Two regulations apply to most AI products
If you build an AI system that is also a product with digital elements placed on the EU market, you face both the AI Act and CRA simultaneously. The regulations have different scopes, different enforcement bodies, and different timelines — but they share 6 core obligations that can be addressed with one technical documentation set.
AI Act timeline — what applies when
| Date | Obligation | |---|---| | 2 February 2025 | Article 5 prohibited practices — in force now | | 2 August 2025 | GPAI model obligations (Art. 51–56) | | 2 August 2026 | High-risk AI systems (Annex III) + notified body obligations | | 2 August 2027 | High-risk AI embedded in regulated products (Annex I) | | 11 December 2027 | CRA full obligations |
If your product uses a General Purpose AI model (GPAI), obligations apply from August 2025.
Is your AI system prohibited?
Article 5 banned 8 AI system categories on 2 February 2025. If your product includes any of:
- Subliminal manipulation techniques
- Exploitation of vulnerable groups
- Real-time remote biometric identification in public spaces (law enforcement)
- Emotion recognition in workplaces or educational institutions
- Biometric categorisation by sensitive characteristics
- Untargeted facial image scraping for recognition databases
- Social scoring by public authorities
…immediate review is required. Deploying a prohibited system carries penalties up to €35M or 7% of global annual turnover.
→ AI Act prohibited practices — full Article 5 breakdown
AI Act × CRA — 6 shared obligations
| Obligation | AI Act | CRA | |---|---|---| | Cybersecurity measures | Art. 15 (high-risk) | Annex I Part I §2(1–13) | | Technical documentation | Art. 11 + Annex IV | Art. 31 + Annex VII | | SBOM (including model provenance) | Art. 11(1)(g) | Annex I Part II §1 | | Incident/anomaly logging | Art. 12 | Annex I Part I §2(7) | | Conformity assessment | Art. 43 | Art. 32–33 | | Post-market monitoring | Art. 72 | Art. 13 |
One technical documentation set can satisfy both AI Act Annex IV and CRA Annex VII requirements — with sections addressing AI-specific obligations (risk management system, accuracy metrics, bias testing) and CRA-specific obligations (vulnerability management, SBOM, CVD policy).
SBOM for AI products: include model provenance — model weights hash, ONNX/format identifier, training framework version, inference runtime version. This satisfies both CRA Annex I Part II §1 and AI Act Art. 11(1)(g) transparency requirements.
→ AI Act × CRA overlap — detailed mapping
Incident notification — two parallel workflows
AI Act high-risk systems require serious incident reporting to market surveillance authorities (Art. 73). CRA Article 14 requires ENISA notification for actively exploited vulnerabilities. These are separate obligations with separate timelines and separate recipients:
| Framework | Trigger | Timeline | Recipient | |---|---|---|---| | AI Act Art. 73 | Serious incident or malfunction | Without undue delay | National market surveillance authority | | CRA Art. 14 | Actively exploited vulnerability | 24h early warning → 72h → 14 days | ENISA |
Your incident classification process must distinguish AI Act incidents (safety/rights impact) from CRA vulnerability disclosures (security exploitation).
GPAI models — obligations from August 2025
If your product integrates a GPAI model (including third-party models via API):
- Maintain technical documentation of the model
- Comply with EU copyright law on training data
- Publish summary of training data (transparency)
- For systemic risk models (>10^25 FLOP): adversarial testing, incident reporting, cybersecurity measures
What NexCyber provides for AI product companies
- AI Act risk classification: prohibited / high-risk / limited / minimal risk
- AI Act × CRA overlap mapping: 6 shared obligations, one documentation set
- SBOM with AI model provenance tracking
- Dual incident notification workflow: AI Act + CRA Article 14
- Evidence layer: technical documentation, conformity assessment records, post-market monitoring logs
Tools
- AI Act Risk Classifier — 5-minute classification
- CRA Scope Checker — CRA applicability for your AI product
- EU Market Access Score — AI Act + CRA readiness
Related answers
- AI Act prohibited practices — Article 5
- AI Act × CRA overlap
- SBOM under CRA (including model provenance)
- CRA Article 14 vulnerability reporting
NexCyber — EU Market Access Compliance Platform