AI Act, Article 6(1): AI inside regulated products after the Digital Omnibus
Tun KelteschPublished
Article 6 of Regulation (EU) 2024/1689 sends AI systems into the high-risk category by two routes. Annex III lists use cases, the route most coverage discusses. Article 6(1) attaches to product safety instead: AI that is a safety component of, or itself is, a product under the sectoral legislation listed in Annex I, where that product already requires third-party conformity assessment. The Digital Omnibus reset both routes' dates; the products route kept the later one, 2 August 2028.
Most companies that date reaches do not think of themselves as AI companies. They make lifts, toys, machines or diagnostic instruments, and someone has proposed adding a model to one.
Two routes, two dates
Regulation (EU) 2026/1744, adopted 8 July 2026, in the Official Journal of 24 July, in force since 27 July, amends three regulations, not one: the AI Act, the aviation regulation 2018/1139 and the Machinery Regulation (EU) 2023/1230.
The rewritten Article 113, third paragraph, point (c) makes Chapter III, Sections 1 to 3 apply from 2 December 2027 for the Article 6(2)/Annex III route and from 2 August 2028 for the Article 6(1)/Annex I route, previously 2 August 2026 and 2 August 2027. The products route was always the later one; the Omnibus kept the stagger while narrowing it from twelve months to eight. The deferral carries the classification rules themselves, with one carve-out for Article 6(5), the Commission's duty to issue classification guidelines. It covers Sections 1 to 3 only: the notified-body infrastructure of Section 4 has applied since 2 August 2025, and the conformity-assessment machinery of Section 5, Article 43 included, since 2 August 2026, which is why the assessment plumbing below runs on its own clock.
The two routes can meet in one system, a listed use case inside a regulated product. Classification is per route, and point (c) sets its dates the same way, route by route: a system caught by both answers to the Annex III limb first, in December 2027.
The dates are fixed. The proposal's mechanism is gone.
Under COM(2025) 836, Article 1, point (31)(a), Chapter III would have applied six months (Annex III) or twelve (Annex I) after a Commission decision confirming adequate support measures, with the 2027 and 2028 dates as outer limits in any case. The adopted regulation dropped it: flat dates, with no trigger and no Commission power to shift them. The mechanism was a pull-forward option, so its removal means the rules can no longer arrive earlier than those dates either, and moving them at all now takes fresh legislation. The residue is recital (40): the Commission "should ensure" support measures arrive in due time.
How that is landing in commentary was checked against a population defined before searching: four fixed queries on 4 August 2026, one item per publisher, published between 1 June and 4 August. Eleven items could be classified; four more were unreachable, including every press candidate, so the sample is four law-firm alerts, one consultancy and six vendor and independent blogs, all in English. Ten of the eleven state the two dates as separate. Three mention that the adopted text dropped the proposal's mechanism, none of them the law-firm alerts, and one still describes the deferral as conditional.
The two-limb test
Article 6(1) (consolidated text, 27 July 2026) opens with a clause that matters to suppliers: it applies "irrespective of whether an AI system is placed on the market or put into service independently" of the product. Then both limbs must hold: (a) the system is intended as a safety component of, or itself is, a product covered by the Union harmonisation legislation in Annex I; (b) that product must undergo third-party conformity assessment under it.
The chapeau is what catches the vendor selling a safety-component model separately: it is a provider in its own right. Article 25(3) shifts the provider obligations to the product manufacturer where the system ships under the manufacturer's name or trademark with a Section A product, and the amended Article 25(4) puts a written-agreement duty on third-party suppliers, so the manufacturer can obtain what its own compliance needs.
The Omnibus narrowed the test, in force since 27 July 2026. Article 6(1a): AI used solely for non-safety user assistance, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component, unless, per Article 6(1b), its failure or malfunctioning would endanger health and safety. Article 6(1c): third-party assessment required solely for other risks (radio spectrum, non-safety interference) no longer satisfies limb (b). Article 3(14) now keys a safety function to an intended purpose of preventing or mitigating health-and-safety risks. Article 6(3), the significant-risk derogation, belongs to the Annex III route; here the only narrowing is paragraphs 1a to 1c.
Classification under this route applies from 2 August 2028: a system meeting the test today lands in the category then, not now.
Where it lands, sector by sector
Annex I after the Omnibus has two sections. Section A lists eleven instruments: toys, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices and in vitro diagnostics. Section B lists nine more, aviation, vehicles, rail and marine equipment among them, where only a slice of the AI Act applies.
Lifts. Every conformity route under Directive 2014/33/EU, Articles 15 and 16, involves a notified body: limb (b) always holds. Limb (a) decides: a model that controls when the brake engages is a safety component; one optimising traffic between floors falls under Article 6(1a), unless failure endangers safety.
Toys. Directive 2009/48/EC stays operative until the Toy Safety Regulation (EU) 2025/2509 applies on 1 August 2030. Where applied harmonised standards cover all of a toy's relevant safety requirements, the route is internal production control; otherwise a notified body performs EC-type examination. No published harmonised standard covers AI behaviour in a toy, so an AI safety feature in practice means EC-type examination, and limb (b) with it. The rewritten Article 43(3) cuts both ways here: high-risk classification never forces a third-party route the sectoral law does not require, and the internal-control option stays open only if harmonised standards or common specifications covering the AI Act requirements are applied as well, instruments whose lateness recital (40) itself records.
Radio equipment. Under Directive 2014/53/EU, the Article 3(1) health-and-safety requirements can always be self-assessed; a notified body becomes mandatory only for the Article 3(2) and 3(3) requirements, and only where harmonised standards were not applied or do not exist. Article 6(1c) now discounts exactly that case where the risk is spectrum or non-safety interference, so the route's reach over radio equipment is narrow. One edge stays open: a mandatory Article 3(3) requirement that does concern health and safety, a boundary the texts do not draw.
Machinery. Machinery left the main track on 27 July 2026: the Omnibus deleted the Machinery Directive from Section A and listed the Machinery Regulation, which applies from 14 January 2027, in Section B. For machinery AI classified under Article 6(1), only Articles 6(1), 60a and 102 to 112 of the AI Act apply; the substantive requirements are to arrive as essential health and safety requirements in the Machinery Regulation's own Annex III, through delegated acts applying by 2 August 2028, and until machinery-specific standards exist, compliance with AI Act harmonised standards or common specifications will count as presumption of conformity with them. The annex is not empty in the meantime: from 14 January 2027 it already requires protection of safety-critical software against accidental or intentional corruption (section 1.1.9) and, for control systems with fully or partially self-evolving behaviour, that the machinery cannot act beyond its defined task and movement space, that data on the safety-related decision-making is recorded and retained for a year, and that correction remains possible at all times (section 1.2.1). The regulation's Annex I, Part A, points 5 and 6 force a notified-body procedure for safety components and embedded systems with "fully or partially self-evolving behaviour using machine learning approaches ensuring safety functions". A frozen, non-learning model may sit outside those points, and outside Part A the Machinery Regulation requires a notified body only conditionally in Part B, and not at all for machinery outside its Annex I. Outside that annex limb (b) fails; for Part B, where self-assessment is open only with full harmonised-standard coverage, the texts do not settle whether the conditional requirement counts. Whether a frozen model still counts as self-evolving is unsettled and not the engineer's call; what turns on it is the difference between a mandatory notified-body procedure and internal control.
Medical devices and IVDs. Medical devices are now the route's main population. MDR Annex VIII, Rule 11 classifies software intended to inform diagnostic or therapeutic decisions at class IIa minimum, class IIb where the impact can be a serious deterioration or a surgical intervention, class III where it can be death or irreversible deterioration; software monitoring physiological processes is class IIa, class IIb where the parameters are vital and their variation could put the patient in immediate danger. Class IIa and above means a notified body under Article 52, and limb (b) with it. The rule's last line matters as much: all other software is class I and self-certifies, so device software outside those branches is not carried into the category by this route. Under the IVDR, classes B to D take a notified body (Article 48).
The collision with the MDR and IVDR clocks
On 2 August 2028 the route starts applying mid-transition. Already out of the legacy windows by then: MDR class III and class IIb implantables other than the well-established-technology items, whose window (Regulation (EU) 2023/607, Article 120(3a)(a)) closed on 31 December 2027, and on the IVD side class D and every device holding a Directive 98/79/EC notified-body certificate. Still inside them on that date: the MDR cohorts of Article 120(3a)(b) and (3b), class IIb other than the implantables on the 2027 date, class IIa, class I sterile or measuring, plus the up-classified ex-class I cohort where legacy software sits, placeable on the market until 31 December 2028; and under the IVDR (Regulation (EU) 2024/1860, Article 110(3b)) the formerly self-certified cohort, class C until 31 December 2028, class B and class A sterile until 31 December 2029.
The windows were never unconditional. They hold only for manufacturers that had a quality management system in place and a notified-body application lodged by 26 May 2024, with a signed agreement by 26 September 2024 (MDR Article 120(3c)); the IVDR's staggered equivalent closes for class C on 26 September 2026, weeks after this piece publishes. And they hold only without "significant changes in the design and intended purpose". MDCG 2020-3 Rev.1, guidance rather than law, treats an algorithm change that may alter diagnosis or therapy, and new medical functionality, as significant. The AI Act's grandfathering (amended Article 111(2)) turns on close but not identical wording, "significant changes in their designs", with no intended-purpose limb and no guidance apparatus behind it. One engineering act, adding a model to a legacy device, will usually raise both questions at once: it can end the device's transition status and bring the AI system into scope.
COM(2025) 1023 of 16 December 2025 counts 51 notified bodies designated under the MDR and 19 under the IVDR, and names "the limited certification capacity of the notified bodies" alongside manufacturer preparedness among the causes of shortage risk (checked 4 August 2026). The same document proposes moving the MDR and IVDR from Section A to Section B, the move machinery has already made (procedure 2025/0404(COD): awaiting committee decision, checked 4 August 2026). Adopted as proposed, it would remove the AI Act limb of the double question and leave the device limb, and the capacity constraint, exactly where they are. Decisions today run under the law in force.
What the route obliges
For the Section A sectors the requirements are the Chapter III, Section 2 catalogue: a risk management system run across the lifecycle (Article 9), data governance (10), technical documentation (11), automatic logging (12), transparency to the deployer (13), human oversight (14), and the Article 15 duty on accuracy, robustness and cybersecurity, plus, from Section 3, the Article 16 provider duties, carried under Article 25(3) by the product manufacturer that ships the AI under its own name. Section B products, machinery among them, get none of this directly; their requirements arrive through the sectoral law itself.
What is specific to this route is where the checking happens. The rewritten Article 43(3) folds the Section 2 requirements into the sectoral conformity assessment, one procedure rather than two, together with an assessment of the Article 17 quality management system, and Article 11 permits a single documentation set with the sectoral paperwork. Sectoral notified bodies may assess the AI requirements transitionally from 27 July 2026 and must apply for AI Act designation by 28 January 2028. Two instruments can shrink the catalogue before it applies: delegated acts under the new Article 2(13), due by 2 August 2027, may limit which of Articles 9 to 15 and 17 to 25 apply where Section A law protects equivalently, and the Article 96(1)(g) guidelines, due by 1 August 2027, are to say how Articles 8(2), 9(10) and 17(3) sit next to sectoral duplicates. Two years is less comfortable than it sounds: the work lands on teams already running a certified QMS, and the standards the assessment leans on are the ones recital (40) says came late.
The boundary is an architecture decision
The same data, and often the same model, can sit inside the regulated product function or outside it. Research tooling, internal analysis, manufacturing and process analytics, exploratory work on the company's own data: none of it is touched by this route. Article 6(1) attaches where the output becomes a safety component of the product, or the product itself, and it attaches to the product, not only to the model. The line belongs in the system design, drawn explicitly and early.
- A model frozen inside a certified product is a change-control problem: retraining raises a design-change question, and in the device world the significant-change question twice over, as above. The retraining cadence a data team assumes is free is not free.
- Teams that begin on the regulated side inherit documentation and assessment burden before they know whether the model works at all.
- Teams that begin outside can establish value first, on the same data, then cross deliberately once there is something worth certifying.
- Deciding late means rebuilding, because data flows, logging and documentation were laid down on the wrong side of the line; deciding at the architecture stage costs a diagram.
Four calls here do not belong to an engineer: whether a frozen, non-learning model is "self-evolving" under the Machinery Regulation's Annex I; whether an assistance function crosses Article 6(1b); whether applied standards cover all of a toy's relevant safety requirements; whether a radio-equipment requirement forcing a notified body also concerns health and safety. Pre-decision answers to those come from a regulatory adviser; a notified body's view arrives inside the assessment, once the procedure is already running.
Enforcement in Luxembourg
The Article 50 report found a directly applicable obligation with no designated enforcer. This route works the other way round. For Section A products, Article 74(3) makes the authority already doing market surveillance under the sectoral law the AI Act market surveillance authority by operation of law, and Luxembourg's sectoral structures exist: the ILNAS competent-authorities list (version 5.4, September 2023, checked 4 August 2026; it predates the AI Act, so it evidences the sectoral remits, not an AI-specific designation) has ILNAS for toys, lifts and radio equipment, and the Direction de la santé for medical devices. Machinery is different: ILNAS keeps its sectoral surveillance role there, but machinery now sits in Section B, which Article 74 does not reach. And Article 74(3) is a default a Member State may displace by designating another authority with coordination duties, an allocation Bill 8476 can still make.
The bill still matters here for two things: national penalty rules under Article 99(1) need it, and the Article 70(2) designations and single point of contact, due 2 August 2025, are outstanding. Checked 4 August 2026: still in committee, Conseil d'État opinion 10 July 2026.
Timeline
| Date | What applies |
|---|---|
| 2 February 2025 | AI Act Chapters I and II apply |
| 2 August 2025 | Notified bodies (Chapter III, Section 4), GPAI, governance, penalties (except Article 101) |
| 2 August 2026 | Article 50 transparency — not deferred |
| 2 December 2026 | New prohibitions (Article 5(1)(ba)(bb), 5(1a)(1b)); Article 50(2) catch-up |
| 14 January 2027 | Machinery Regulation (EU) 2023/1230 applies |
| 2 August 2027 | Article 2(13) delegated acts due |
| 2 December 2027 | High risk, Annex III — moved by Regulation (EU) 2026/1744 |
| 31 December 2027 | MDR class III and IIb implantable (except the well-established-technology list), IVDR class D and 98/79/EC-certificate holders: last day for placing on the market |
| 28 January 2028 | Sectoral notified-body designation applications due |
| 2 August 2028 | High risk, Article 6(1)/Annex I — moved by Regulation (EU) 2026/1744; Machinery Regulation AI delegated acts apply by this date |
| 31 December 2028 | MDR 2028 cohorts and IVDR class C: last day for placing on the market |
| 31 December 2029 | IVDR class B and A sterile: last day for placing on the market |
| 1 August 2030 | Toy Safety Regulation (EU) 2025/2509 applies |
| 2 August 2030 | Public-authority backstop (Article 111(2)) |
What is still moving
COM(2025) 1023, the Section B move above. The Article 6(5) classification guidelines, due 2 February 2026 and existing only as drafts of 19 May 2026, one of the three on Annex I, with the consultation closed on 23 July and nothing final as of 4 August 2026. The Machinery Regulation delegated acts, not yet adopted. The Article 2(13) acts, due 2 August 2027. The Article 96(1)(g) guidelines, due 1 August 2027. And harmonised standards, whose lateness recital (40) gives among its reasons for the dates, alongside common specifications, guidance and national authorities.
Frequently asked questions
Is 2 August 2028 conditional on standards being ready? No. The proposal's mechanism, a Commission decision that could have pulled the dates forward, was dropped; the adopted dates move only by new legislation.
Is our product's AI high-risk? Only where both limbs hold: the system is a safety component of, or itself is, a product covered by Annex I legislation, and that product must undergo third-party conformity assessment for health-and-safety risks. The route applies from 2 August 2028; the dates run route by route, so an Annex III use case in the same system answers to that route from 2 December 2027.
We are adding AI to a CE-marked legacy device. What changes? The significant-change question, twice: under MDCG guidance an algorithm change that may alter diagnosis or therapy is significant, which ends MDR or IVDR transition status and means a full notified-body assessment, and the AI Act's Article 111(2) turns on a near-identical trigger for bringing the system into scope.
We build machinery with an ML safety function. What applies when? From 14 January 2027, the Machinery Regulation, with a notified-body procedure where the safety function uses self-evolving machine learning (Annex I, Part A, points 5 and 6). The AI-specific requirements arrive in its Annex III by delegated acts applying by 2 August 2028; the AI Act itself reaches machinery only through Articles 6(1), 60a and 102 to 112.
Who enforces this in Luxembourg? For Section A products, the sectoral market surveillance authorities, by operation of law (Article 74(3)); fines wait on Bill 8476.
Our models are internal research tools. Are we caught? Not by this route: an internal tool is neither a safety component of, nor itself, a product covered by Annex I, so limb (a) fails. The question reopens the moment an output becomes part of a product function.
An engineer's implementation read, not legal advice. No lawyer reviewed this text.
Every date, article number and annex reference above was checked against the Official Journal and consolidated texts on 4 August 2026; the Commission proposals and draft guidelines, the MDCG guidance, the procedure files, the ILNAS list and the Bill 8476 dossier were checked the same day at the sources linked inline. The two files still moving, the Bill 8476 dossier and procedure 2025/0404(COD), were re-checked on 18 August 2026, unchanged. If you want a specific point checked before you decide anything, write to me.