Under the EU AI Act, a "product manufacturer" is a company that makes a physical, regulated product and embeds an AI system into it as a safety component. The Act lists the product manufacturer among the operators of an AI system, but does not give the term a standalone definition the way it defines provider, deployer, importer, and distributor. Instead, Article 25(3) sets out a specific rule: where a high-risk AI system is a safety component of a product covered by existing EU product legislation, and that product is placed on the market under the manufacturer's own name or trademark, the product manufacturer is considered the provider of that AI system and takes on the provider's obligations.
Who the product manufacturer is
The product manufacturer is not a software vendor in the ordinary sense. It is a maker of tangible, already-regulated products — machinery, medical devices, vehicles, lifts, toys, radio equipment, and similar goods that fall under the Union harmonisation legislation listed in Annex I of the EU AI Act. These products have long been governed by sector-specific safety rules and their own conformity-assessment procedures, quite apart from AI.
What brings such a manufacturer into the AI Act is the way modern products increasingly rely on AI to stay safe. When an AI system performs a safety function inside the product — for example, a collision-avoidance system in a vehicle or a diagnostic component in a medical device — that AI system is a "safety component." Its failure or malfunction could endanger health or safety, which is precisely why the Act treats it with the same seriousness as the product it protects.
The Article 25(3) rule
Article 25(3) is the key provision. It addresses a specific situation with three conditions:
- the AI system is high-risk;
- it is a safety component of a product covered by the Annex I Union harmonisation legislation; and
- the product is placed on the market or put into service under the product manufacturer's own name or trademark.
Where all three hold, the product manufacturer is considered the provider of the high-risk AI system and is subject to the provider's obligations under the Act.
Why the manufacturer becomes the provider
The logic is accountability. A buyer sees one product, sold under one brand, and holds that brand responsible for its safety. It would make little sense for the manufacturer to answer for the product as a whole while a separate party answered for the AI inside it. By designating the manufacturer as the provider of the embedded AI system, the Act creates a single accountable party for the entire product — the same company that already carries the product's sectoral safety obligations also carries the AI obligations that now sit within it.
The duties that then attach
Once treated as the provider, the product manufacturer takes on the high-risk provider obligations, which include:
- A risk-management system operating across the AI system's lifecycle;
- Technical documentation demonstrating how the system meets the applicable requirements;
- Data governance for the datasets used to develop the system;
- Record-keeping and logging so the system's operation can be traced;
- Transparency and human oversight appropriate to the system's use; and
- Accuracy, robustness, and cybersecurity proportionate to the risk.
A distinctive feature is that the conformity assessment for the AI system is integrated into the product's existing sectoral conformity route rather than run as a separate parallel exercise. Where the underlying product legislation already requires a third-party assessment, the AI requirements are assessed as part of that same procedure — one file, one process, one declaration of conformity — so manufacturers work within a framework they already know rather than a wholly new one.
Relationship to the provider and other operators
The product manufacturer sits within the Act's wider cast of operators — provider, deployer, importer, distributor, authorised representative, and the product manufacturer itself. In most cases these are distinct parties with distinct duties. Article 25(3) is the bridge: it does not create a new obligation set but instead maps the product manufacturer onto the existing provider role for the AI system embedded in its product.
An original AI developer may still supply the underlying model or system, and contractual arrangements typically govern how documentation and information pass along the chain. But toward the market and the authorities, the party that put its name on the product answers as the provider of its AI safety component. Organisations navigating these roles can work through the full framework in our EU AI Act guide.
This article is an educational explainer, not legal advice. The precise obligations that apply to any given product and AI system depend on the underlying sectoral legislation and the specifics of the deployment; assessing them for a particular case is a task for qualified legal and conformity-assessment advisers.
