If you're a Product Manufacturer — what's specific to your role
For: product_manufacturer
Tier: free+
Time: ~11 min
Why you'd do this
Product Manufacturer (Art. 2(1)(e)) is the role most commonly missed at scoping time. Many manufacturers assume the AI Act is about pure-software AI vendors and that their existing MDR / Machinery Regulation compliance covers the AI portion. It does not. Art. 25(3) explicitly treats you as Provider for any AI system you integrate under your name — meaning the full Chapter III provider stack (risk management, data governance, technical documentation, post-market monitoring, incident reporting) lands on top of your sectoral obligations. This chapter walks the 6 decisions that consume the most setup time, in the order they typically arise.
Before you start
- Read the Concept Primer chapter first — it defines the 6 roles and explains why Annex I product manufacturers carry both sectoral and AI Act duties
- Confirm whether your product is listed in AI Act Annex I §A — this is where the harmonised-product universe (medical devices, machinery, lifts, toys, PPE, marine equipment, civil aviation, motor vehicles, etc.) is enumerated. The Profiling Wizard's Annex I product question is the gate.
- Have your existing sectoral technical documentation index handy — Art. 11(2) lets you integrate the AI Act technical documentation into the same dossier rather than maintaining two parallel files.
- Identify your sectoral notified body (if any) — the AI Act assessment often integrates with the existing sectoral conformity assessment when the NB is accredited for both regimes.
Step 1
Decision 1 — Are you actually an Annex I product manufacturer?
The Product Manufacturer role triggers only when all three conditions are met:
- Your product is on the AI Act Annex I §A list of harmonised Union products (medical device under MDR/IVDR, machinery, lift, toy, PPE, marine equipment, civil aviation system, motor vehicle, or one of the other 12 categories — full list in Annex I)
- You integrate an AI system as a safety component of that product, OR you sell the AI system together with the product under your own name
- You place the product on the EU market under your own name or trademark
If any of the three fail, you're NOT a Product Manufacturer in the Art. 2(1)(e) sense — you may still be a Deployer (using AI internally) or a Provider (selling standalone AI), but the Art. 25(3) provider-override does not fire.
The Profiling Wizard's Annex I product question + Product Manufacturer identity question together gate this. See chapter Profiling Wizard deep dive for the UI flow.
Step 2
Decision 2 — What Art. 25(3) does to your obligation set
Once the Annex I + integration + own-name conditions are met, Art. 25(3) treats you as the Provider for the embedded AI system. The legal effect:
- The full Chapter III provider obligations (Art. 8 through Art. 27, plus Art. 43 conformity assessment + Art. 72 post-market monitoring + Art. 73 incident reporting) apply to you, for the AI portion of your product
- You cannot delegate these to your AI component supplier by contract — the regulator looks to you, the name on the product, as the responsible party
- Your sectoral obligations (MDR Annex II technical documentation, Machinery Regulation essential safety requirements, etc.) continue to apply in full — the AI Act stack is cumulative, not substitutive
Practically this means a single medical device with an AI diagnostic component carries: MDR risk management (ISO 14971) + AI Act Art. 9 risk management + MDR clinical evaluation + AI Act Art. 10 data governance + MDR technical documentation + AI Act Art. 11 technical documentation. The good news is that these can be integrated (next decision); the bad news is you must evidence both.
Step 3
Decision 3 — Use Art. 11(2) single-document simplification?
Art. 11(2) is the key Product Manufacturer-friendly simplification: you may integrate the AI Act technical documentation into your existing sectoral technical documentation, producing a single integrated dossier rather than two parallel files. Conditions:
- The integrated dossier must contain all information required by AI Act Annex IV (9 sections: general description, design specifications, training data, validation, risk evidence, change log, post-market plan, instructions, EU declaration)
- Section equivalence is fact-specific — some sectoral templates (MDR Annex II, Machinery Regulation Annex IV) already cover 70-80% of Annex IV with re-labelling; others (Toy Safety Directive technical file) cover less
- The integrated dossier remains subject to both sectoral and AI Act audit — your notified body and the market surveillance authority can each request relevant sections
ComplianceLint's Compliance All-in-One Pack export (Business+, see chapter 23) generates the AI Act Annex IV portion as a structured PDF you can drop into the relevant section of your sectoral dossier. Pro+ tier per-article PDFs cover the same content for individual articles if you prefer to assemble manually.
Step 4
Decision 4 — Pick the conformity assessment route
Art. 43(3) gives Product Manufacturers a specific route: when your product already undergoes third-party conformity assessment under the sectoral Union harmonisation legislation listed in Annex I §A, the AI Act assessment is integrated with the existing sectoral assessment. Practically:
- Your existing sectoral notified body can also perform the AI Act assessment, provided they have obtained AI Act accreditation (check the NANDO database for AI Act scope on your NB's listing)
- If your sectoral NB lacks AI Act scope, you need a second NB for the AI portion — adds time + cost; consider switching to an NB with both scopes if available
- The integrated assessment yields a single CE marking covering both regimes — you do not stack two CE marks on the product
Self-assessment (Annex VI internal control) is not available for AI in Annex I products subject to third-party sectoral assessment — Art. 43(1) routes them to Annex VII or the integrated route described above.
Note: NB certification itself is OUTSIDE ComplianceLint's scope. We produce the integrated dossier and the EU declaration; you submit it to your NB.
Step 5
Decision 5 — Integrate post-market monitoring + incident reporting
Most Annex I sectoral regimes already require post-market monitoring (MDR Art. 83 PMS, Machinery Regulation Article 47 etc.) and incident reporting (MDR MIR / EUDAMED, Machinery Regulation national authorities). AI Act Art. 72 + 73 stack on top. The practical question is whether to run them as a single process or parallel:
- Single integrated PMS — extend your existing sectoral PMS with AI-specific monitoring (model drift, accuracy degradation, edge-case behaviour). Sectoral procedures already require vigilance; layering AI Act-specific data collection on top is operationally simpler than two systems
- Incident reporting — a single incident may require reporting to both the sectoral authority (e.g., national competent authority for medical devices via EUDAMED) AND the AI market surveillance authority. Reporting deadlines may differ (MDR MIR is 15/10/2 days depending on severity; AI Act Art. 73 is 15 days / 2 days)
- Documentation — your PMS plan must reference AI-specific metrics; your incident-response procedure must include the AI market surveillance authority in the notification matrix
ComplianceLint's Human Gates questionnaires for Art. 72 + 73 (Pro+) ask the integration questions explicitly — you declare whether you run integrated or parallel PMS, and the resulting PDFs reflect that declaration.
Step 6
Decision 6 — Supplier flowdown for the embedded AI component
Most Product Manufacturers do not develop the AI component in-house — you procure it from an AI provider and integrate. Art. 25(4) covers this: suppliers of AI systems / components / tools / training data must, on request, provide the Product Manufacturer with the information needed to comply with AI Act obligations.
Practically, this means your supplier contracts with AI component vendors should require:
- Access to the AI system's risk management evidence (Art. 9) — including known limitations + intended use envelope
- Access to training data documentation (Art. 10) sufficient for you to populate the Annex IV §2(d) training-data section
- Notification of material changes to the AI system that would require you to re-assess conformity (model retraining, architecture change, training-data drift)
- Cooperation with market surveillance investigations + incident reporting if the incident involves the AI component
Without these contractual flowdowns, you remain the named responsible party on the product but lack the underlying evidence to defend conformity — a substantial enterprise risk.
ComplianceLint does not generate contract clauses (that's a legal-counsel task, not a compliance-tool task), but the concept primer Art. 25(4) section enumerates the categories of information you need to obtain from suppliers — a useful starting checklist for your procurement team.
What can go wrong
- Our AI is only used in the device's UI layer (e.g., natural-language interface to settings) — does Art. 25(3) still apply? — Art. 25(3) fires when the AI is integrated as a safety component. Pure UX / convenience AI that does not influence safety-critical decisions is generally outside the safety-component scope. But the threshold is fact-specific — a 'voice interface' that lets a user override a safety lockout IS a safety component. The Profiling Wizard asks the Annex I safety component question directly; if you answer 'no' there, the engine drops the Annex I-driven high-risk obligations and you fall back to either limited-risk (Art. 50 transparency) or minimal-risk. When in doubt, consult product-regulation counsel — a wrong answer here can invalidate your Declaration of Conformity.
- Our sectoral notified body refuses to do the AI Act assessment — they say it's not in their scope. — As of 2025-2026, the number of notified bodies with AI Act scope is growing but still limited. Options: (a) verify on the NANDO database whether your NB has applied for AI Act accreditation — many are in process; (b) split the assessment between two NBs (sectoral + AI Act) — operationally feasible, the regulator accepts split-NB dossiers; (c) switch to an NB with both scopes — disruptive mid-project but a cleaner long-term answer. ComplianceLint does not maintain a NB directory — see the European Commission's NANDO database for current accreditations.
- We already have an MDR / Machinery Regulation tech file. Can we just slot the AI Act sections in without restructuring? — Yes, that's the Art. 11(2) integration path. Practically, you map AI Act Annex IV §1-9 to your existing sectoral template — most fields have natural homes (general description → MDR Annex II §1; intended purpose → MDR Annex II §1.1; risk management → MDR Annex II §5 / ISO 14971 file; etc.). The AI-specific sections (training data §2(d), evaluation methodology §3, post-market AI-specific monitoring §6) typically need to be added as new subsections. The Compliance All-in-One Pack export (Business+) provides the AI Act portion in a structure you can drop in directly.
- Wizard still shows us as Provider obligations applying even though we set Product Manufacturer = yes — That's expected behaviour, not a bug. Art. 25(3) deems you Provider for the embedded AI — the Provider obligation stack (Art. 8-27, 43, 72, 73) applies to you by law. The wizard's Product Manufacturer identity flag affects which Annex I carve-outs fire (e.g., Art. 11(2) single-document path) and which conformity-assessment route surfaces, but does NOT remove the underlying Provider obligations. See Concept Primer for the Art. 25(3) Provider-override explanation.
Related
- concept-primer
- profiling-wizard-deep-dive
- persona-provider
- human-gates-deep-dive
- compliance-all-in-one-pack
- compliance-profile-setup
Last updated: 2026-07-27