) apply from 2 August 2027. GPAI model obligations apply from 2 August 2025 and prohibitions from 2 February 2025. Source: Regulation (EU) 2024/1689 Article 113.
Does the CRA cover AI-specific risks like model poisoning?
Indirectly. The CRA (Regulation (EU) 2024/2847) imposes essential cybersecurity requirements on all products with digital elements via Annex I, including secure-by-design, vulnerability handling, and SBOM obligations. AI-specific threats — data-poisoning, adversarial inputs, model-extraction — are addressed by Article 15 of the AI Act for high-risk systems. The two layers stack: CRA for the binary and supply chain, AI Act Article 15 for AI-specific robustness.
Can one CE mark cover the AI Act, CRA, RED, EMC, LVD, and Machinery all at once?
Yes — that is the design. Article 48(5) of the AI Act states the CE marking shall indicate that a high-risk AI system also fulfils the requirements of other Union law providing for CE marking. The Declaration of Conformity must list every applicable act. Practically, manufacturers prepare one technical file with sectoral chapters and one DoC referencing all directives and regulations applied.
What happens to an AI hardware product placed on the market before the AI Act applies?
Article 111 of the AI Act contains transitional provisions for high-risk systems already on the market. Significant design changes after the application date generally trigger the new requirements, but legacy stock is treated separately. For the CRA, Article 69 sets staged transitional provisions — most obligations apply from 11 December 2027. Manufacturers shipping new units after these dates must comply regardless of when the product line launched.
Continue reading
Related guides
guide
CE marking for industrial sensors and gateways
EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.
9 min read
guide
CE marking medical wearables — MDR + CRA overlap
How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.
9 min read
guide
CE marking for IoT consumer products — end-to-end
End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.
9 min read
guide
France — CE marking and additional national obligations
France-specific add-ons to CE marking: DGCCRF market surveillance, Loi Toubon French-language documentation, Triman waste-sorting logo, AGEC law and REP eco-organisme registration.
6 min read
Put this into practice
Free tools & references
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
- Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.