CRA Article 12 creates a specific bridge between the Cyber Resilience Act and the EU AI Act. For high-risk AI systems that are also products with digital elements, CRA cybersecurity compliance can satisfy the AI Act Article 15 cybersecurity requirement where the statutory conditions are met, while the AI Act's other requirements continue to apply independently.
The CRA and AI Act Can Apply to the Same Product
The Cyber Resilience Act and the EU AI Act regulate different aspects of digital products, so a product can fall within both frameworks. CRA analysis starts with whether there is a product with digital elements within the Regulation's scope and which economic operator is responsible for placing or making it available on the Union market. The AI Act uses its own concepts and classifications, including rules for identifying high-risk AI systems. A software or hardware product containing an AI system can therefore require both a CRA product-security analysis and an AI Act analysis. Applying one regulation does not automatically remove the other. The useful starting point is to map the product once, then record separately which CRA and AI Act provisions apply to the product and its AI functionality.
CRA Article 12 Creates a Specific Cybersecurity Bridge
Article 12 of the CRA directly addresses products with digital elements that also qualify as high-risk AI systems under Article 6 of Regulation (EU) 2024/1689. Where those products fulfil the CRA essential cybersecurity requirements in Annex I Part I, the manufacturer's processes comply with the vulnerability-handling requirements in Annex I Part II, and the required level of cybersecurity protection is demonstrated in the CRA EU declaration of conformity, the product is deemed to comply with the cybersecurity requirements in Article 15 of the AI Act to the extent covered by that declaration. This bridge is designed to avoid unnecessary duplication. It does not convert CRA compliance into compliance with every AI Act obligation.
AI Act Article 15 Covers More Than a Generic Security Statement
Article 15 of the AI Act requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity and to perform consistently in those respects throughout their lifecycle. The CRA coordination concerns the cybersecurity part of that requirement. Accuracy and robustness requirements under the AI Act remain relevant independently. Manufacturers should therefore avoid describing Article 12 as a complete substitution of CRA compliance for AI Act compliance. A combined product file should identify which CRA cybersecurity controls support Article 15 cybersecurity and which AI Act requirements require their own evidence, testing, governance or technical measures.
AI-Specific Cybersecurity Risks Still Need to Be Considered
The CRA expressly recognises that cybersecurity risk assessment for a product that is also a high-risk AI system needs to account for risks relevant to the cyber resilience of the AI system. This can include attempts by unauthorised parties to alter the system's use, behaviour or performance and AI-specific vulnerabilities such as data poisoning or adversarial attacks. Product teams should therefore avoid using a conventional software threat model that ignores the AI components of the product. The CRA risk assessment can remain the central product-security record, but it should include the attack paths, data dependencies, model interfaces and other AI-specific characteristics that materially affect cybersecurity risk.
Conformity Assessment Is Coordinated Between the Two Regulations
CRA Article 12 also coordinates conformity assessment. For products covered by Article 12, the relevant conformity assessment procedure in Article 43 of the AI Act generally applies. There is an important exception for certain products that are also important or critical products with digital elements under the CRA. Where the AI Act route would rely on internal control, the CRA can require the stronger CRA conformity procedures for the essential cybersecurity requirements. This preserves the assurance level attached to important and critical CRA product categories. Manufacturers should therefore perform both the AI Act classification and the CRA product classification before deciding which assessment route will apply.
A Single Technical Documentation Set Can Reduce Duplication
Article 31 of the CRA supports coordinated documentation for Article 12 products that are also subject to other Union legal acts requiring technical documentation. A single set of technical documentation can contain the information required by the CRA and the information required by those other Union laws. For an AI product, this can reduce duplicated architecture descriptions, risk evidence and conformity records. It does not reduce the substance of either legal framework. The combined file still needs to contain the information each applicable regulation requires and should make it possible to identify which evidence supports which requirement.
A Practical CRA and AI Act Mapping Approach
Teams developing AI-enabled products should maintain a combined regulatory map rather than two disconnected compliance projects. Define the marketed product, identify the AI functionality, determine whether the product is within CRA scope, assess whether the AI system is high-risk under the AI Act, and classify the product under the CRA where relevant. Build one cybersecurity risk model that includes ordinary software and hardware threats as well as AI-specific attack paths. Map the resulting controls to CRA Annex I and the relevant AI Act cybersecurity requirement, then identify the conformity route and documentation structure. This makes the Article 12 coordination visible and prevents the organisation from either duplicating the same evidence or incorrectly assuming that one regulation replaces the other.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.