The classic trap
Recital 50 illuminates Article 6(1) of the AI Act: an AI system becomes automatically high-risk as soon as it is a safety component of a product already subject to third-party conformity assessment (machinery, medical devices, lifts, automotive, aviation, toys...). The trap that market surveillance authorities will sanction: believing that an auxiliary AI module (computer vision in a production line, failure scoring in a medical device, obstacle detection in a lift) escapes the high-risk regime because it is secondary. Once the final product goes through a notified body, the embedded AI follows the same regime, with cumulative sectoral obligations (MDR, machinery, RED) and AI Act requirements.
Covered products and the cumulation logic
Recital 50 lists the harmonised regimes that trigger automatic high-risk classification. For each product you place on the market, ask three questions:
- Was my product already subject to third-party assessment under a legislation listed in Annex I of the AI Act (Machinery Directive 2006/42/EC then Regulation 2023/1230, MDR 2017/745, IVDR 2017/746, Lifts Directive 2014/33/EU, RED 2014/53/EU, Pressure Equipment Directive 2014/68/EU, Toys Directive 2009/48/EC, automotive regulation, EASA aviation regulation, ATEX, etc.)?
- Is my AI system integrated as a safety component, meaning its failure endangers health, safety or property?
- Is the product itself an AI system within the meaning of Article 3(1) of the AI Act?
If yes to the first question + (yes to the second OR yes to the third), your AI is high-risk. You then cumulate AI Act requirements (risk management Article 9, data quality Article 10, technical documentation Article 11, logging Article 12, transparency Article 13, human oversight Article 14, robustness Article 15) with sectoral requirements. The notified body that already assessed your product extends its scope to AI, or a second body intervenes in parallel.
Practical pitfalls
- Underestimating safety component qualification for embedded ML modules (predictive maintenance, anomaly detection, torque regulation).
- Believing that the existing CE certification covers the AI: it only covers the product in its assessed state, any substantial model update triggers reassessment.
- Forgetting that training datasets become an integral part of the technical documentation enforceable against market surveillance.
- Neglecting coordination between upstream AI provider (foundation model) and integrator (final product manufacturer): Article 25 obligations on the responsibility chain are poorly mapped.
- For the medical sector (MDR/IVDR), confusing MDR risk classes (I, IIa, IIb, III) with AI Act high-risk qualification: both regimes coexist and do not substitute each other.
How Luxgap automates this risk
Our Luxgap AI Product Classifier makes it impossible to misroute an AI system embedded in a regulated product. The tool scans your product catalogue (PLM such as Windchill, Aras, Teamcenter, Odoo Manufacturing), your ML model library (MLflow, Azure ML, Vertex AI, private Hugging Face) and your existing CE technical files, then cross-references each product-model combination with the complete matrix of Annexes I and III of the AI Act and the 12 harmonisation legislations cited in recital 50.
- Automatically classifies each AI system as high-risk, limited-risk or minimal-risk, with enforceable justification referenced article by article.
- Detects substantial model updates (drift, retraining, new architecture) that trigger reassessment by a notified body, via MLflow webhooks and GitHub Actions.
- Maps the Article 25 responsibility chain between foundation model provider, integrator and distributor, and identifies missing contractual clauses.
- Generates Annex IV technical documentation ready for notification: system description, training data, human oversight measures, logs, risk assessment.
- Tracks the list of notified bodies designated for the AI Act and alerts as soon as a new body is competent for your sector (medical, machinery, automotive).
- Produces a cryptographically sealed timestamped PDF report, enforceable during market surveillance inspection.
Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS brick according to your industrial perimeter. Request a personalised quote and our teams prepare a demonstration on your real catalogue, with a free 48h white audit to map your AI systems exposed to the high-risk regime before any engagement.