DEV Community

Multigrid
Multigrid

Posted on Originally published at multigrid.ai

The General Product Safety Regulation and AI-Enabled Consumer Products

Most AI-enabled consumer products are not high-risk AI systems and never will be. A smart speaker, a toy with a conversational feature, a companion app for a treadmill: none of them appears in Annex III of the AI Act. They are still regulated, and the instrument that regulates them is the General Product Safety Regulation.

When the GPSR is the instrument that applies

Regulation (EU) 2023/988 was adopted on 10 May 2023 and has applied since 13 December 2024, replacing the 2001 General Product Safety Directive. The text is at EUR-Lex, ELI reg/2023/988.

It is a safety net, and Article 2 says so structurally: it applies to products placed or made available on the market insofar as there are no specific provisions with the same objective in Union harmonisation legislation. If a sectoral regime — the Machinery Regulation, the Toy Safety rules, the Radio Equipment Directive, the Medical Devices Regulation — covers the risk, that regime governs it. Where it does not, or where a product has a risk its sectoral regime never contemplated, the GPSR fills the space.

That is why it matters for AI. A consumer product with a generative feature frequently has a risk profile nobody wrote a harmonised standard for: a toy that improvises speech, an appliance that acts on a spoken instruction it misheard, an assistant that gives a confident and wrong answer about a dosage or a household chemical. Even where sectoral rules apply to the hardware, the GPSR’s market surveillance, recall and Safety Gate chapters continue to apply to products covered by harmonised legislation where that legislation contains no equivalent provisions.

Whether a specific product falls under the GPSR, a sectoral regime or both is a scoping question with real consequences, and it is not one to settle from a summary. This page is not legal advice; take it on the product.

The safety assessment includes learning behaviour

Article 5 states the general obligation: economic operators shall place or make available on the market only safe products. Article 6 then lists the aspects taken into account in assessing whether a product is safe, and two of them were added for exactly this class of product.

One is appropriate cybersecurity features, where required by the nature of the product, to protect it against external influences including malicious third parties where such influence might have an impact on the safety of the product. The other is the evolving, learning and predictive functionalities of the product. That second limb is short and it does a great deal of work: it means a product whose behaviour changes after purchase is assessed on the behaviour it can develop, not only on the behaviour it shipped with.

Article 6 also requires attention to the categories of consumers at risk when using the product, in particular vulnerable consumers including children, the elderly and persons with disabilities. For a conversational product aimed at or reachable by children this is the operative clause, and it is the one that connects a prompt-injection or jailbreak result — ordinarily discussed as a security bug — to a product safety obligation.

What a manufacturer must actually do

  • Internal risk analysis and technical documentation. Article 9 requires manufacturers to carry out an analysis of the risks of the product and to draw up technical documentation containing at least a general description of the product and its essential characteristics relevant for assessing safety. It must be kept available for ten years and produced to authorities on request.
  • Identify the product and yourself. Type, batch or serial number and manufacturer contact details on the product or its packaging. For software-defined products this obligation is routinely met badly — a version identifier that lets you tie an incident to a build is the point of it.
  • Investigate complaints and keep a register. Manufacturers must investigate complaints concerning safety, keep a register of complaints, recalls and corrective measures, and keep distributors informed. A stream of reports that the assistant said something unsafe is a safety complaint, not a support ticket.
  • A responsible person in the Union. A product may not be placed on the market unless there is an economic operator established in the Union responsible for compliance tasks — the provision that catches non-EU sellers shipping direct to consumers.

Accidents, recalls and the Safety Gate

Article 19 requires a manufacturer who knows, on the basis of available information, that a product it has placed on the market has caused an accident to notify the authorities of the member state where the accident occurred, without undue delay, through the Safety Business Gateway. The duty is triggered by an accident, not by a lawsuit and not by press coverage.

Where a product is dangerous, corrective measures follow, up to recall. The GPSR is unusually prescriptive about how a recall is communicated: the recall notice must reach affected consumers directly where the operator holds their details, must be clearly headed as a safety recall, must not use language that minimises the risk, and must offer an effective remedy — repair, replacement or refund — with at least two options open to the consumer. A refund offered only as store credit does not satisfy it.

For a connected product, a recall may in practice mean disabling a feature over the air. That is fast, and it is also a product change made to every unit in the field, which is worth thinking about against the liability regime described in the revised Product Liability Directive, where an update under the manufacturer’s control extends the window in which defectiveness is judged.

Running alongside the AI Act

The mental model people arrive with is a hierarchy, with the AI Act on top. It is not one. The AI Act regulates AI systems by risk class and places obligations on providers and deployers of those systems. The GPSR regulates consumer products by safety and places obligations on economic operators in the supply chain. A single device can be subject to both, to one, or — if it is a professional product with no consumer market and no Annex III use — to neither.

Two practical consequences. First, a product outside the scope of the AI Act’s high-risk rules is not unregulated, and “we checked, it is minimal risk” is not a compliance conclusion — the risk tiers answer a narrower question than most readers think. Second, the GPSR’s accident notification runs on a different trigger and a different clock from the AI Act’s serious incident reporting for high-risk systems; a company subject to both needs one intake process capable of firing either, which is what serious incident reporting covers on the AI Act side.

Related

Top comments (0)