Companies adding artificial intelligence to software and connected products will face new cybersecurity reporting requirements in the European Union from 11 September 2026, adding another layer of regulatory responsibility to the rapid adoption of AI across business applications.
The issue is becoming increasingly relevant as companies incorporate generative AI and other models into existing products, either through commercial application programming interfaces or publicly available models. While adding AI functionality has become technically straightforward, the resulting product can introduce new security dependencies and, in some circumstances, bring the company integrating the technology within the manufacturer obligations of the EU Cyber Resilience Act.
Under the CRA, a business that incorporates an AI model into a product with digital elements and markets that product under its own name can be responsible for meeting the regulation’s cybersecurity requirements. Companies making substantial modifications to products already on the market can also assume manufacturer responsibilities.
The implications extend beyond the AI model itself. Open-source models can introduce vulnerabilities through compromised files, dependencies or unsafe code, while externally hosted commercial models create different risks associated with their integration and reliance on third-party infrastructure.
Security researchers have demonstrated that apparently legitimate AI model files can contain malicious code capable of executing when a model is loaded. The source article cites research identifying around 100 malicious models on a major AI repository and approximately 350,000 unsafe or suspicious findings detected by a scanning partner across models examined on the platform.
Commercial AI services can reduce some of these risks by keeping the model outside the customer’s own infrastructure, but they introduce others. Applications processing emails, websites and documents can be vulnerable to indirect prompt injection, where malicious instructions embedded within external content influence an AI system and potentially cause unintended actions or disclosure of information.
Reliance on external AI providers can also create operational dependencies. Changes to models, interfaces or behaviour may alter assumptions on which an application’s security controls were originally designed, while outages or compromises affecting the provider can have consequences for products built around its services.
The regulatory timetable makes these issues increasingly immediate.
Most provisions of the Cyber Resilience Act become applicable on 11 December 2027, when manufacturers of covered products will face requirements concerning cybersecurity risk assessment, secure product development, vulnerability management, technical documentation and conformity procedures.
Certain reporting obligations arrive considerably earlier. From 11 September 2026, manufacturers will begin facing mandatory notification requirements concerning actively exploited vulnerabilities and severe security incidents affecting covered products.
For actively exploited vulnerabilities, manufacturers must provide an early warning through the CRA reporting mechanism without undue delay and, in any event, within 24 hours of becoming aware of the vulnerability. A more detailed vulnerability notification follows within 72 hours, while a final report is generally required within 14 days after a corrective or mitigating measure becomes available.
The timetable for severe incidents is similar but not identical, making it important that businesses establish procedures around the precise type of event rather than treating every CRA notification as following one universal reporting sequence.
The practical challenge is therefore not simply detecting a vulnerability. Companies need to establish which AI models and other software components are embedded within their products, their origins and versions, how they have been modified and who is responsible for escalating a security event when it occurs.
This becomes more complicated when products depend on multiple external components. Manufacturers cannot necessarily transfer regulatory responsibility simply because a vulnerability originated in third-party or open-source software incorporated into their own commercial product.
AI makes maintaining this visibility particularly important. Models can be replaced, updated or fine-tuned during a product’s lifetime, while the surrounding software can contain libraries, APIs and other dependencies that change independently. Maintaining an accurate inventory of these components will therefore become an increasingly important part of cybersecurity governance.
The CRA’s broader requirements will eventually reinforce this approach through lifecycle vulnerability management and technical documentation. Software bills of materials can help companies identify dependencies when a vulnerability emerges, while AI products may require similarly detailed records covering models and associated components.
The potential financial consequences are substantial. For breaches of some of the CRA’s principal requirements, penalties can reach EUR 15 million or 2.5% of worldwide annual turnover for the preceding financial year, whichever is higher, although the applicable maximum depends on the particular infringement.
For businesses rapidly adding AI features to existing products, the immediate question is therefore shifting from whether AI can improve functionality to whether the organisation understands the additional security architecture and regulatory responsibilities that accompany it.
With the first CRA reporting requirements taking effect on 11 September, companies operating in the EU have only a short period remaining to establish who monitors vulnerabilities, how incidents are assessed, which products are affected and who is authorised to make regulatory notifications.
The growing use of AI does not fundamentally change the principle behind the Cyber Resilience Act: companies placing digital products on the European market are expected to understand and manage their cybersecurity risks throughout the product lifecycle.
What AI changes is the complexity. A product can now depend on models, datasets, external services and software components that may evolve long after its initial release. For companies embracing AI across their product ranges, keeping track of those dependencies is becoming as important as adding the AI functionality itself.
Source: CMS