{
  "node_id": "eu-ai-act-cyber-resilience-act-intersection",
  "title": "EU AI Act and Cyber Resilience Act - Dual Compliance for Connected AI Products",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "Providers of AI systems embedded in connected products face dual compliance obligations under Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2024/2847 (EU Cyber Resilience Act, CRA); the CRA applies to products with digital elements (PDEs) that are directly or indirectly connected to a network - including IoT devices, industrial control systems, smart home products, medical devices (software as a medical device), and connected vehicles; where a connected product contains an AI system that is: (a) a safety component of a product covered by EU AI Act Annex II (e.g., Machinery Regulation, Medical Devices Regulation) - the AI system is automatically high-risk under EU AI Act Article 6(1); (b) within a CRA-covered product - the product must also comply with CRA essential cybersecurity requirements; the key dual compliance obligations are: (1) conformity assessment - both the EU AI Act conformity assessment (for high-risk AI systems) and the CRA conformity assessment (for products with digital elements) must be completed before CE marking; for some products, a single integrated conformity assessment covers both instruments; (2) vulnerability management - CRA Article 13 requires providers to address known vulnerabilities throughout the product lifecycle; EU AI Act Article 15 requires robustness against adversarial inputs and cybersecurity for high-risk AI systems; (3) incident reporting - CRA Article 14 requires notification of actively exploited vulnerabilities and security incidents to ENISA; EU AI Act Article 73 requires notification of serious incidents affecting high-risk AI systems to market surveillance authorities; (4) documentation - CRA requires technical documentation under CRA Annex V; EU AI Act Article 11 requires separate technical documentation - both must be maintained; the CRA applies from December 11, 2027 (with an 18-month transition for essential requirements); the EU AI Act high-risk provisions apply from August 2, 2026.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-cyber-resilience-act-intersection.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-6-classification-high-risk",
    "eu-cyber-resilience-act-2024-connected-products",
    "eu-ai-act-accuracy-robustness-cybersecurity"
  ],
  "primary_citations_count": 5
}