Skip to content

When a Product Manufacturer Becomes the "Provider" Under the EU AI Act

9 min read · updated August 11, 2026

Article 3(3) defines a provider as whoever develops an AI system and places it on the market under their own name or trademark. That works for software sold as software. It does not work when the AI is a component inside a lift, a surgical robot or a toy, so Article 25 adds a rule that moves provider status to the manufacturer of the product.

Why the Act needed a special rule for products

Regulation (EU) 2024/1689 makes an AI system high-risk by two different routes, and the split matters here. Article 6(2) with Annex III catches systems by their use case: recruitment, credit, education, essential services. Article 6(1) catches them structurally: an AI system is high-risk where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and that product is required to undergo a third-party conformity assessment under that legislation. The Regulation, including Annex I, is published at EUR-Lex.

Annex I Section A is the list of instruments that carries the full AI Act consequence: machinery, toy safety, recreational craft, lifts, equipment for potentially explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, gas appliances, medical devices and in vitro diagnostic medical devices. These are regimes with decades of existing practice, their own notified bodies, their own technical files and their own CE marking. Layering a second, independent provider onto a machine that already has a manufacturer would produce two parties each holding half a conformity file, which is the outcome Article 25(3) exists to prevent.

Article 25(3), and its two limbs

Article 25(3) provides that, for high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Annex I Section A, the product manufacturer is considered the provider of the high-risk AI system and is subject to the provider obligations in Article 16, in either of two circumstances: where the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer; or where the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.

Whether a given component is a “safety component”, and whether a given product falls under an Annex I Section A instrument and requires third-party conformity assessment, are determinations about your specific product under sectoral law. This page is not legal advice and cannot make them. Take advice on your own facts.

The second limb is the one that catches people, and it is a software-update rule in disguise. A machine ships in 2027 with no AI in it. In 2028 the manufacturer pushes an over-the-air update adding an AI-driven safety function under its own brand. The system was put into service under the manufacturer’s name after the product was placed on the market, so the manufacturer is the provider of that AI system, with the full Article 16 obligation set, for a product it already sold. Any manufacturer with a connected fleet needs this limb in front of it before it plans a feature release.

Both limbs turn on the name or trademark. An AI component supplied to a manufacturer, integrated, and shipped under the manufacturer’s brand engages the rule. An AI system that reaches the end user under the AI vendor’s own brand, in the vendor’s own product, does not — that vendor is simply the provider under Article 3(3) and Article 25(3) never comes into play.

Article 25(1) is the general version of the same idea and should be read alongside: a distributor, importer, deployer or other third party becomes a provider if it puts its name or trademark on a high-risk system already on the market (subject to contractual arrangements allocating obligations otherwise), if it makes a substantial modification to such a system, or if it modifies the intended purpose of a system that was not high-risk so that it becomes high-risk. Article 25(2) then provides that the original provider ceases to be the provider of that specific system, and must cooperate with the new provider by making available the necessary information and reasonably expected technical access — unless it had clearly specified that its system is not to be changed into a high-risk AI system.

What the AI supplier still owes: Article 25(4)

Provider status moving to the manufacturer does not leave the AI supplier with nothing. Article 25(4) requires that the provider of a high-risk AI system and the third party supplying an AI system, tools, services, components or processes used or integrated in it specify, by written agreement, the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, so that the provider can fully comply with its obligations under the Regulation.

This is a statutory obligation to contract, and it is the provision to cite when a component supplier declines to hand over what the manufacturer needs for its Article 11 technical documentation or its Article 9 risk management file. It has one carve-out: it does not apply to third parties making tools, services, processes or components accessible to the public under a free and open-source licence, other than general-purpose AI models. The AI Office is to develop and recommend voluntary model contractual terms to support this relationship. For what those terms need to cover in practice, see AI contract clauses.

The practical negotiation this creates is asymmetric in a way worth naming. The manufacturer carries the regulatory exposure — conformity assessment, CE marking, post-market monitoring, incident reporting, the Article 99 penalty ceilings — while the technical facts it must document sit with a supplier that has no direct AI Act liability for that system. Article 25(4) is the lever, and a written agreement made before integration is worth considerably more than the same argument made during a market surveillance investigation.

One conformity assessment, one CE mark

The reward for the manufacturer taking on provider status is that it does not have to run two parallel processes. Article 8(2) provides that where a product contains an AI system to which both the AI Act requirements and the requirements of Annex I Section A legislation apply, providers are responsible for full compliance and may, to ensure consistency and avoid duplication, integrate the necessary testing, reporting and documentation into what already exists under the sectoral legislation.

Article 43(3) carries that through to assessment: for high-risk systems covered by Annex I Section A legislation, the provider follows the relevant conformity assessment procedure required under that legislation, and the AI Act requirements in Chapter III Section 2 are assessed as part of it — by the notified body already designated under the sectoral instrument, which becomes entitled to control the AI system’s conformity provided it has been assessed for that competence. The result is one technical file, one notified body, one declaration of conformity and one CE marking affixed under the sectoral regime, not an AI-specific mark alongside it.

The registration obligation is where the two regimes diverge again: Annex I Section A products do not go into the same public EU database entry as Annex III systems. Check the registration rules against your route rather than assuming they follow the conformity assessment.

Dates, and Annex I Section B

Article 113 is explicit that the Article 6(1) route runs late. The obligations for high-risk systems caught by Article 6(1) — the product route this page is about — apply from 2 August 2027, rather than 2 August 2026 as for Annex III systems. A manufacturer has a year longer than a recruitment-software vendor, and it needs it: reopening a conformity assessment for a machine takes longer than reopening a SaaS compliance file.

Annex I Section B is different again and is a common source of error. It lists product legislation in sectors with their own comprehensive Union frameworks — civil aviation, motor vehicles and their components, agricultural and forestry vehicles, marine equipment, rail interoperability. For AI systems that are safety components of products covered by those instruments, Article 2(2) provides that only a small set of the Regulation’s provisions applies, with the AI-related requirements instead brought into the sectoral regimes by the amending articles at the end of the Regulation. If your product is a vehicle or an aircraft, the answer to “what does the AI Act require” is largely “read the sectoral rules once they are updated”, and Article 25(3) is not the provision you need.