Comparison

CRA vs AI Act: which one applies to your product?

Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.

Short answer: a high-risk AI system under the AI Act is not excluded from the CRA. Both apply, and Cybiq’s engine returns “needs review” for this combination, because the two conformity assessments are meant to coordinate rather than duplicate.

What each one regulates

The CRA applies to a product with digital elements made available on the market with a data connection to a device or network, and it names Regulation (EU) 2024/1689 directly when handling the AI Act interplay for high-risk AI systems.

“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”

“Regulation (EU) 2024/1689”

Regulation (EU) 2024/1689 (the Artificial Intelligence Act) classifies certain AI systems as “high-risk” based on their intended purpose, for example AI used in recruitment, credit scoring, or as a safety component of a regulated product, and imposes its own risk-management, data-governance, technical-documentation and human-oversight duties on the providers of those systems, alongside a cybersecurity requirement of its own in Article 15. Full text: Regulation (EU) 2024/1689, OJ L, 12.7.2024 (AI Act).

Do they overlap, and which wins

The CRA names a short, closed list of other Union acts that take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.

“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”

A high-risk AI system is not on that list: the CRA does not carve it out of scope the way it carves out medical devices, aviation-certified equipment or road vehicles. Instead the two regimes are designed to interlock, and Article 12(1) sets that interlock up as a three-part test, without prejudice to the AI Act’s own accuracy and robustness requirements, which the CRA does not touch. A high-risk AI system is deemed to comply with the AI Act’s cybersecurity requirement (its Article 15) only where all three of the following hold:

“shall be deemed to comply with the cybersecurity requirements set out in Article 15 of that Regulation”

“Without prejudice to the requirements relating to accuracy and robustness set out in Article 15 of Regulation (EU) 2024/1689, products with digital elements which fall within the scope of this Regulation and which are classified as high-risk AI systems pursuant to Article 6 of that Regulation shall be deemed to comply with the cybersecurity requirements set out in Article 15 of that Regulation where: (a) those products fulfil the essential cybersecurity requirements set out in Part I of Annex I; (b) the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I; and (c) the achievement of the level of cybersecurity protection required under Article 15 of Regulation (EU) 2024/1689 is demonstrated in the EU declaration of conformity issued under this Regulation.”

Meeting condition (a) alone is not enough: all three conditions must hold, including the declaration of conformity actually demonstrating the required level of protection, not just the underlying Annex I compliance.

Feed this combination into Cybiq’s wizard and it returns needs_review, not a final in-scope or out-of-scope verdict: the Regulation coordinates the two conformity assessments rather than settling every detail itself, and getting that coordination right for a specific product is a job for a specialist, not an automated check. That is a deliberate difference from the seven exclusion regimes above: those return needs_review because a different authority’s regime governs the product instead of the CRA, while the AI Act interplay rule returns needs_review because both regimes govern the product together and the coordination still has to be worked out for your specific case.

What this means in practice

Check your product. Run the free Cybiq check: six questions, a definitive verdict, and every claim anchored word-for-word in the Official Journal. For the terms used here, see the glossary; for more scope questions, see the FAQ; for the dates that matter, see the CRA timeline.

Cybiq checks the CRA only: it does not assess your product’s compliance with the AI Act or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.