We have reached a point where artificial intelligence drives cars, regulates the temperature of refrigerators, or decides when a connected toy responds to a child's voice.
The application of AI in commercial products is regulated by the European AI Regulation or AI Act, a regulation that operates on three distinct fronts: the manufacturer of the product, the seller, and the user in their business, each with their own obligations.
When an AI Product Becomes 'High Risk'
The criterion is in Article 6.1 of the Regulation and is twofold. First, AI must be a safety component of a product already regulated by the European CE marking regulation (vehicles, toys, elevators, machinery, medical products). On the other hand, the product must require a conformity assessment by an independent body.
If both conditions are met, the AI system is considered high risk. The automatic emergency braking of a car, the algorithm that governs the stopping of an elevator, or the software that limits the behaviour of a connected toy would fall into this category.
The Digital Omnibus clarified the concept. It states that the purpose of the system must be to prevent or mitigate risks to the health of individuals or property. Those that merely assist the user, optimise performance, or provide convenience do not meet this criterion: the voice assistant of a washing machine does not make the washing machine high risk; the system that stops the machine if it detects a hand near the blade does.
The distinction matters because the volume of connected products continues to grow. The autonomous driving software market, led by Waymo with over 14.4% market share by 2025, is already deploying level 2 to 4 assistance in commercial vehicles, according to the Global Market Insights report updated in April 2026.
What Manufacturers Must Do
The good news is that the requirements for AI (risk management, data quality, technical documentation, human oversight, cybersecurity) are already integrated into the conformity assessment that the product undergoes to display the CE marking.
The obligations for AI integrated into Annex I products will apply from 2 August 2028, and machinery will migrate to a sectoral regime: its AI requirements will be directly incorporated into the Machinery Regulation. Vehicles and aviation have already followed this sectoral path.
There is also a clarified grace period: if a type and model of product was already legally on the market before the application date, subsequent units can continue to be sold without new certification as long as the design does not change significantly.
The crux of the matter, however, does not allow for delay. More than 30% of IoT devices worldwide remain vulnerable to unauthorised access due to weak encryption or outdated firmware, according to data collected in the Fortune Business Insights smart home appliances market analysis.
What Sellers or Users of These Products Should Monitor
The importer and distributor must verify, before marketing, that the product bears the CE marking, the EU declaration of conformity, and the technical documentation.
For its part, the company deploying the product (a fleet of commercial vehicles, autonomous machinery on-site) assumes the obligations of the deployment responsible: using the system according to the supplier's instructions, assigning oversight to trained personnel with authority to intervene, keeping activity records for at least six months, and reporting serious incidents.
A recommended solution is to consult specialists in compliance with the Artificial Intelligence Act. The most advanced compliance platforms like Atico34 AI Governance allow for an inventory of all software and hardware incorporating artificial intelligence in the company, determining their risk level and notifying the responsible party (and even creating a production halt alert) in case of any irregularity.
Other tools like Lakera focus more on cybersecurity. In its case, it offers advanced tools to subject products to 'adversarial attacks' (malicious attempts to corrupt the AI or hardware) and verify their resilience under the strict guidelines of high-risk systems.
The reasonable operational sequence for any of the three links fits into four steps: inventory which products incorporate AI and which meet the dual condition of Article 6.1, require or prepare the conformity documentation, assign an internal compliance officer, and schedule adaptation with a view to August 2028.
The underlying lesson is that Europe has not invented a parallel bureaucracy for AI: it has included it within the CE marking. For companies, compliance is not a new procedure. It is the same as before, with one more chapter.





