Comparison
CRA vs AI Act: which one applies to your product?
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Short answer: a high-risk AI system under the AI Act is not excluded from the CRA. Both apply, and Cybiq’s engine returns “needs review” for this combination, because the two conformity assessments are meant to coordinate rather than duplicate.
What each one regulates
The CRA applies to a product with digital elements made available on the market with a data connection to a device or network, and it names Regulation (EU) 2024/1689 directly when handling the AI Act interplay for high-risk AI systems.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
“Regulation (EU) 2024/1689”
Regulation (EU) 2024/1689 (the Artificial Intelligence Act) classifies certain AI systems as “high-risk” based on their intended purpose, for example AI used in recruitment, credit scoring, or as a safety component of a regulated product, and imposes its own risk-management, data-governance, technical-documentation and human-oversight duties on the providers of those systems, alongside a cybersecurity requirement of its own in Article 15. Full text: Regulation (EU) 2024/1689, OJ L, 12.7.2024 (AI Act).
Do they overlap, and which wins
The CRA names a short, closed list of other Union acts that take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
A high-risk AI system is not on that list: the CRA does not carve it out of scope the way it carves out medical devices, aviation-certified equipment or road vehicles. Instead the two regimes are designed to interlock, and Article 12(1) sets that interlock up as a three-part test, without prejudice to the AI Act’s own accuracy and robustness requirements, which the CRA does not touch. A high-risk AI system is deemed to comply with the AI Act’s cybersecurity requirement (its Article 15) only where all three of the following hold:
- the product fulfils the essential cybersecurity requirements set out in Part I of Annex I;
- the manufacturer’s processes comply with the essential cybersecurity requirements set out in Part II of Annex I; and
- the EU declaration of conformity issued under the CRA demonstrates that the level of cybersecurity protection the AI Act requires has actually been achieved.
“shall be deemed to comply with the cybersecurity requirements set out in Article 15 of that Regulation”
“Without prejudice to the requirements relating to accuracy and robustness set out in Article 15 of Regulation (EU) 2024/1689, products with digital elements which fall within the scope of this Regulation and which are classified as high-risk AI systems pursuant to Article 6 of that Regulation shall be deemed to comply with the cybersecurity requirements set out in Article 15 of that Regulation where: (a) those products fulfil the essential cybersecurity requirements set out in Part I of Annex I; (b) the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I; and (c) the achievement of the level of cybersecurity protection required under Article 15 of Regulation (EU) 2024/1689 is demonstrated in the EU declaration of conformity issued under this Regulation.”
Meeting condition (a) alone is not enough: all three conditions must hold, including the declaration of conformity actually demonstrating the required level of protection, not just the underlying Annex I compliance.
Feed this combination into Cybiq’s wizard and it returns needs_review, not a final in-scope or out-of-scope verdict: the Regulation coordinates the two conformity assessments rather than settling every detail itself, and getting that coordination right for a specific product is a job for a specialist, not an automated check. That is a deliberate difference from the seven exclusion regimes above: those return needs_review because a different authority’s regime governs the product instead of the CRA, while the AI Act interplay rule returns needs_review because both regimes govern the product together and the coordination still has to be worked out for your specific case.
What this means in practice
- If your product with digital elements is also a high-risk AI system, you do not get to skip the CRA; the two apply together.
- Meeting the CRA’s essential cybersecurity requirements is necessary but not sufficient on its own: your EU declaration of conformity also has to demonstrate the level of protection the AI Act’s Article 15 requires before the deemed-compliance route in Article 12(1) applies, so plan one coordinated technical file rather than two separate ones.
- Run the CRA and AI Act classification questions side by side early: they test different things, product cybersecurity against AI risk category, and can land on different conformity routes and different notified bodies.
- Budget for both regimes’ timelines; meeting one deadline does not excuse the other.
- Cybiq’s check returns “needs review” for this combination, not a final verdict; get a specialist to confirm the coordinated assessment for your specific product.
Cybiq checks the CRA only: it does not assess your product’s compliance with the AI Act or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.