Hey developers! Ever heard of the EU Cyber Resilience Act (CRA)? If you're building AI applications or agents that might hit the European market, this is something you absolutely need to pay attention to. It's not just another piece of legal jargon; it's a game-changer for how we approach security in AI.
Here's the deal: if your AI product has digital elements and is available in the EU, the CRA applies to you. And while the full provisions kick in by December 2027, a crucial part, vulnerability reporting, starts much sooner, on September 11, 2026. This means even for products already out there, you'll need to report actively exploited vulnerabilities within 24 hours.
Think about it: if an attacker uses a clever prompt injection against your LLM-powered agent right now, would you even know? And if you did, could you generate a detailed report in just 24 hours? For many AI products, the honest answer is probably no. The CRA was designed with traditional software in mind, and AI systems introduce some unique challenges that break those old assumptions.
What the CRA Really Asks From AI Systems
The CRA's core requirements are laid out in Annex I, covering both product features and manufacturer processes. It's all about making products







