whitepaper
What the EU AI Act Means for Connected Products
Artificial intelligence is increasingly becoming part of connected products, industrial operations, and digital services. As organisations embed AI into monitoring, automation, and service workflows, they also need to understand how those systems are governed, how decisions are made, and where accountability sits.
For teams building and operating connected products, the EU AI Act matters because it introduces a risk-based framework for AI systems used or placed on the EU market. It does not treat every software capability the same, and it does not apply to every digital feature labelled as “intelligent.”
For many organisations, the key question is not simply whether they use AI. It is whether a specific AI capability in a connected product or service falls within the scope of the Act, what level of risk it creates, and what responsibilities follow from the role the organisation plays in the AI value chain.
Why this matters now
AI is moving from experimentation into everyday operational use. In connected products and industrial environments, it is already being used to support predictive maintenance, anomaly detection, operator assistance, and service optimization.
As these capabilities become more embedded in real-world products, customers increasingly expect visibility into how AI is used, what data supports it, and how outputs can be reviewed or challenged. The EU AI Act responds to that shift by setting harmonised rules for AI and scaling obligations according to risk.
For product, engineering, and operations teams, that means governance can no longer be treated as an afterthought. It needs to be considered alongside product design, deployment, monitoring, and lifecycle management. Building trusted AI isn’t just about meeting regulatory requirements. It’s about creating AI-enabled products that customers are confident adopting.
Is your use case in scope?
One of the first practical questions for any connected product team is whether a feature is actually an AI system under the Act. That matters because the regulation does not apply to every software application or every automated workflow.
Purely deterministic software is generally outside the scope of the legislation. By contrast, systems that infer from inputs to generate predictions, recommendations, decisions, or content may fall within scope, depending on how they function in practice.
For AIoT teams, this is an important distinction. A fixed rules engine used for threshold alerts may be treated very differently from a model that predicts equipment failure, generates operator recommendations, or supports an AI assistant for service teams.
What the risk-based approach means
A central feature of the EU AI Act is its risk-based approach. The higher the potential impact of an AI system on health, safety, or fundamental rights, the more demanding the obligations become.
In practice, that means not every AI use case in a connected product will face the same level of scrutiny. Some applications may trigger transparency obligations, while higher-risk use cases require more extensive governance, documentation, oversight, and controls.
For connected product organisations, the most useful takeaway is simple: governance should be proportionate to the use case. Teams should understand where AI is used, what decisions it supports, what impact it may have, and what safeguards are needed around it.
Why your role matters
Responsibilities under the Act do not depend only on the system itself. They also depend on the role an organisation plays in the AI value chain, including whether it acts as a provider or deployer.
That distinction matters for connected product businesses. An organisation using third-party AI internally may face a different set of responsibilities from one embedding AI into a commercial product or service delivered to customers.
For many platform customers, this is where the discussion becomes practical. Teams need to identify which AI capabilities they use, who owns them, how they are introduced into products or operations, and where accountability sits across product, engineering, legal, and security functions.
To manage these responsibilities, both providers and deployers must support staff AI literacy. Delivering role-specific training ensures teams build a general understanding of AI alongside the context needed for risk-aware operations
What IoT teams should do now?
Preparing for the EU AI Act starts with visibility. Organisations should inventorize AI-related use cases across connected products and services, identify which ones may fall within scope, and assess whether those capabilities influence operational decisions, customer outcomes, or regulated processes.
The next step is to clarify internal responsibilities. Teams should understand whether they are acting mainly as providers, deployers, or both, and ensure that governance, documentation, monitoring, and escalation processes are defined early rather than added later.
This is also where platform capabilities matter. Strong operational visibility, device lifecycle management, traceable data flows, and well-governed integration points can help teams build AI-enabled services with more control and confidence
The product team perspective
Understanding what to look for when adopting AI-enabled products is only one side of the equation. The teams building those products also need to consider how the EU AI Act affects product design, development, governance and lifecycle management.
Our companion white paper, The EU AI Act Explained: What Product Teams Need to Know, explores the regulation from the product team’s perspective, including how to identify AI capabilities that may fall within scope, understand risk and responsibilities, and build governance into the product development lifecycle.
Read the product team’s guide to the EU AI Act
How Cumulocity supports trustworthy AIoT
“At Cumulocity, we believe trusted AI is built — not added later.”
Cumulocity helps organisations develop, deploy, and manage connected products and AI-enabled services on an enterprise-grade AIoT platform. Its positioning around connected asset management, AI-ready data, and operational visibility aligns well with the needs of teams that want to scale AIoT responsibly
For customers preparing for the opportunities and responsibilities created by the EU AI Act, the most relevant platform value is not “compliance” in isolation. It is the ability to build connected products on a foundation of visibility, control, lifecycle management, and data governance that supports trustworthy AI in practice.
The organisations best placed to benefit from AI will be those that combine innovation with clear accountability. For connected product teams, that means treating governance as part of the product lifecycle from the beginning, not as a separate activity added after deployment.
DISCOVER WHAT CUMULOCITY CAN DO FOR YOUR BUSINESS
Discover how Cumulocity helps organizations connect, manage and scale their AIoT solutions with a demo tailored to your business goals and use case.