The EU AI Act and Chinese-made products: what applies now, what waits until 2028
Chinese factories put “AI” on the spec sheet because it sells, and compliance newsletters put 2 August 2026 in the subject line because it was the date the EU AI Act became fully applicable. Six days before that date, Brussels moved the rules that would have caught goods — and left in force the one obligation that catches almost everyone.
Direct answer: The EU AI Act’s high-risk rules do not touch AI inside imported products until 2 August 2028. Regulation (EU) 2026/1744, in force 27 July 2026, moved them there. What applies now is Article 50 transparency: an AI system that interacts with a person, or that generates content, has to say that it is AI. Penalties for breaching it reach €15 million or 3% of worldwide turnover.
What changed six days before the deadline
The AI Act entered into force on 1 August 2024 with its obligations staged over four years. 2 August 2026 was the date the bulk of it applied, including the high-risk requirements for the standalone systems listed in Annex III. AI built into regulated products — machinery, toys, lifts, medical devices — was to follow on 2 August 2027.
Neither date survived. On 24 July 2026 the Official Journal published Regulation (EU) 2026/1744, the Digital Omnibus on AI. It entered into force on 27 July 2026, six days before the deadline it moved, and amended 42 articles of the Act. The stated reason was infrastructure rather than politics: the harmonised standards the high-risk regime assumes, and the conformity-assessment bodies meant to apply them, were not going to exist in time.
| High-risk category | Was | Now |
|---|---|---|
| Annex III — standalone systems: biometrics, employment, education, essential services, law enforcement | 2 August 2026 | 2 December 2027 |
| Annex I — AI embedded in products covered by EU product legislation | 2 August 2027 | 2 August 2028 |
If you import physical goods, the second row is your row, and it bought you two years.
A deferral is not a repeal, and three things did not move. The prohibited practices in Article 5 have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Article 50 transparency applied on 2 August 2026 and still does — with a short grace period to 2 December 2026 for marking the output of synthetic-content systems that were already on the market. The penalty tiers were not touched either.
Who owes what — and who you become if you rebrand
The Act allocates duties by role, and the roles are defined in Article 3 rather than by what feels commercially true. This is where buyers misplace themselves.
| Role | Who it is | What it carries |
|---|---|---|
| Provider | Whoever develops an AI system, or has one developed, and places it on the market under their own name or trademark | The heavy end: conformity assessment, technical documentation, registration, post-market monitoring — and the Article 50 transparency duties, which are not limited to high-risk systems |
| Importer | A person established in the EU who places on the market a system bearing the name or trademark of a third-country person | Under Article 23: verify the conformity assessment was done, the technical documentation exists, the CE marking and EU declaration of conformity are present, and the provider has appointed an authorised representative. Keep the documents for ten years |
| Distributor | Anyone else in the chain making the system available | Check the marking and documentation are there before passing it on |
| Deployer | Whoever uses the system under their own authority, professionally | Use it as instructed; disclose emotion recognition and deep fakes under Article 50(3) and 50(4) |
| Authorised representative | An EU-established mandate holder for a third-country provider | Required by Article 22 only for providers of high-risk systems — and not before December 2027 or August 2028 |
The private-label trap, in a second regulation. Read the importer definition again: it describes someone placing goods on the market that bear somebody else’s trademark. Put your own brand on a Chinese-made device and that sentence stops describing you. You are the provider, and you have taken on the obligations you thought you were buying away from. It is the same trap that catches private-label buyers under the Digital Product Passport, and it catches the same people. See also who is the importer of record?, which is a different question with a similar answer.
What applies, and when
| Date | What applies | Does it reach imported goods? |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5); AI literacy (Article 4, since rewritten as a duty to support literacy rather than guarantee it) | Rarely. Article 5 bans manipulation, exploitation of vulnerability and social scoring — not ordinary consumer electronics |
| 2 August 2025 | General-purpose AI models; governance; the penalty regime | No, unless you place a model on the market yourself |
| 2 August 2026 | The rest of the Act, including Article 50 transparency | Yes. This is the live obligation today |
| 2 December 2026 | Machine-readable marking under Article 50(2) for synthetic-content systems already on the market; the new prohibition on image-manipulation systems added by the omnibus | Yes, if the product generates text, images, audio or video |
| 2 December 2027 | High-risk requirements for Annex III standalone systems | Seldom — this is software sold as software |
| 2 August 2028 | High-risk requirements for AI embedded in Annex I products | Yes. This is the date for machinery, toys, lifts, radio equipment, PPE and medical devices |
Article 50 is worth reading properly, because it is short and it is the part that is already in force. Providers must ensure a system designed to interact directly with people tells them it is AI, unless that is obvious to a reasonably well-informed person. Providers must mark synthetic output in a machine-readable format. Deployers must disclose emotion recognition, biometric categorisation and deep fakes. The disclosure has to arrive at the first interaction, in a clear and distinguishable form.
Translated into a shipment: a talking doll, a companion device, a display that answers questions, an appliance with a voice assistant. If a person will talk to it and it will answer, something on or in that product has to say it is AI — in the packaging, the interface, or the first thing it says.
The high-risk test most summaries get wrong
Almost every summary of the Act says AI in toys, lifts and medical devices is high-risk. Read as written, that is wrong, and it is the error that drives buyers into work they do not need.
Article 6(1) sets two conditions, and both must be met:
- the AI system is a safety component of a product, or is itself a product, covered by the EU product legislation listed in Annex I; and
- that product is required to undergo third-party conformity assessment under that same legislation before it can be placed on the market.
Most products in Annex I self-certify. Machinery outside the specifically listed categories self-certifies. Class I medical devices self-certify. A toy self-certifies where the harmonised standards are applied in full. Where the product self-certifies, the AI inside it is not high-risk by this route — the first condition is met and the second is not.
| Annex I, Section A — the New Legislative Framework instruments |
|---|
| Machinery · toys · recreational craft and personal watercraft · lifts and safety components · equipment for potentially explosive atmospheres · radio equipment · pressure equipment · cableway installations · personal protective equipment · appliances burning gaseous fuels · medical devices · in vitro diagnostic medical devices |
Section B adds vehicles, rail, marine equipment, civil aviation and unmanned aircraft, where the AI Act’s requirements are folded into the sectoral regimes rather than applied directly.
The conformity route decides the AI question, not the other way round. Before anyone asks whether the AI is high-risk, settle whether the product needs a notified body. That is an ordinary product-compliance question you can answer from the harmonised standards and your existing test reports — and it disposes of the AI question for most consumer goods in an afternoon. Whether the certificates you were sent are real is a separate exercise, and a more productive one.
Toys deserve a note of their own, because two rules are converging on them. The AI Act’s high-risk route reaches an AI toy only when the toy needs third-party assessment. The new Toy Safety Regulation — in force since January 2026, applicable from 1 August 2030 — takes a different route to the same product, requiring connected and AI-enabled toys to be assessed for effects on mental health and cognitive development. Neither date is urgent. Both are on the same product, and the second one is not a compliance question a factory in Chenghai has heard of yet.
“It has AI” — what that means on a Chinese spec sheet
The word on the datasheet is usually 智能, and it translates as “smart” at least as often as “intelligent”. A 智能 kettle has a thermostat. A 智能 lock has a fingerprint reader and a lookup table. Neither is an AI system, and no amount of reading the AI Act will tell you which one you have bought — that answer is in the factory.
The definition in Article 3(1) turns on inference: a machine-based system that, for explicit or implicit objectives, infers from its input how to generate outputs such as predictions, content, recommendations or decisions. The Commission’s guidelines of 6 February 2025 put simple deterministic rules, basic statistical estimators and plain data visualisation outside it. Most “AI” on an Alibaba listing is outside it too.
Three questions settle it, and all three are supplier questions rather than legal ones:
- Does it infer, or does it look up? A threshold, a rule table and a fixed decision tree are not inference. A model that was trained on data is.
- Where does the model run, and whose is it? On the device, on your server, on the factory’s server, or against a third-party model API in China. The last answer is common and it is the one that matters most, because it turns a product question into a data-transfer question and a service-continuity question at the same time. Get the name of the model provider in writing.
- Does it change after it ships? Over-the-air model updates mean the thing you assessed is not the thing in the customer’s hands six months later. That is a different compliance object, and a different conversation with your insurer.
Marketing copy is not evidence in either direction. A listing says AI because AI sells; a datasheet may omit it because the engineer who wrote it does not think a keyword-spotting model is worth mentioning. Ask the factory, and ask about behaviour rather than labels.
Who actually enforces this
The Act is enforced by national market surveillance authorities, and until member states named them, “the EU will enforce it” was an empty sentence. Germany has now named them, and its allocation is worth reading because it tells an importer who will actually knock.
The KI-MIG — the AI market surveillance and innovation promotion act — came into force on 29 July 2026. It makes the Bundesnetzagentur the central coordinating authority (§ 5) and the single national contact point (§ 6). But it deliberately does not create one AI regulator:
- § 2(2) leaves the existing product market surveillance authorities competent for AI within harmonised product legislation — machinery, medical devices, and the rest of Annex I.
- § 2(3) names BaFin for AI systems used in direct connection with a regulated financial activity, across some twenty-five categories of supervised institution.
- § 2(6) assigns state-level authorities for public bodies deploying AI, and § 2(8) the state media authorities for journalistic and advertising uses.
For a buyer importing goods, that is a useful result: the authority with your file is the product market surveillance authority you already deal with, not a new agency with a new inbox. The BaFin designation gets the headlines, and it is irrelevant to anyone shipping consumer goods.
| Breach | Ceiling |
|---|---|
| Prohibited practices (Article 5) | €35 million or 7% of total worldwide annual turnover, whichever is higher |
| Other operator obligations — including Article 50 transparency | €15 million or 3% |
| Supplying incorrect or misleading information to authorities | €7.5 million or 1% |
The omnibus did not change these. As with product compliance generally, the fine is rarely the real exposure: goods that cannot lawfully be made available are goods sitting somewhere, and a held container costs a season.
The other direction: selling AI into China
China did not write one AI act. It wrote a stack of instruments, and the parts that reach a foreign company are not the parts that get discussed.
| Instrument | In force | Whether it reaches you |
|---|---|---|
| Amended Cybersecurity Law — adopted 28 October 2025, first revision since 2017 | 1 January 2026 | Background. A new Article 20 puts AI into the foundational statute and raises penalty ceilings across the board |
| Measures for Labeling AI-Generated Synthetic Content, with a mandatory national standard | 1 September 2025 | Directly. AI-generated text, images, audio or video published on Chinese platforms needs a visible label and a machine-readable one. It catches your marketing, not your product |
| Interim Measures for Generative AI Services | 15 August 2023 | If you offer a generative service to the public in mainland China, wherever you are established |
| Interim Measures on AI anthropomorphic interactive services — CAC, promulgated 10 April 2026 | 15 July 2026 | If your product or app provides continuous emotional interaction. No virtual-companion services to under-18s at all; parental consent under 14; a mandated minor mode |
| AI Technology Ethics Review and Services Measures (Trial) — MOST, MIIT and eight other departments, issued 2 April 2026 | — | Reaches AI research and development carried out in China. That is your ODM, not you — but it is now their cost and their timeline |
The labelling rule is the one that quietly catches Western companies, because it applies to content rather than to goods. If any part of your Chinese-language marketing is AI-generated — product imagery, a synthetic voiceover, a 小红书 post drafted by a model — it needs to be labelled on the way out, and the platform is required to check. That is a marketing operations problem with a regulatory deadline attached, and it has been live since September 2025.
The anthropomorphic-services measures deserve attention from anyone in the AI companion category, which is currently one of the fastest-moving product lines coming out of Shenzhen and Chenghai. A device built for the Chinese market since 15 July 2026 has an age gate and a minor mode designed in. A device built for export may not — and the EU is arriving at children and AI from the opposite direction, through toy safety. The same factory is being asked for two different things by two regulators who have not read each other.
How to ask a Chinese supplier about the AI in the product
None of this is exotic. It is the difference between a question the factory can answer and a question that produces 是的.
- Ask about behaviour, not about categories. “Does the device change what it does based on data it collects?” gets a real answer. “Is this a high-risk AI system under Regulation 2024/1689?” gets agreement, because agreement is what a sales manager is for.
- Settle the conformity route first. Does the product need a notified body under its own product legislation? Answer that and you have usually answered the high-risk question too.
- Establish where the model runs and whose it is. On-device, your cloud, their cloud, or a third-party Chinese API. Ask for the provider’s name, and ask what happens to the product if that provider withdraws the endpoint.
- Ask what changes after shipping. Firmware updates, model updates, feature flags. Get it in writing whether the shipped configuration can change without your approval.
- Put it in the purchase contract, not in a questionnaire. A supplier disclosing its own product information under an agreed clause is doing something different from a foreign buyer running an investigation — a distinction that has become its own live issue in China. Build the AI questions into the specification annex, next to tolerances and packaging.
- Check which entity would sign. Declarations have to sit with the actual manufacturer. If the company you are buying from is registered for wholesale rather than manufacturing, its declarations will not survive scrutiny — see is my supplier a factory or a trading company?
- Record what you were not told. A documented “we don’t know” is a finding you can act on. An assumption written into a technical file is not.
- If you are rebranding it, budget for being the provider. Not in 2028 — in the quarter you decide, because it changes what you need from the factory and what you have to get into the contract.
Most of these questions fail not because the factory refuses but because they arrive in English, in a spreadsheet, addressed to a sales account rather than to engineering. Put to the right person in Mandarin, with the reason attached, they are ordinary questions with ordinary answers — which is the whole premise of briefing a supplier properly.
Quick FAQ
Does the EU AI Act apply to products I import from China?
It applies to AI systems placed on the EU market wherever they were made, so a Chinese-made product containing an AI system is in scope. Very little of it bites yet. The high-risk requirements for AI embedded in regulated products were deferred to 2 August 2028. What applies from 2 August 2026 is Article 50 transparency.
My supplier says the product has AI. Is it a high-risk AI system?
Probably not. Article 6(1) requires two things at once: the AI must be a safety component of, or itself be, a product covered by the Annex I product legislation, and that product must be required to undergo third-party conformity assessment. Most Annex I products self-certify, and where the product self-certifies the AI inside it is not high-risk by that route.
Do I need a separate CE mark for the AI in the product?
No. The AI Act does not add a second CE mark to a product that already carries one. CE marking obligations under Article 48 attach to high-risk AI systems, and where the AI sits inside a product already CE-marked under Annex I legislation, it is that product’s marking, declaration of conformity and technical documentation that carry it — and not before 2 August 2028.
Does my Chinese supplier need an EU authorised representative?
Only if they are the provider of a high-risk AI system. Article 22 applies to third-country providers of high-risk systems and to nobody else, and it does not apply until 2 December 2027 for standalone Annex III systems or 2 August 2028 for AI embedded in Annex I products. A blanket claim that every Chinese exporter now needs one is wrong.
What if I sell the product under my own brand?
Then you are likely the provider rather than the importer. Article 3 defines an importer as someone placing on the market a system bearing the name or trademark of a third-country person — put your own trademark on it and that definition stops describing you, and the provider obligations start. This catches private-label and marketplace sellers routinely.
Do China’s AI rules apply to my company?
Three of them might. The labelling measures in force since 1 September 2025 catch AI-generated content you publish on Chinese platforms, including marketing. The generative-AI measures catch services offered to the public in mainland China wherever the provider sits. The ethics-review measures reach AI research and development carried out in China — which is your ODM, not you.
What is the single thing worth doing this quarter?
Work out which of your products contain something that actually infers rather than something marketing calls 智能, and which Chinese legal entity would have to sign a declaration about it. Every problem further down this road is a version of not knowing the second answer.
Find out what your supplier actually holds
For one product line and one destination market: the document set an importer is normally asked for, which of those the factory holds today, which are missing, and what they say about the gap. Dated, sourced, and answered on the record in Mandarin.
Sources
- Regulation (EU) 2024/1689 — the AI Act, in force 1 August 2024
- Regulation (EU) 2026/1744 — the Digital Omnibus on AI; published in the Official Journal 24 July 2026, in force 27 July 2026
- EUR-Lex — the AI Act consolidated as amended on 27 July 2026
- European Parliament — committee vote of 18 March 2026 supporting the postponement of the high-risk rules
- European Commission — guidelines on the definition of an AI system, 6 February 2025
- AI Act Article 3 — definitions of provider, deployer, importer and distributor
- AI Act Article 22 — authorised representatives of third-country providers of high-risk AI systems
- AI Act Article 23 — obligations of importers of high-risk AI systems
- AI Act Article 50 — transparency obligations, as amended by the Digital Omnibus
- AI Act Annex I — the product legislation that routes AI into the high-risk category
- KI-MIG — the German AI market surveillance act, in force 29 July 2026; § 2 allocates authorities and § 2(3) names BaFin
- EUR-Lex summary — the new Toy Safety Regulation, applicable from 1 August 2030
- PRC Cybersecurity Law amendments — adopted 28 October 2025, in force 1 January 2026, adding an AI article and raising penalties
- China’s Measures for Labeling AI-Generated Synthetic Content and the accompanying mandatory national standard — both in force 1 September 2025
- CAC Interim Measures on AI anthropomorphic interactive services — promulgated 10 April 2026, in force 15 July 2026
- Measures for the Administration of AI Technology Ethics Review and Services (Trial) — issued 2 April 2026 by MOST, MIIT and eight other departments
This guide is general information, not legal advice. Requirements vary by city, document and personal circumstances — confirm your specific case before acting. Last checked 1 September 2026.