The Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements placed on the EU market. The EU AI Act is a separate instrument that regulates artificial intelligence systems. A product that has digital elements and also includes AI can fall within both, so the two regimes stack rather than replace one another. This guide stays high-level, because the interaction between them is still settling.
It helps to keep the questions separate.
An AI-enabled connected product may need to answer both questions at once.
Cybersecurity is the natural seam between the two. A product that embeds an AI component still has to meet the CRA's essential requirements for the product as a whole, including vulnerability handling and the SBOM. AI Act Article 15 requires high-risk AI systems to maintain appropriate accuracy, robustness and cybersecurity throughout their lifecycle and to resist attacks on their use, outputs and performance; where an AI-enabled product also falls within the CRA, the two sets of obligations generally apply cumulatively rather than one replacing the other.
The practical planning point is that meeting the CRA does not automatically discharge AI Act duties, and vice versa. Treat them as two overlapping obligations to be mapped, not one.
A sensible posture is to establish your CRA position first, since its product-security requirements apply to any product with digital elements regardless of AI content, and then layer the AI-specific analysis on top. The AI Act applies in phases from 2 February 2025, 2 August 2025, 2 August 2026 and, for Article 6(1) product-related high-risk systems, 2 August 2027, all ahead of the CRA's general application date of 11 December 2027.
CRANIS2 is built for the EU Cyber Resilience Act, not the AI Act. It structures the product-security evidence a product with digital elements needs, its SBOM, vulnerability handling, and conformity documentation, including for products that happen to embed AI. Where that CRA evidence is also useful as you work through AI Act duties, treat it as a by-product: CRANIS2 does not assess or document AI Act conformity, and you should not rely on it for that. This page is here for orientation. Create an account to get your CRA evidence in order.
Yes. The CRA applies to products with digital elements placed on the EU market, and embedding AI does not remove a product from that scope. The AI Act may add further obligations on top.
No. They are separate instruments with different subjects. CRA conformity does not automatically satisfy AI Act Article 15, nor does AI Act conformity satisfy the CRA; the AI Act's express cybersecurity presumption in Article 42(2) applies only where an applicable certification or statement has been issued under an EU cybersecurity certification scheme established under Regulation (EU) 2019/881.
A practical approach is to establish the CRA position first, because its product-security requirements apply to any product with digital elements, then map AI-specific obligations on top. The AI Act's phased dates (2 February 2025, 2 August 2025, 2 August 2026 and 2 August 2027 for Article 6(1) product-related high-risk systems) all fall before the CRA's general application date of 11 December 2027.
Related guides: Does the CRA apply to my product? and CRA alongside DORA, GPSR and the Product Liability Directive.