AI Act vs CRA: what they share and how they differ

AI Act and CRA share 5 of 24 control themes and 8 checks. 80% of CRA requirements can be proven with checks AI Act already uses, 27% the other way round.

EURegulationPhasing in

AI Act

How to make an AI system compliant with the EU AI Act

33 requirementsNext Aug 2, 2027
EURegulationPhasing in

CRA

How an AI product complies with the Cyber Resilience Act

5 requirementsNext Dec 11, 2027
5/24shared control themes
8shared checks
80%of CRA requirements covered by AI Act evidence
27%of AI Act requirements covered by CRA evidence

At a glance

AI Act CRA
JurisdictionEuropean Union sameEuropean Union same
KindRegulation sameRegulation same
StatusPhasing in samePhasing in same
BindingYes sameYes same
Object analysedAI systemDigital product
ScopeProviders, deployers, importers and distributors of AI systems; providers of GPAI models.Manufacturers, importers, distributors of digital products.
Territorial reachExtraterritorial: applies when the system is placed on the EU market or its output is used in the EU.Products placed on the EU market.
PenaltiesUp to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).Up to €15M or 2.5% of worldwide turnover.
Qualification axesAI Act risk level, Organisation role, General-purpose modelProduct class
RolesProvider, Deployer, GPAI providerManufacturer, Importer
Requirements335
Next milestoneAug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025Dec 11, 2027, Full application

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

8

CodeCheckRequirements AI ActRequirements CRA
VER-005-01Complete technical documentation compliant with Annex IV
VER-007-01Instructions for use complete and compliant with Art. 13
VER-009-03Cybersecurity of the AI system verified
VER-AUTO-03EU declaration of conformity drafted
VER-016-F-01CE marking affixed in accordance with Art. 48
VER-022-F-01Risk and incident response procedure
VER-024-F-01Conformity assessment procedure performed (Annex VI or VII)
VER-009-F-04Resilience to adversarial attacks tested

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

AI Act

24

EX-001
EX-003
EX-008
EX-010
QMS Art. 17
EX-011
EX-013
EX-019
DPIA Art. 26§9
EX-020
FRIA Art. 27
EX-023
Accessibility Art. 16(l)
EX-026
Value chain Art. 25
EX-027
Compliant use Art. 26§1
EX-028
Input data Art. 26§4
EX-031

Timelines

PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Dec 10, 2024CRA · Entry into force
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
Jul 10, 2025AI Act · GPAI Code of Practice published
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Jun 11, 2026CRA · Conformity assessment bodies
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Sep 11, 2026CRA · Reporting obligations (vulnerabilities, incidents)
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Dec 11, 2027CRA · Full application
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo