Fewer than 100 days remain until September 11, 2026 — the date Article 14 of the EU's Cyber Resilience Act (CRA) takes effect, imposing mandatory reporting of cybersecurity vulnerabilities and incidents. It arrives well ahead of the CRA's full applicability in 2027, and it already covers software with AI components.
The CRA sets up a two-track reporting regime for manufacturers of "products with digital elements" — a broad category that explicitly includes software, and software with AI functionality. If a manufacturer becomes aware that a vulnerability in its product is being actively exploited, it must notify ENISA (the EU's cybersecurity agency) and the relevant member state's CSIRT within 24 hours. The same 24-hour window applies if it becomes aware of a severe incident affecting the product's security.
The obligation falls on manufacturers that place products with digital elements on the EU market — which includes software vendors that embed AI models as part of their product, not just the labs that train the underlying models. If your company sells or distributes AI-enabled software to customers in the EU, this obligation likely applies to you directly, even if you're not the one training the model underneath.
Meeting a 24-hour deadline in practice requires having the process built ahead of time, not improvised when the incident happens: an active vulnerability-detection channel (bug bounty, monitoring relevant CVEs for your AI stack), a clear decision chain for who determines whether something qualifies as "active exploitation," and a ready report template so you're not drafting one under pressure during the critical first hours.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel