AI in Practice Sep 11, 2026

Cyber Resilience Act: New Security Requirements Now Apply to AI Companies

Cyber Resilience Act: New Security Requirements Now Apply to AI Companies

The Cyber Resilience Act (CRA), adopted by the European Union in 2024, comes at a time when both creating and attacking software are becoming easier. Generative coding tools help small teams ship products quickly, while also making it easier to introduce weak authentication, exposed secrets, unverified dependencies, or code no one fully understands. The CRA was not created specifically in response to AI, but its emphasis on security throughout the product lifecycle is becoming increasingly relevant as AI accelerates software development.

What the Cyber Resilience Act changes

Regulation (EU) 2024/2847 applies to many products with digital elements made available on the EU market. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security. Early warnings are due within 24 hours of awareness, followed by more detailed notifications within 72 hours and a final report later. This duty also covers products that were placed on the market before these rules started to apply.

The main security, documentation, conformity assessment, and CE-marking requirements apply from 11 December 2027. Every manufacturer of a product in scope will need risk assessments, secure default settings, a software bill of materials, regular testing, a vulnerability disclosure process, security updates for a defined support period, and technical documentation. The product's classification decides whether the company can assess conformity itself or needs an independent body.

These obligations matter because AI affects both sides of cybersecurity. Attackers can use generative tools to research targets, adapt malicious code, and test more attack paths. At the same time, vibe coding lets people create applications without understanding every dependency, permission, or security assumption in the generated code.

Vibe coding is not inherently unsafe. The problem begins when rapid generation replaces code ownership, review, testing, and documentation. Faster code creation requires stronger verification, not weaker controls.

What responsible implementation looks like

For AI startups, every generated change should have a human owner. Sensitive changes involving authentication, customer data, secrets, or actions in connected systems need additional review. Build processes should check code, dependencies, credentials, infrastructure, authorization, and customer isolation before release.

Teams also need a rehearsed process for identifying affected versions and users within hours of discovering an incident. A 24-hour reporting deadline cannot be met if the company first has to find the responsible engineer, affected customers, or required platform credentials.

At Siesta AI, this direction matches how enterprise software should be built: with SSO, clear access controls, audit logs, permission management, private deployment options, and explicit rules for customer data. CRA applicability still depends on product scope, deployment model, and the company’s role in the supply chain. These controls are not, by themselves, a blanket claim of compliance, but they provide the foundation for documenting risk and responding when something goes wrong.

Security claims must match the product

The CRA is not only a development concern. A product’s intended purpose is also shaped by instructions, sales materials, contracts, and public statements. If a presentation promotes autonomous operation in a critical process while the security assessment assumes human supervision, the company has created a gap between its claims and controls.

AI companies should review their website, presentations, contracts, and security addenda together. Unsupported statements such as “fully secure” or “CRA compliant” should be replaced with specific information about access control, auditability, deployment, updates, incident contacts, and support periods. Every security claim should have an owner and supporting evidence.

The Cyber Resilience Act formalizes disciplines that become more important as AI reduces the effort required to write and attack code. Vibe coding can shorten development cycles, but it cannot shorten the chain of accountability.

Building AI for business should not mean choosing between useful capabilities and security. See how Siesta AI combines governed access, auditability, private deployment options, and human oversight in real company workflows. Schedule a demo.

Enjoy this post? Join our newsletter
Don't forget to share it

The Enterprise AI Platform

Empower your company with AI chat, search, agents, workflows, and recordings, all in one secure platform.

ISO 27001 | GDPR | SSO | Encryption
AI Chat AI Search AI Agents Recordings Workflows Memory Tasks Skills Approvals
OpenAI Google Gemini Anthropic Claude Mistral Use any model | EU Made in EU

Related Articles

All posts