NewsAI RegulationCyber Resilience ActNIS2

Cyber Resilience Act: Manufacturers Must Report Vulnerabilities from September

The EU is tightening security requirements for product manufacturers. From September, a new obligation to report security vulnerabilities takes effect – alongside the AI Regulation and NIS2 Directive, German companies face complex compliance tasks.

From September 2026: Obligation to report vulnerabilities

Cyber Resilience Act: Manufacturers Must Report Vulnerabilities from September

The Cyber Resilience Act brings a new reality for European manufacturers: vulnerabilities must be reported from September onwards. This is just one of several regulatory waves hitting companies right now – and the requirements are piling up.

The essentials

  • From September 2026, the obligation to report security vulnerabilities under the Cyber Resilience Act takes effect
  • Since 02.08.2026, transparency obligations under the AI Regulation (Article 50) are enforceable
  • From 09.12.2026, the Product Liability Directive becomes relevant
  • NIS2 registration deadlines have already passed (31.07.2026); fines up to €10 million or 2% of global annual turnover threaten

Transparency and liability: The regulatory triptych

The EU has created a globally recognized legal framework with the AI Regulation. Since early August 2026, transparency obligations under Article 50 have been enforceable – companies must document how their AI systems work. The company VeroNex has submitted the EU2122 standard to the IETF to technically standardize AI verification evidence and ensure compliance with the EU AI Act and the Product Liability Directive.

The Product Liability Directive follows from December 2026 – another milestone that holds manufacturers accountable. In parallel, courts are already dealing with concrete cases: the Munich Regional Court ruled in the GEMA v. Suno proceedings that training AI models is unlawful if it leads to memorization of protected content. The exception for text and data mining does not justify either the storage or the output of such content.

NIS2: Management liability and supply chain obligations

The NIS2 Implementation Act has been in force since 06.12.2025. Registration deadlines with the Federal Office for Information Security (BSI) have expired following a grace period until 31.07.2026 – and now it's getting serious for affected companies.

Criterion Threshold
Number of employees from 50 employees
Turnover from €10 million
Affected sectors 18 defined industries
Max. fine (particularly important entities) €10 million or 2% of global annual turnover
Fine for late registration up to €500,000

A key aspect: personal liability of management and the passing of security requirements along the supply chain. Even companies not directly subject to the directive – such as car dealerships – are forced to comply with standards through contractual requirements from their clients. Typical requirements include multi-factor authentication (MFA), patch management, and incident management.

Legal analysis is in full swing

The complexity of the new regulations is evident in legal practice: the publisher C.H. Beck is publishing a comprehensive commentary on the AI Regulation at the end of August 2026 with 1,200 pages. At the same time, copyright issues are occupying courts – Carlsen Verlag has filed a lawsuit against OpenAI in connection with an AI-generated picture book. An expert, Felix Stang, pointed out that the probability of a purely coincidental match between the disputed picture book and the original is about 18,000 times lower than winning the lottery.

What this means for you

German companies are under pressure: regulation is no longer optional but concrete with specific deadlines. Those not yet registered risk substantial fines. The obligation to report vulnerabilities from September requires new processes – and the AI transparency obligations since August are already live. For many businesses, now is the time to bring legal and IT departments together and create a clear implementation plan. The question is no longer whether, but how quickly.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.