MICKAI®ArticlesDoes the EU Cyber Resilience Act …
Article · 21 July 2026

Does the EU Cyber Resilience Act apply to AI products?

Yes for AI shipped as software on the EU market, with reporting duties biting from 11 September 2026.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aicyber resilience acteu regulationon-premise aisoftware security

Yes, if the AI ships as software placed on the EU market. The Cyber Resilience Act, Regulation 2024/2847, covers products with digital elements, and commercial AI software qualifies like any other software. It entered into force in December 2024, its vulnerability and severe-incident reporting duties apply from 11 September 2026, and its main obligations apply from 11 December 2027.

The question matters now because the first of those dates is weeks away. From 11 September 2026 vendors must report actively exploited vulnerabilities and severe incidents, and buyers of AI software should already be asking every vendor on their list how that duty will be met.

What does the Cyber Resilience Act actually cover?

Products with digital elements placed on the EU market in the course of a commercial activity: hardware with software inside it, and software supplied on its own. There is no AI exemption. An AI system supplied as installable software, a model runtime, an inference server or an AI-enabled device is a product with digital elements once it is placed on the market. Software an organisation builds purely for its own use, and never places on the market, sits outside.

When do the CRA duties bite?

Three dates matter.

  • December 2024: the regulation entered into force.
  • 11 September 2026: the reporting duties apply, covering actively exploited vulnerabilities and severe incidents.
  • 11 December 2027: the main obligations apply, including the essential cybersecurity requirements and conformity assessment.

The September date is the operative one for 2026 planning: a vendor with no vulnerability handling process today has weeks, not years, to build one that can report on the clock.

Is SaaS AI inside or outside the CRA?

Largely outside. The CRA regulates products, and a purely remote service is not a product placed on the market; cloud and SaaS offerings sit mainly in NIS2 territory, where obligations attach to essential and important entities rather than to the software artefact itself. Software supplied for installation on customer infrastructure is squarely inside. That asymmetry is worth noticing in procurement: an on-premise AI vendor carries product-level duties the buyer can test directly, while a SaaS AI service owes its duties largely to regulators, out of the buyer's sight.

What CRA duties can a buyer check an on-premise AI vendor against?

Four are directly testable before any deadline arrives.

  • Secure-by-default configuration: the software installs in a hardened state, not with sample credentials and open ports.
  • A vulnerability handling process: a published route to receive reports, triage them and ship fixes.
  • Security updates for the support period: patches supplied for a defined period, stated up front.
  • A software bill of materials: the vendor can produce an SBOM listing the components inside what it ships.

A vendor that cannot answer these four today will struggle to meet the main obligations by December 2027, and a struggling vendor is supply-chain risk with a countdown attached.

How does the CRA relate to the EU AI Act?

They are separate instruments, and the interplay is easy to overstate. The AI Act governs how AI systems are classified, governed and used; the CRA governs the cybersecurity of products with digital elements. Where both apply, the CRA supplies the cybersecurity requirements for high-risk AI systems that are products with digital elements, so a vendor does not face two competing cyber regimes over the same product. A buyer should track the two separately: AI Act status answers what the system may be used for, CRA status answers whether the shipped software is securely built, maintained and patched.

How does a vendor prove update integrity inside your perimeter?

This is where the CRA meets sovereignty. Security updates only reduce risk if the operator can verify that what was installed is exactly what the vendor shipped, and that nothing else changed on the way in. We build Mickai, a Sovereign Intelligence Operating System, to run offline on operator-owned hardware: updates arrive as signed artefacts through a controlled inbound perimeter, and every installation is itself an audited event, sealed to a post-quantum signed audit ledger under FIPS 204, the primary post-quantum digital signature standard. The operator can prove, entirely offline, which versions ran when and that every change was authorised. The CRA obliges vendors to maintain their software securely; a sealed ledger turns that obligation into evidence the buyer holds rather than a promise the buyer stores.

The Cyber Resilience Act turns vendor security hygiene from a marketing claim into a duty a buyer can check.

The wider architecture, including the inbound perimeter and the sealed ledger, is described at /sovereign-ai, and the film at /film shows the system in operation.

Frequently asked questions

Does the CRA apply to AI software my company builds for internal use?

Generally no. The CRA attaches to products with digital elements placed on the EU market in the course of a commercial activity, and software developed and used purely internally is not placed on the market. The analysis can change where software is supplied to group companies or to customers, so the boundary deserves proper advice rather than assumption.

Is my AI SaaS subscription covered by the Cyber Resilience Act?

Mostly no. Purely remote services sit largely outside the CRA and in NIS2 territory instead, where duties fall on essential and important entities. Components of the service supplied for installation on the customer's infrastructure, such as agents or connectors, can be inside the CRA, so mixed deployments need both lenses applied.

What should I ask my on-premise AI vendor before September 2026?

How they will report actively exploited vulnerabilities and severe incidents from 11 September 2026, whether the default configuration is hardened, how long the security-update support period runs, and whether an SBOM can be produced on request. The quality of those answers is a fair proxy for readiness for the main obligations in December 2027.

Do UK AI vendors have to comply with the CRA?

Yes, where they place products on the EU market. The CRA applies by market, not by vendor nationality, so a UK vendor supplying installable AI software into the EU carries the same duties as an EU vendor. For UK vendors the practical trigger to test is EU-market exposure, product by product.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/does-the-eu-cyber-resilience-act-apply-to-ai-products. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles