AI Act, Article 6(1): AI inside regulated products after the Digital Omnibus
Tun KelteschPublished Updated
Article 6 of Regulation (EU) 2024/1689 puts AI systems in the high-risk category by two routes. Most coverage stays with the Annex III use cases; product teams should read Article 6(1), which covers AI inside products regulated by the sectoral legislation in Annex I. Since the Digital Omnibus it applies from 2 August 2028, to companies that make lifts, toys, machines or diagnostic instruments and are adding a model to one.
Which date applies to you
| If you make | Route | From |
|---|---|---|
| A lift where a model controls when the brake engages | Article 6(1); every lift conformity route involves a notified body | 2 August 2028 |
| A lift where a model only optimises traffic between floors | Excluded by Article 6(1a), unless its failure would endanger safety | Not caught |
| A toy with an AI safety feature | Article 6(1); no harmonised standard covers AI behaviour, so EC-type examination in practice | 2 August 2028 |
| Radio equipment | Only in a narrow edge case since Article 6(1c) | 2 August 2028, if caught |
| Machinery with a machine-learning safety function | Annex I, Section B, through the Machinery Regulation | 14 January 2027; AI requirements by 2 August 2028 |
| Medical device software in class IIa or above, IVDs in classes B to D | Article 6(1), on top of the MDR and IVDR transition deadlines | 2 August 2028 |
| A listed Annex III use case, including one inside a regulated product | Article 6(2) | 2 December 2027 |
| Internal research tools and process analytics | Not a safety component of a product | Not caught |
What the Digital Omnibus changed
Regulation (EU) 2026/1744, in force since 27 July 2026, rewrote Article 113: Chapter III, Sections 1 to 3 apply from 2 December 2027 for Annex III and from 2 August 2028 for Annex I, instead of 2 August 2026 and 2 August 2027. The proposal, COM(2025) 836, tied the start to a Commission decision on support measures. The adopted text dropped that decision: the dates are fixed, and only new legislation can move them.
The test
Article 6(1) (consolidated text, 27 July 2026) applies "irrespective of whether an AI system is placed on the market or put into service independently" of the product. A vendor selling a safety-component model separately is a provider; if the model ships under the manufacturer's name, Article 25(3) moves those obligations to the manufacturer.
Both limbs must hold: (a) the system is a safety component of a product covered by Annex I legislation, or is that product; (b) that product must undergo third-party conformity assessment.
The Omnibus narrowed each limb. Under Article 6(1a), AI used only for non-safety user assistance, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component, unless its failure would endanger health and safety (Article 6(1b)). Under Article 6(1c), an assessment required only for other risks, such as radio spectrum, no longer satisfies limb (b).
Machinery
Machinery moved to Section B on 27 July 2026. The AI Act reaches it only through Articles 6(1), 60a and 102 to 112; the substantive requirements will come through delegated acts under the Machinery Regulation (EU) 2023/1230, applying by 2 August 2028. From 14 January 2027 that regulation already requires self-evolving control systems to stay within their defined task and movement space, keep a year of records on their safety-related decisions and remain correctable (Annex III, section 1.2.1). Systems with "fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions" need a notified body (Annex I, Part A, points 5 and 6).
Medical devices
Under the MDR, Annex VIII, Rule 11, software that informs diagnostic or therapeutic decisions or monitors physiological processes is at least class IIa and needs a notified body. Under the IVDR, classes B to D do.
The 2028 date lands mid-transition: class IIa and class IIb legacy devices other than implantables, including up-classified former class I software, can be placed on the market until 31 December 2028 (Regulation (EU) 2023/607); IVD class C until the same date and class B until 31 December 2029 (Regulation (EU) 2024/1860). The windows also required a notified-body agreement by set dates; for IVDR class C that deadline closed on 26 September 2026. They hold only without "significant changes in the design and intended purpose", and the MDCG 2020-3 Rev.1 guidance counts an algorithm change that may alter diagnosis or therapy as significant. The AI Act's grandfathering in Article 111(2) turns on "significant changes in their designs". Adding a model to a legacy device can end its transition status and bring the AI into scope at once.
COM(2025) 1023 counts 51 MDR and 19 IVDR notified bodies, a capacity it names as a cause of shortage risk, and proposes moving the MDR and IVDR to Section B, as happened with machinery (procedure 2025/0404(COD): awaiting committee decision). Both checked 4 August 2026.
What the route requires
For Section A products: Articles 9 to 15 (risk management, data governance, technical documentation, logging, transparency to the deployer, human oversight, accuracy, robustness and cybersecurity) and the Article 16 provider duties. The rewritten Article 43(3) folds them into the sectoral assessment, together with a check of the Article 17 quality management system. Delegated acts under Article 2(13), due by 2 August 2027, may trim the list where sectoral law already protects equivalently.
Planning the architecture
The same data, and often the same model, can sit inside the regulated product function or outside it. Article 6(1) attaches when an output becomes a safety component of the product, and where that happens is a design decision, cheapest to make while the architecture is still a diagram.
A model frozen inside a certified product turns every update into change control: retraining raises a design-change question, and in a medical device the significant-change question under both the MDR and the AI Act. Retraining that a data team treats as routine becomes a release that needs regulatory review.
Starting on the regulated side means documentation and assessment work before anyone knows whether the model performs. Starting outside, you can prove value on the same data and cross once there is something worth certifying. For that crossing to be a planned release, keep the experimental pipeline's data flows, logs and documentation apart from the product's inference path from the start. Decide late, and they may already sit on the wrong side of the line.
Four questions belong to a regulatory adviser before the design is fixed: whether a frozen model is "self-evolving" under the Machinery Regulation; whether an assistance function crosses Article 6(1b); whether applied standards cover all of a toy's relevant safety requirements; and whether a radio-equipment requirement that forces a notified body also concerns health and safety. A notified body gives its view only once the assessment is running.
Enforcement in Luxembourg
For Section A products, Article 74(3) makes the sectoral market surveillance authority the AI Act authority by operation of law, so the enforcement gap described in the Article 50 piece does not arise here. The ILNAS competent-authorities list (version 5.4, September 2023, which predates the AI Act; checked 4 August 2026) names ILNAS for toys, lifts and radio equipment and the Direction de la santé for medical devices. Machinery, now in Section B, is outside Article 74. Bill 8476 can still designate another authority, and national penalties under Article 99(1) wait on it. Checked 4 August 2026: still in committee, Conseil d'État opinion 10 July 2026.
An engineer's implementation read, not legal advice. No lawyer reviewed this text.
I checked every date, article number and annex reference above against the Official Journal, the consolidated texts and the sources linked inline on 4 August 2026. Bill 8476 and procedure 2025/0404(COD) were re-checked on 18 August 2026, unchanged.
I build AI systems, mostly computer vision and applied machine learning. If you are putting a model into a regulated product, I can help you draw the product boundary and the architecture around it before either is fixed: write to me.