Solutions · By Industry · Ai Ml

AI & ML Products

AI Act risk classification + CRA cybersecurity — one technical documentation set for both.

Pain

Article 5 prohibited practices have been enforceable since February 2025 — this is not a 2027 problem.

What you want

Confidence your AI product isn't quietly falling into a banned category, and one documentation set instead of two.

What you get

AI Act risk classifier + CRA Annex I mapped together, SBOM with model provenance, dual incident notification workflow.

Two regulations apply to most AI products

If you build an AI system that is also a product with digital elements placed on the EU market, you face both the AI Act and CRA simultaneously. The regulations have different scopes, different enforcement bodies, and different timelines — but they share 6 core obligations that can be addressed with one technical documentation set.


AI Act timeline — what applies when

| Date | Obligation | |---|---| | 2 February 2025 | Article 5 prohibited practices — in force now | | 2 August 2025 | GPAI model obligations (Art. 51–56) | | 2 August 2026 | High-risk AI systems (Annex III) + notified body obligations | | 2 August 2027 | High-risk AI embedded in regulated products (Annex I) | | 11 December 2027 | CRA full obligations |

If your product uses a General Purpose AI model (GPAI), obligations apply from August 2025.

AI Act risk classifier


Is your AI system prohibited?

Article 5 banned 8 AI system categories on 2 February 2025. If your product includes any of:

  • Subliminal manipulation techniques
  • Exploitation of vulnerable groups
  • Real-time remote biometric identification in public spaces (law enforcement)
  • Emotion recognition in workplaces or educational institutions
  • Biometric categorisation by sensitive characteristics
  • Untargeted facial image scraping for recognition databases
  • Social scoring by public authorities

…immediate review is required. Deploying a prohibited system carries penalties up to €35M or 7% of global annual turnover.

AI Act prohibited practices — full Article 5 breakdown


AI Act × CRA — 6 shared obligations

| Obligation | AI Act | CRA | |---|---|---| | Cybersecurity measures | Art. 15 (high-risk) | Annex I Part I §2(1–13) | | Technical documentation | Art. 11 + Annex IV | Art. 31 + Annex VII | | SBOM (including model provenance) | Art. 11(1)(g) | Annex I Part II §1 | | Incident/anomaly logging | Art. 12 | Annex I Part I §2(7) | | Conformity assessment | Art. 43 | Art. 32–33 | | Post-market monitoring | Art. 72 | Art. 13 |

One technical documentation set can satisfy both AI Act Annex IV and CRA Annex VII requirements — with sections addressing AI-specific obligations (risk management system, accuracy metrics, bias testing) and CRA-specific obligations (vulnerability management, SBOM, CVD policy).

SBOM for AI products: include model provenance — model weights hash, ONNX/format identifier, training framework version, inference runtime version. This satisfies both CRA Annex I Part II §1 and AI Act Art. 11(1)(g) transparency requirements.

AI Act × CRA overlap — detailed mapping


Incident notification — two parallel workflows

AI Act high-risk systems require serious incident reporting to market surveillance authorities (Art. 73). CRA Article 14 requires ENISA notification for actively exploited vulnerabilities. These are separate obligations with separate timelines and separate recipients:

| Framework | Trigger | Timeline | Recipient | |---|---|---|---| | AI Act Art. 73 | Serious incident or malfunction | Without undue delay | National market surveillance authority | | CRA Art. 14 | Actively exploited vulnerability | 24h early warning → 72h → 14 days | ENISA |

Your incident classification process must distinguish AI Act incidents (safety/rights impact) from CRA vulnerability disclosures (security exploitation).


GPAI models — obligations from August 2025

If your product integrates a GPAI model (including third-party models via API):

  • Maintain technical documentation of the model
  • Comply with EU copyright law on training data
  • Publish summary of training data (transparency)
  • For systemic risk models (>10^25 FLOP): adversarial testing, incident reporting, cybersecurity measures

What NexCyber provides for AI product companies

  • AI Act risk classification: prohibited / high-risk / limited / minimal risk
  • AI Act × CRA overlap mapping: 6 shared obligations, one documentation set
  • SBOM with AI model provenance tracking
  • Dual incident notification workflow: AI Act + CRA Article 14
  • Evidence layer: technical documentation, conformity assessment records, post-market monitoring logs

Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment