The classic trap
Recital 87 closes a loophole: a product manufacturer (industrial machine, medical device, connected toy, lift) that embeds an AI safety component cannot offload responsibility onto its AI supplier. If the AI system is not placed on the market separately, the product manufacturer assumes all provider obligations under the AI Act: technical documentation, conformity assessment, CE marking, risk management, post-market monitoring. The EU AI Office and market surveillance authorities will prioritise manufacturers who believe a contract with the AI subcontractor is enough, without owning the conformity of the integrated product themselves.
The integration test: who is responsible for what?
The rule is binary and you need to know which side you fall on:
- AI sold separately from the product (e.g. a computer vision module marketed as a standalone brick): the AI developer is the provider under the AI Act, the product manufacturer is deployer or importer depending on the case.
- Embedded and non-separable AI (e.g. a braking algorithm built into a machine tool, an anomaly detection AI welded into a medical device): the product manufacturer absorbs all provider obligations, even if it subcontracted the AI development.
- The scope covers products under Union harmonisation legislation based on the New Legislative Framework: machinery (Regulation 2023/1230), medical devices (MDR/IVDR), toys, lifts, radio equipment, personal protective equipment, etc.
- Contractual consequence: your agreements with third-party AI developers must require delivery of the Annex IV technical documentation, training datasets, performance metrics and a full audit right, otherwise you will not be able to discharge your obligations.
- CE marking consequence: the CE marking of the final product now also covers AI Act conformity, and the notified body will assess both dimensions in an integrated manner.
How Luxgap automates this risk
Our Luxgap AI Embedded Conformity Mapper removes the blind spot for manufacturers embedding third-party AI in CE-marked products: the tool automatically maps each AI component in your product bill of materials, qualifies its status (embedded / separable) against the recital 87 criteria, and identifies the full chain of obligations that fall back on you. A specialised LLM agent reads your technical specs, supplier contracts and CE marking files to detect hidden AI components, including those your R&D teams had not identified as such (ML models embedded in third-party firmware, computer vision libraries shipped inside an SDK).
- Automatically detects AI components in your bill of materials by cross-referencing your PLM (Siemens Teamcenter, PTC Windchill), Git repositories and supplier contracts in Odoo or SAP.
- Classifies each component against the recital 87 grid: separable AI (third-party provider responsible) versus embedded AI (product manufacturer responsible), with defensible justification.
- Generates the contractual clauses to inject into your AI supplier agreements to secure access to Annex IV documentation, datasets and conformity evidence.
- Produces the integrated conformity dossier combining AI Act and sectoral legislation (Machinery, MDR, RED, Toys) ready for the notified body, with cryptographic version traceability.
- Alerts in real time when an AI supplier modifies its model, triggering a conformity reassessment before the change invalidates your CE marking.
- Computes an exposure score per product and per manufacturing line, prioritising remediations based on regulatory and commercial risk.
Available as part of a Luxgap CISO mandate or as a standalone SaaS module depending on your industrial perimeter. Request a tailored quote and our teams will prepare a demonstration on your real product bill of materials, with a free 48-hour blind audit to map your hidden AI components before any engagement.