← Writing

Note

The EU compliance cliff

Three 2026 deadlines define the rest of the year for anyone shipping AI into the EU. Treat the AI Act and the CRA as one engineering problem, not two compliance projects.

The EU compliance cliff is 72 days away. Is your team ready for what the AI Act and the CRA will actually require?

Three 2026 deadlines define the rest of the year for anyone shipping AI into the EU:

  • Aug 2, 2026 — most of the AI Act applies. Conformity assessments, post-market monitoring, fundamental rights impact assessments, transparency obligations, GPAI rules.
  • Sept 11, 2026 — CRA vulnerability reporting goes live. Every product with digital elements on the EU market, legacy products included.
  • Dec 2, 2026 — synthetic content watermarking under the AI Act.

The CRA reporting cadence is the part most security teams haven’t internalised. 24h early warning to ENISA and your national CSIRT. 72h full notification. 14d final report. The clock starts at discovery, not at convenience, and most teams don’t have a tested 24h pipeline yet.

For anyone shipping AI in a product into the EU, both acts apply. They were written by different parts of the Commission with different vocabularies, but the engineering work overlaps heavily. Threat modelling, logging, incident response, technical documentation, post-market monitoring — all show up in both.

The thesis is simple: treat the AI Act and CRA as one engineering problem, not two compliance projects. Build the controls once and map the evidence into both audits. Teams that do this work in the next 90 days will be in a far better position than those who don’t.

The brief, in full

The eleven-slide version — timelines, role-split actions, the 24/72/14 cadence, and the AI Act × CRA overlap map:

Slide 1 — The 2026 EU Compliance Cliff (title).
Slide 2 — the two regulations at a glance.
Slide 3 — the 2026 deadline timeline.
Slide 4 — AI Act obligations.
Slide 5 — role-split actions: if you build AI vs if you deploy AI.
Slide 6 — the Cyber Resilience Act.
Slide 7 — the 24 / 72 / 14 reporting cadence.
Slide 8 — CRA actions.
Slide 9 — the AI Act × CRA overlap map.
Slide 10 — build the controls once, map to both audits.
Slide 11 — closing / summary.

↓ Download the deck (PPTX)

Where is your team positioned for the upcoming regulatory deadlines, and how are you preparing?