We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Back to glossary
Glossary5 min read

Product Manufacturer (EU AI Act)

Under the EU AI Act, a product manufacturer that embeds a high-risk AI safety component in an own-branded product counts as the provider (Article 25(3)).

Product Manufacturer (EU AI Act)

Under the EU AI Act, a "product manufacturer" is a company that makes a physical, regulated product and embeds an AI system into it as a safety component. The Act lists the product manufacturer among the operators of an AI system, but does not give the term a standalone definition the way it defines provider, deployer, importer, and distributor. Instead, Article 25(3) sets out a specific rule: where a high-risk AI system is a safety component of a product covered by existing EU product legislation, and that product is placed on the market under the manufacturer's own name or trademark, the product manufacturer is considered the provider of that AI system and takes on the provider's obligations.

Who the product manufacturer is

The product manufacturer is not a software vendor in the ordinary sense. It is a maker of tangible, already-regulated products — machinery, medical devices, vehicles, lifts, toys, radio equipment, and similar goods that fall under the Union harmonisation legislation listed in Annex I of the EU AI Act. These products have long been governed by sector-specific safety rules and their own conformity-assessment procedures, quite apart from AI.

What brings such a manufacturer into the AI Act is the way modern products increasingly rely on AI to stay safe. When an AI system performs a safety function inside the product — for example, a collision-avoidance system in a vehicle or a diagnostic component in a medical device — that AI system is a "safety component." Its failure or malfunction could endanger health or safety, which is precisely why the Act treats it with the same seriousness as the product it protects.

The Article 25(3) rule

Article 25(3) is the key provision. It addresses a specific situation with three conditions:

  • the AI system is high-risk;
  • it is a safety component of a product covered by the Annex I Union harmonisation legislation; and
  • the product is placed on the market or put into service under the product manufacturer's own name or trademark.

Where all three hold, the product manufacturer is considered the provider of the high-risk AI system and is subject to the provider's obligations under the Act.

Why the manufacturer becomes the provider

The logic is accountability. A buyer sees one product, sold under one brand, and holds that brand responsible for its safety. It would make little sense for the manufacturer to answer for the product as a whole while a separate party answered for the AI inside it. By designating the manufacturer as the provider of the embedded AI system, the Act creates a single accountable party for the entire product — the same company that already carries the product's sectoral safety obligations also carries the AI obligations that now sit within it.

The duties that then attach

Once treated as the provider, the product manufacturer takes on the high-risk provider obligations, which include:

  • A risk-management system operating across the AI system's lifecycle;
  • Technical documentation demonstrating how the system meets the applicable requirements;
  • Data governance for the datasets used to develop the system;
  • Record-keeping and logging so the system's operation can be traced;
  • Transparency and human oversight appropriate to the system's use; and
  • Accuracy, robustness, and cybersecurity proportionate to the risk.

A distinctive feature is that the conformity assessment for the AI system is integrated into the product's existing sectoral conformity route rather than run as a separate parallel exercise. Where the underlying product legislation already requires a third-party assessment, the AI requirements are assessed as part of that same procedure — one file, one process, one declaration of conformity — so manufacturers work within a framework they already know rather than a wholly new one.

Relationship to the provider and other operators

The product manufacturer sits within the Act's wider cast of operators — provider, deployer, importer, distributor, authorised representative, and the product manufacturer itself. In most cases these are distinct parties with distinct duties. Article 25(3) is the bridge: it does not create a new obligation set but instead maps the product manufacturer onto the existing provider role for the AI system embedded in its product.

An original AI developer may still supply the underlying model or system, and contractual arrangements typically govern how documentation and information pass along the chain. But toward the market and the authorities, the party that put its name on the product answers as the provider of its AI safety component. Organisations navigating these roles can work through the full framework in our EU AI Act guide.

This article is an educational explainer, not legal advice. The precise obligations that apply to any given product and AI system depend on the underlying sectoral legislation and the specifics of the deployment; assessing them for a particular case is a task for qualified legal and conformity-assessment advisers.

On this page

  • Who the product manufacturer is
  • The Article 25(3) rule
  • Why the manufacturer becomes the provider
  • The duties that then attach
  • Relationship to the provider and other operators

Share

Product and governance updates — see our privacy policy.

Frequently asked questions

Frequently asked questions

Not in the way it defines provider, deployer, importer, and distributor. The Act names the product manufacturer among the operators of an AI system but gives it no standalone Article 3 definition. Its role is set out functionally in Article 25(3), which explains when a product manufacturer is treated as the provider of an embedded high-risk AI system.

Under Article 25(3), when a high-risk AI system is a safety component of a product covered by the EU harmonisation legislation listed in Annex I, and that product is placed on the market or put into service under the manufacturer's own name or trademark. In that situation the manufacturer is considered the provider of the AI system and takes on the provider's obligations.

The high-risk provider obligations: a risk-management system, technical documentation, data governance, record-keeping, transparency and human oversight, and accuracy, robustness, and cybersecurity. The AI conformity assessment is integrated into the product's existing sectoral conformity procedure rather than carried out as a separate exercise, so it becomes part of a route the manufacturer already follows.

An original developer may still supply the underlying model or system, and contracts usually govern how documentation and information flow along the chain. But toward the market and the authorities, the company that placed the finished product on the market under its own brand answers as the provider of the embedded AI safety component — creating a single accountable party for the whole product.

Natali Craig
Olivia Rhye
Drew Cano

Still have questions?

Can’t find the answer you’re looking for? Talk to our team and we’ll help you get started.

Get in touch

Related terms

Provider (EU AI Act)Glossary

Provider (EU AI Act)

A Provider under the EU AI Act develops an AI system or GPAI model and places it on the market under its own name. Learn the definition, test, and duties.

Read more
Operator (EU AI Act)Glossary

Operator (EU AI Act)

An operator is the EU AI Act's umbrella term for any party in the AI value chain: provider, product manufacturer, deployer, authorised representative, importer, or distributor.

Read more
EU AI Act (Artificial Intelligence Act)Glossary

EU AI Act (Artificial Intelligence Act)

The EU AI Act is the EU's risk-based law for artificial intelligence. A plain-language summary of what it regulates, when it applies, and who must comply.

Read more

See how Qadar AI implements these concepts at runtime

A product specialist will reply within one business day

Book a demo

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·