cd /news/ai-policy/eu-ai-act-and-cra-timelines-and-reso… · home topics ai-policy article
[ARTICLE · art-95239] src=opensource.org ↗ pub= topic=ai-policy verified=true sentiment=· neutral

EU AI Act and CRA: Timelines and Resources

The Open Source Initiative (OSI) reported that the European Union has passed two milestones in implementing its Cyber Resilience Act (CRA) and AI Act, with the European Commission publishing guidance on the CRA and most provisions of the AI Act coming into force. The CRA guidance clarifies obligations for open source software and stewards, while the AI Act introduces a risk-based framework with transparency requirements, and OSI has been involved in developing the AI Act & AI Transparency Code of Practices.

read4 min views1 publishedAug 13, 2026
EU AI Act and CRA: Timelines and Resources
Image: Opensource (auto-discovered)

Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open Source.

For Open Source developers, maintainers, and organizations, these developments raise important questions about how new regulatory frameworks apply across the software ecosystem. Clear, practical information is essential to help the community understand new requirements, distinguish applicable obligations, and continue building and sharing open technologies. The first milestone comes in the form of Commission guidance on the Cyber Resilience Act. The law establishes cybersecurity requirements for products with digital elements, including vulnerability handling, security updates, and lifecycle responsibilities. The European Commission’s guidance provides answers to many of the burning questions about the CRA. The guidance contains sections both on Open Source software and Open Source software stewards, which both offer important clarifications on how the CRA will impact Open Source in practice.

Since it was proposed in 2022, the OSI has been working with European policymakers to ensure the CRA is written with Open Source in mind. The guidance is a direct result of the dialogue Open Source communities have had with the Commission, both bilaterally, and through Eclipse’s Open Regulatory Compliance Working Group (ORC WG). In combination with ORC WG’s own resources, this guidance now gives Open Source developers, communities, and companies an overview of what the CRA means for them.

The OSI has also sought to make it easier for Open Source developers who have to comply with the CRA to do so, bringing Open Source voices into the standardisation process by working as a key partner with ETSI, who are responsible for the Standards developers must adhere to to comply with the CRA. ETSI recently announced the availability of the 17 vertical final draft standards developed in the framework of the CRA and which are currently under Public Enquiry.

The second milestone is the coming into force of most of the provisions of the EU’s AI act. The law introduces a risk-based framework for artificial intelligence, with obligations being introduced progressively. Among other areas, the regulation includes provisions related to general-purpose AI models, transparency, documentation, and governance.

Here, again, the OSI has been deeply involved. Most recently, we were invited by the European Commission to support the development of the AI Act & AI Transparency Code of Practices, which set out ways by which AI developers can meet the requirements of the AI act, in particular the transparency requirements, which have just recently come into force.

Open Source communities have an important role to play in these discussions. Not every developer or maintainer will have the same responsibilities under these frameworks, and understanding where obligations apply is key to ensuring that regulation supports innovation while protecting users and developers.

As implementation of the EU AI Act progresses, OSI will continue working with European policymakers and the broader Open Source community to provide education, share expertise, and advocate for approaches that recognize the importance of Open Source AI for innovation, transparency, and collaboration.

With regards to the CRA, the OSI will also continue to collaborate with organizations across the Open Source ecosystem, while also engaging with and educating policymakers. Through ETSI and ORC WG, OSI and the community have been collecting resources, facilitating discussions, and developing practical guidance related to Open Source compliance and emerging European regulations.

EU AI Act Timeline:

Date | What happens | | 1 Aug 2024 | AI Act enters into force | | 2 Feb 2025 | Definitions, AI literacy, and prohibited AI practices apply | | 2 Aug 2025 | General-purpose AI (GPAI) obligations apply; EU AI governance becomes operational | | 2 Aug 2026 | Majority of the Act applies; enforcement begins; Article 50 transparency rules apply | | 2 Dec 2026 | Additional prohibitions and certain transition requirements apply | | 2 Aug 2027 | Member States should have AI regulatory sandboxes operational | | 2 Dec 2027 | Rules for certain high-risk AI systems (Annex III) apply | | 2 Aug 2028 | Rules for high-risk AI embedded in regulated products (Annex I) apply |

EU CRA Timeline:

Date | What happens | | 10 Dec 2024 | CRA enters into force | | 11 Jun 2026 | Provisions on notification of conformity assessment bodies apply | | 27 Jul 2026 | European Commission publishes practical implementation guidance | | August 2026 | Vertical standards start public review | | 11 Sep 2026 | Vulnerability and severe incident reporting obligations begin | | 11 Dec 2026 | Member States should have sufficient conformity assessment bodies notified | | 30 Oct 2027 | Further standards expected | | 11 Dec 2027 | Full application of the CRA; main obligations apply |

Resources:

European Commission guidance on general-purpose AI models and the AI ActOSI’s resources on Open Source AI and the Open Source AI DefinitionEuropean Commission guidance on the CRAOpen Regulatory Compliance Working Group CRA resourcesETSI Technical Committee on Cyber Security resourcesETSI vertical standards of the CRA

── more in #ai-policy 4 stories · sorted by recency
── more on @open source initiative 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/eu-ai-act-and-cra-ti…] indexed:0 read:4min 2026-08-13 ·