PAPER B · REGULATION

AI Act & CRA: what's due in 2026, what slipped to 2027

KET · 04 — INSIGHTS

Seven weeks

As I write this, two EU deadlines fall within the next seven weeks. A third passed more than a year ago, enforcement is under way, and it's the one people talk about least.

None of them made headlines. All of them are enforceable.

The problem isn't that companies don't know these texts exist — most have heard about them ten times. The problem is that they don't know what applies to them, by when, and what an acceptable proof looks like. Between announced postponements, denied postponements, firms selling urgency and firms selling delay, the calendar has become unreadable. It's that unreadability that costs money, not the texts themselves.

This paper is a dated snapshot. Not a legal analysis: I'm not a lawyer and Keteris never gives legal advice. It's the calendar as an engineer has to read it to know what to build, and in what order.


What's due now

11 September 2026 — CRA: vulnerability reporting

The Cyber Resilience Act (EU Regulation 2024/2847) imposes cybersecurity requirements on every digital product placed on the EU market. Software, SaaS applications, connected objects. The most common confusion is about scope, so let's clear it immediately: the test fits in one sentence.

Is your software distributed or sold? Subscription, licence, freemium, an API exposed to customers — you're in. Only strictly internal software escapes.

What becomes mandatory on 11 September isn't full compliance. It's the reporting of actively exploited vulnerabilities:

  • first report within 24 hours,
  • update within 72 hours,
  • final report within 14 days,
  • recipients: ENISA and the national CSIRT.

Read the deadline carefully. Twenty-four hours isn't a documentation milestone: it's an on-call duty. If nobody's designated, if nobody knows who drafts and who sends, the deadline is already lost the moment the incident happens. It's an operational process to stand up, not a policy to write.

And that's where the real market gap sits. This spring's studies converge: roughly two-thirds of small and mid-sized software companies know about the CRA and don't know how to implement it. That's not an awareness problem. It's a technical-execution problem — mapping your components, wiring up a notification chain, producing evidence — and the supply on that layer is surprisingly thin.

2 August 2026 — AI Act: penalties on AI literacy

Article 4 of the AI Act (EU Regulation 2024/1689) has, since February 2025, required any organisation using AI to see to a sufficient level of competence among the people who operate it — an obligation the Digital Omnibus, adopted at the end of June 2026, softened into an obligation of means: to support literacy, no longer to guarantee it. So the obligation already existed. What changes in early August is that the penalty regime becomes applicable — not the AI Act's general cap, but the tier set for this breach: up to €7.5 million or 1% of worldwide turnover.

I'd rather be direct on this, because a lot of sales pitches lean on it: the immediate risk of a fine for an AI-literacy gap is low. National authorities are still standing up, enforcement priorities will focus first on serious cases, and nobody is going to fine a mid-sized company because its salespeople use an assistant without formalised training.

What is very real, on the other hand, is what a customer, an insurer or a large-account buyer will ask you for within twelve months: show me your training register, the list of your AI systems, and who's accountable for them. Literacy is the first document you'll be asked for, because it's the easiest to ask for.

Selling fear of the fine here would be dishonest. Selling the preparation of a file you'll be asked for anyway is another matter.


What's been postponed — and why that isn't good news

Two important blocks were pushed back — to late 2027 and to 2028.

The AI Act's "high-risk" obligations. Systems used in sensitive areas — recruitment, credit, critical infrastructure — were meant to carry heavy obligations earlier. The Digital Omnibus, adopted definitively by the Council of the EU on 29 June 2026, locked in that postponement: Annex III high-risk systems (recruitment, credit and the like) to 2 December 2027, Annex I systems (product safety) to 2 August 2028.

Full application of the CRA. Security by design, SBOM, technical documentation, guaranteed updates, CE marking: 11 December 2027.

Three observations on these postponements.

First, they're misunderstood. A postponement of "high-risk" obligations doesn't suspend the general obligations, nor literacy, nor transparency. Each postponement produces a wave of "we've got time" that spills far beyond its actual scope.

Second, what's postponed is precisely what takes the longest. An SBOM maintained automatically in an integration pipeline isn't a document you write the night before: it's a pipeline to modify. Technical documentation compliant with Annex V is built version after version. Pushing the date back doesn't reduce the workload — it only reduces the number of months available to absorb it.

Third, and this is the point I keep as a working principle: a pitch built on fear of the fine collapses with every postponement. The calendars will move again. The value of a traceable, documented, defensible system does not — it serves the customer, the insurer, the buyer and the regulator alike. That's why we sell operational risk reduction, and the fine second.


The calendar on one page

DeadlineTextWho's concernedWhat's required
In force (enforcement since Jan 2026)EAA (accessibility)From 10 staff or €2M turnover — public sites and appsAccessibility conformance, accessibility statement. Fines up to €50k per service, renewable
2 Aug 2026AI Act, Art. 4Any organisation using AIAI literacy: trained staff, register. Penalties applicable
11 Sep 2026CRAAny software/SaaS sold in the EUReporting of exploited vulnerabilities: 24 h / 72 h / 14 d (ENISA + CSIRT)
2 Dec 2027AI Act — high-risk (Annex III)Recruitment, credit, sensitive infrastructureHeavy obligations — postponement locked in by the Digital Omnibus
11 Dec 2027CRA — full applicationSame as CRASecurity by design, SBOM, technical doc (Annex V), update policy, CE marking
2 Aug 2028AI Act — high-risk (Annex I)Product-safety-related systemsHeavy obligations — postponement locked in by the Digital Omnibus

A note for readers outside France

Two obligations on our radar are country-specific and don't generalise, so they sit here rather than in the table above.

Digital accessibility applies EU-wide (the European Accessibility Act, in force since 28 June 2025, from 10 staff or €2M turnover — public websites and mobile apps). What differs is the national technical reference and the enforcement body. In France the reference is the RGAA (106 checkable criteria) and controls began in January 2026. A word on overlays — the widgets sold for a few tens of euros a month that promise one-click accessibility: they don't pass audits, and their presence is sometimes read as a sign of bad faith. Real accessibility means fixing the code. There's no shortcut.

E-invoicing is being rolled out on national timelines (France from September 2026 for receiving structured invoices; Morocco on a stricter "clearance" model, deployment started for large companies). The compliant-platform layer is largely covered; the opportunity sits in what happens after the invoice is received — reconciliation, posting, follow-up — which is automation work, not compliance work.


Where to start if you've done nothing

In this order. It's deliberate: each step produces a piece the next ones use.

1. The inventory, this week. What software do you sell? What AI systems are actually used in the company, including the ones IT doesn't know about? What public-facing sites and apps do you run? Three lists. Without them, everything else is guesswork — and I've never seen this exercise fail to produce at least one surprise.

2. The reporting process, before 11 September. If you publish software, this is the closest and most operational deadline. Detection, triage, notification chain, report templates, roles and on-call. It's set up in days, not months — but not the night before.

3. The SBOM, right after. The inventory of your components, in standard formats (SPDX or CycloneDX), generated automatically in your integration pipeline. It's the most structuring CRA building block, and it also serves your day-to-day security. Done by hand, it's out of date the next day.

4. Accessibility, in parallel. An audit of the public site, then fixing the code. It's the only subject on this list where a fine is already in circulation.

5. AI literacy, once the rest is moving. A register of systems, a training path, a trace. Less urgent than it looks in terms of penalty risk, but it's the first document a buyer will ask you for.

One thing not to do: treat these subjects as four separate projects, with four vendors and four methods. It's the same work every time — inventory, process, documentation, proof. The companies that have understood this move three times faster on the second regulation than on the first.


What can still move

For intellectual honesty, and because watching it is our job:

  • The CRA's harmonised technical standards are still being finalised. The regulation is stable; the exact way to demonstrate conformity keeps getting more precise. Any commitment made today must be dated and revisable.
  • The AI Act's timeline was just amended by the Digital Omnibus (June 2026). It can still move, either way — watching it remains necessary.
  • NIS2 remains a special case in some member states — France in particular, where transposition ran badly late while the national agency published its reference framework and is pushing organisations to anticipate anyway. If you're among the concerned entities, waiting is a bad bet.

State verified on 24 July 2026. A compliance paper without a verification date is worthless — this one will be updated, and changes will be flagged at the bottom.

Read nextWhy 88% of AI pilots die — and the 12% protocol: the same mechanics — inventory, process, documentation, proof — applied to AI systems.


Keteris brings software and AI systems into compliance: CRA reporting process, SBOM, technical documentation, AI Act inventories, accessibility. We apply this path to our own products — Le Reglo, our regulatory-watch platform, has been running in production since 2024.

A deadline that concerns you? Book a 30-minute scoping call — enough to know which scope you're in.

All insights