§ AI Act · CRA COMPARISON

AI Act vs Cyber Resilience Act

If a vendor's connected product embeds AI, both regimes apply to it. The CRA's Annex I cybersecurity requirements feed AI Act Article 15 — useful to know when you're reviewing a vendor's conformity file rather than tracking every clock yourself.

Summary

For a compliance director tracking vendor conformity across regulations: the Cyber Resilience Act (Regulation (EU) 2024/2847) was published in November 2024 and the substantive obligations apply from 11 December 2027. When the AI Act and CRA both apply — most commonly when AI is embedded in a connected product — the regimes are cumulative, with AI Act Article 15 cybersecurity requirements layered on top of the CRA's Annex I essential cybersecurity requirements.

Where the same product is in scope of both, Article 43(3) of the AI Act directs the integrated conformity assessment under the CRA procedure. The single CE marking covers both regimes, and the Annex IV AI Act technical file is integrated with the CRA technical documentation.

The most operationally significant CRA addition for AI manufacturers is the vulnerability-handling regime: coordinated disclosure obligations, mandatory security updates throughout the support period, and 24-hour reporting of actively exploited vulnerabilities to ENISA via the single reporting platform under Article 14.

Who this applies to
Manufacturers of products with digital elements, AI vendors selling software components, importers and distributors, ENISA, market surveillance authorities for digital products — and compliance directors at payment institutions, EMIs, fintechs, and insurers who need to verify a vendor's conformity documentation before procuring an AI-enabled connected device.
Compliance deadline
AI Act high-risk: 2 August 2026 as written; Annex III provisionally 2 December 2027 (Digital Omnibus agreement of 7 May 2026, pending formal adoption). CRA: vulnerability reporting from 11 September 2026; substantive obligations from 11 December 2027.
§ Key articles

What the law says

AI Act Article 6(1)
Annex I product path — AI as safety component of a regulated product is high-risk.
AI Act Article 15
Accuracy, robustness, and cybersecurity for high-risk AI.
CRA Article 13
Essential cybersecurity requirements for products with digital elements.
CRA Annex I §1
Security properties — confidentiality, integrity, availability, secure development, vulnerability handling.
CRA Annex I §2
Vulnerability-handling requirements — coordinated disclosure, security updates.
CRA Article 14
Reporting obligations — actively exploited vulnerabilities and severe incidents.
CRA Article 32
Conformity assessment procedure — Annex VIII for important and critical products.
§ Detail

In depth

Payment institutions, e-money institutions, and insurers rarely manufacture connected products themselves, but they buy and deploy them — biometric authentication terminals, connected point-of-sale hardware, IoT sensors in claims handling. When one of those devices embeds AI, the vendor's conformity file has to satisfy both the AI Act and the Cyber Resilience Act (CRA) at once. This page sets out how the two regimes combine, verified against the regulation text rather than summarised from memory.

Side-by-side

DimensionAI ActCRA
ScopeAI systems on the EU market.Products with digital elements (hardware + software) on the EU market — excluding cloud SaaS.
TriggerArticle 6 (Annex I/III) or GPAI.Product has digital elements (CRA Art 3) and is in scope (CRA Art 2 with carve-outs).
Substantive controlsArticles 9–15.CRA Art 13 + Annex I (security properties, vulnerability handling).
ConformityAnnex VI internal default; Annex VII for biometric ID; integrated under Art 43(3) for Annex I products.Default conformity; Annex VIII for important products (Class I/II in CRA Annex III); third-party for critical products (CRA Annex IV).
Vulnerability reportingArt 73 serious-incident reporting (15 days; 2 days for fundamental-rights breach).Art 14 — 24h actively exploited vulnerability notification to ENISA via the single reporting platform; severe-incident notification 72h.
Maximum fineEUR 35M / 7%.EUR 15M / 2.5% (essential requirements); EUR 10M / 2% (other obligations).
Application2 August 2026 as written for high-risk; provisionally 2 December 2027 for Annex III (Digital Omnibus, pending formal adoption).11 December 2027 (substantive obligations); 11 September 2026 (vulnerability reporting).

The combined product case

An AI-enabled connected product (a smart camera with object recognition, an industrial sensor with embedded ML, a connected medical device with on-device AI) is in scope of both regulations. If you're evaluating a vendor's documentation for one of these, here is how the two regimes fit together:

Where the regimes diverge

The points below are where a vendor's conformity file can look complete under one regime and still be incomplete under the other:

Practical compliance

For a manufacturer, this is a build checklist. For a compliance director reviewing a vendor, it's a request list — ask the vendor to confirm each of these before signing off procurement.

§ Action items

Practical steps

01
Confirm whether each product is in CRA scope; SaaS-only AI is generally outside CRA but inside AI Act.
02
Build a single integrated technical file across CRA Annex VII and AI Act Annex IV.
03
Set up a 24-hour vulnerability-handling pipeline keyed to CRA Article 14 (single reporting platform via ENISA) with AI Act Article 73 layered on.
04
Publish an SBOM and coordinated-disclosure policy aligned with CRA Annex I §2.
05
Plan around the staggered CRA dates: vulnerability reporting from 11 September 2026; full substantive obligations from 11 December 2027.
§ What Fontvera found

Documents in our corpus

eiopa EU Fetched 2026-04
Opinion on Artificial Intelligence governance and risk management
eurlex EU Fetched 2026-04
EUR-Lex: 32025R0454 (2025-03-07)
ai_office EU Fetched 2026-07
§ Cross-references

Related Fontvera intelligence

Need a cross-border briefing on this?
Search Fontvera ↵ Run the AI Act diagnostic
AI Act Article 50 transparency
5 days
until 2026-08-02, when Article 50 transparency obligations apply (unchanged). Annex III high-risk obligations move provisionally to 2 December 2027 under the Digital Omnibus agreement of 7 May 2026, pending formal adoption.
Preparing for 2 August 2026? Read the EU AI Act August 2026 deadline requirements checklist.