EU Cyber Resilience Act: Mandatory Incident Reporting Kicks In September 11

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-09-02 | By: Carlos Montiel | Reading time: ~5 min

Fewer than 100 days remain until September 11, 2026 — the date Article 14 of the EU's Cyber Resilience Act (CRA) takes effect, imposing mandatory reporting of cybersecurity vulnerabilities and incidents. It arrives well ahead of the CRA's full applicability in 2027, and it already covers software with AI components.

What Article 14 actually requires

The CRA sets up a two-track reporting regime for manufacturers of "products with digital elements" — a broad category that explicitly includes software, and software with AI functionality. If a manufacturer becomes aware that a vulnerability in its product is being actively exploited, it must notify ENISA (the EU's cybersecurity agency) and the relevant member state's CSIRT within 24 hours. The same 24-hour window applies if it becomes aware of a severe incident affecting the product's security.

Mandatory timeline under Article 14: - 24 hours: early warning notification to ENISA/CSIRT - 72 hours: follow-up report with a more detailed assessment - 1 month (incidents) / 14 days after mitigation (vulnerabilities): final report

Who's covered

The obligation falls on manufacturers that place products with digital elements on the EU market — which includes software vendors that embed AI models as part of their product, not just the labs that train the underlying models. If your company sells or distributes AI-enabled software to customers in the EU, this obligation likely applies to you directly, even if you're not the one training the model underneath.

Why this is more urgent than it sounds: a 2026 enterprise survey found that 88% of organizations experienced a confirmed or suspected AI agent security incident in the prior year. Recent public vulnerabilities in agent infrastructure — including a remote code execution flaw in widely used MCP infrastructure — show the risk this regulation targets is real and active, not hypothetical.

What a company should have ready before the deadline

Meeting a 24-hour deadline in practice requires having the process built ahead of time, not improvised when the incident happens: an active vulnerability-detection channel (bug bounty, monitoring relevant CVEs for your AI stack), a clear decision chain for who determines whether something qualifies as "active exploitation," and a ready report template so you're not drafting one under pressure during the critical first hours.

For Latin American companies with EU customers: if your AI-enabled software product has users in Europe, this obligation can apply to you regardless of where you're headquartered — the CRA's test is where the product is placed on the market, not where the manufacturer operates. Worth checking now, not in October, whether your company falls within scope.
Carlos Montiel
Enterprise AI Solutions Architect
LLMs, Agents & Orchestration Specialist
guatemalia.com/#contacto · info@guatemalia.com

Need to implement AI in your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com