[Home](/)/[Resources](/resources)/EU AI Act for Hardware with Embedded AI

EU AI Actembedded AICE markinghardware compliance

# EU AI Act for Hardware with Embedded AI: Compliance Guide

The EU AI Act became law in August 2024 and begins applying in stages through 2027. If your hardware product contains an AI system — machine learning model, computer vision, predictive algorithm, or autonomous control loop — you are subject to its requirements. The obligations depend on the risk classification of the AI system, which is determined by use case, not technology. This guide covers what hardware manufacturers embedding AI need to know.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Feu-ai-act-hardware)

[Check my compliance requirements](/platform/new)

Classification

## How the EU AI Act classifies embedded AI systems

The EU AI Act uses a four-tier risk framework. Unacceptable risk systems are prohibited — social scoring, real-time public biometric surveillance, manipulation systems. High-risk AI systems are permitted but subject to substantial obligations. Annex III lists eight sectors: biometric identification, critical infrastructure, education and employment, essential public services, law enforcement, migration, and justice administration. AI embedded in regulated products — medical devices, machinery, vehicles, toys — is automatically high-risk when the host product is high-risk.

General purpose AI (GPAI) models have separate obligations under Article 53. Limited risk systems face only transparency obligations — disclosure that the user is interacting with AI. Minimal risk systems have no specific AI Act obligations.

For hardware manufacturers, the key classification question is: what does your AI system do, in what context, and for what type of end user? A computer vision system in a consumer camera is different from the same technology used in an access control system. Context determines classification.

High-risk obligations

## What high-risk AI system obligations mean for hardware manufacturers

High-risk AI systems embedded in hardware must meet obligations under Articles 9–15 of the AI Act before being placed on the EU market:

Risk management system: A documented process covering identification and analysis of known and foreseeable risks across the system lifecycle, including post-market monitoring. This is a living document, not a one-time assessment.

Data governance: Training, validation, and testing datasets must be representative and documented. For manufacturers using third-party AI components, supply chain data documentation is required.

Technical documentation: Comprehensive records covering design, development, training approach, performance metrics, limitations, and human oversight mechanisms. Maintained alongside but separate from CE technical files.

Automatic logging: High-risk AI systems must log events that are relevant to post-market monitoring and incident investigation. Logging must be built into the system architecture.

Human oversight: The hardware design must enable effective human oversight — including the ability to intervene, halt, or override the AI system during operation. This affects both software architecture and physical interface design.

Conformity assessment: Self-assessment is permitted for most high-risk categories. Notified body involvement is required for Annex III Category III systems (biometric identification for law enforcement).

Timeline

## AI Act application dates hardware manufacturers must plan around

February 2025: Prohibitions on unacceptable risk AI systems apply. This deadline has passed. August 2025: GPAI model provider obligations apply. If your hardware runs a foundation model, verify that your model provider is compliant with Article 53 transparency and documentation requirements.

August 2026: High-risk AI obligations apply to AI systems embedded in products covered by existing EU product safety legislation — medical devices, machinery, vehicles, toys. This is the most significant deadline for most hardware companies with AI in regulated products. Full conformity assessment, technical documentation, logging, and human oversight requirements must be in place.

August 2027: Full application including remaining Annex III high-risk systems and AI in other regulated sectors. Practical planning implication: if your product falls into the 2026 category, you have a fixed runway. Design decisions affecting logging, human oversight interfaces, and AI system documentation should be made before your next hardware revision.

The AI Act interacts with CE marking. For CE-marked products containing high-risk AI, the AI Act compliance is incorporated into the CE conformity assessment and the Declaration of Conformity must reference Regulation 2024/1689 alongside the applicable EU harmonisation legislation.

## Learn this properly, not just for one product

In-depth courses and books that teach the process — not a one-off answer you'll need to look up again next time.

[Start the course — $199](/courses/11-eu-ai-act-for-hardware-products)See your free roadmap

[Prefer to read? Get the book — $24.99](/books/11-eu-ai-act-for-hardware-products)

## Frequently asked questions

### Does the EU AI Act apply to my product if it uses a simple rule-based algorithm?

Deterministic rule-based systems that do not infer outputs are generally outside the AI Act definition. Products using machine learning, neural networks, or trained classification systems are clearly in scope. The line between rule-based and inference-based is contested — if your system learns from data or updates its behavior based on experience, it is almost certainly an AI system under the Act.

### If my AI model is from a third-party provider, who is responsible for compliance?

Both the model provider (developer) and the deployer (hardware manufacturer integrating the model) have obligations. Providers must supply technical documentation and support post-market monitoring. Deployers implement human oversight, logging, and ensure the system is used as documented. Hardware manufacturers typically act as deployers and take on the responsibility for the complete system.

### What penalties apply for EU AI Act non-compliance?

Penalties are tiered: placing a prohibited AI system on the market — up to EUR 35 million or 7% of global annual turnover. Non-compliance with high-risk obligations — up to EUR 15 million or 3% of global annual turnover. Providing incorrect information to authorities — up to EUR 7.5 million or 1.5% of global annual turnover.

### Does the EU AI Act require a separate mark?

No separate mark is created. AI Act compliance for CE-marked products is incorporated into the existing CE marking framework. The Declaration of Conformity must explicitly reference Regulation 2024/1689 alongside the product safety directives. No additional physical mark appears on the product.

🇪🇺 CE Marking roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇪🇺 CE Marking compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $199](/courses/11-eu-ai-act-for-hardware-products)[Prefer to read? Get the book — $24.99](/books/11-eu-ai-act-for-hardware-products)

Related guides

*   [EU New Product Liability DirectiveNew EU PLD (2024/2853) expands liability to software, firmware updates, and AI.](/guides/eu-new-product-liability-directive)
*   [EU Market Surveillance RegulationEU Regulation 2019/1020 strengthens market surveillance across all CE-marked product categories by expanding economic operator …](/guides/eu-market-surveillance-regulation)
*   [EU Economic Operators ExplainedThe EU product safety framework assigns distinct compliance obligations to each economic operator in the supply chain.](/guides/eu-economic-operators-explained)
*   [CE Marking for Unintentional RadiatorsUnintentional radiators — digital devices that generate RF as a byproduct of operation — must comply with the EU EMC Directive.](/guides/ce-marking-unintentional-radiators)
*   [UAE National AI Strategy and Product ComplianceHow the UAE National Artificial Intelligence Strategy 2031 and its emerging governance framework affect AI-enabled hardware: TDRA guidance, AI ethics principles, sector-specific requirements, and the direction of UAE AI product regulation.](/guides/uae-national-ai-strategy-products)

Educational resource only. Verify current requirements with qualified compliance professionals before making regulatory decisions.