# EU AI Act and CRA: Timelines and Resources

> Source: <https://opensource.org/blog/eu-ai-act-and-cra-timelines-and-resources>
> Published: 2026-08-13 12:45:34+00:00

# EU AI Act and CRA: Timelines and Resources

Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open Source.

For Open Source developers, maintainers, and organizations, these developments raise important questions about how new regulatory frameworks apply across the software ecosystem. Clear, practical information is essential to help the community understand new requirements, distinguish applicable obligations, and continue building and sharing open technologies.

The first milestone comes in the form of [Commission guidance on the Cyber Resilience Act.](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation) The law establishes cybersecurity requirements for products with digital elements, including vulnerability handling, security updates, and lifecycle responsibilities. The European Commission’s guidance provides answers to many of the burning questions about the CRA. The guidance contains sections both on Open Source software and Open Source software stewards, which both offer important clarifications on how the CRA will impact Open Source in practice.

Since it was proposed in 2022, the OSI has been [working](https://opensource.org/blog/tag/cra) with European policymakers to ensure the CRA is written with Open Source in mind. The guidance is a direct result of the dialogue Open Source communities have had with the Commission, both bilaterally, and through Eclipse’s [Open Regulatory Compliance Working Group](https://orcwg.org/) (ORC WG). In combination with ORC WG’s own resources, this guidance now gives Open Source developers, communities, and companies an overview of what the CRA means for them.

The OSI has also sought to make it easier for Open Source developers who have to comply with the CRA to do so, bringing Open Source voices into the standardisation process by working as a key partner with [ETSI](https://www.etsi.org/), who are responsible for the Standards developers must adhere to to comply with the CRA. ETSI recently [announced](https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/) the availability of the 17 vertical final draft standards developed in the framework of the CRA and which are currently under Public Enquiry.

The second milestone is the coming into force of most of the provisions of the [EU’s AI act](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers). The law introduces a risk-based framework for artificial intelligence, with obligations being introduced progressively. Among other areas, the regulation includes provisions related to general-purpose AI models, transparency, documentation, and governance.

Here, again, the OSI has been deeply [involved](https://opensource.org/blog/tag/ai). Most recently, we were invited by the European Commission to support the development of the AI Act & AI Transparency Code of Practices, which set out ways by which AI developers can meet the requirements of the AI act, in particular the transparency requirements, which have just recently come into force.

Open Source communities have an important role to play in these discussions. Not every developer or maintainer will have the same responsibilities under these frameworks, and understanding where obligations apply is key to ensuring that regulation supports innovation while protecting users and developers.

As implementation of the EU AI Act progresses, OSI will continue working with European policymakers and the broader Open Source community to provide education, share expertise, and advocate for approaches that recognize the importance of Open Source AI for innovation, transparency, and collaboration.

With regards to the CRA, the OSI will also continue to collaborate with organizations across the Open Source ecosystem, while also engaging with and educating policymakers. Through ETSI and ORC WG, OSI and the community have been collecting resources, facilitating discussions, and developing practical guidance related to Open Source compliance and emerging European regulations.

**EU AI Act Timeline:**

Date | What happens |
| 1 Aug 2024 | AI Act enters into force |
| 2 Feb 2025 | Definitions, AI literacy, and prohibited AI practices apply |
| 2 Aug 2025 | General-purpose AI (GPAI) obligations apply; EU AI governance becomes operational |
| 2 Aug 2026 | Majority of the Act applies; enforcement begins; Article 50 transparency rules apply |
| 2 Dec 2026 | Additional prohibitions and certain transition requirements apply |
| 2 Aug 2027 | Member States should have AI regulatory sandboxes operational |
| 2 Dec 2027 | Rules for certain high-risk AI systems (Annex III) apply |
| 2 Aug 2028 | Rules for high-risk AI embedded in regulated products (Annex I) apply |

**EU CRA Timeline:**

Date | What happens |
| 10 Dec 2024 | CRA enters into force |
| 11 Jun 2026 | Provisions on notification of conformity assessment bodies apply |
| 27 Jul 2026 | European Commission publishes practical implementation guidance |
| August 2026 | Vertical standards start public review |
| 11 Sep 2026 | Vulnerability and severe incident reporting obligations begin |
| 11 Dec 2026 | Member States should have sufficient conformity assessment bodies notified |
| 30 Oct 2027 | Further standards expected |
| 11 Dec 2027 | Full application of the CRA; main obligations apply |

**Resources:**

[European Commission guidance on general-purpose AI models and the AI Act](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers)[OSI’s resources on Open Source AI and the Open Source AI Definition](https://opensource.org/ai)[European Commission guidance on the CRA](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation)[Open Regulatory Compliance Working Group CRA resources](https://orcwg.org/cra/resources/)[ETSI Technical Committee on Cyber Security resources](https://www.stan4cra.eu/etsi-tc-cyber)[ETSI vertical standards of the CRA](https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/)
