EU AI Act and CRA: Timelines and Resources

Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open Source.

For Open Source developers, maintainers, and organizations, these developments raise important questions about how new regulatory frameworks apply across the software ecosystem. Clear, practical information is essential to help the community understand new requirements, distinguish applicable obligations, and continue building and sharing open technologies.

The first milestone comes in the form of Commission guidance on the Cyber Resilience Act. The law establishes cybersecurity requirements for products with digital elements, including vulnerability handling, security updates, and lifecycle responsibilities. The European Commission’s guidance provides answers to many of the burning questions about the CRA. The guidance contains sections both on Open Source software and Open Source software stewards, which both offer important clarifications on how the CRA will impact Open Source in practice.

Since it was proposed in 2022, the OSI has been working with European policymakers to ensure the CRA is written with Open Source in mind. The guidance is a direct result of the dialogue Open Source communities have had with the Commission, both bilaterally, and through Eclipse’s Open Regulatory Compliance Working Group (ORC WG). In combination with ORC WG’s own resources, this guidance now gives Open Source developers, communities, and companies an overview of what the CRA means for them.

The OSI has also sought to make it easier for Open Source developers who have to comply with the CRA to do so, bringing Open Source voices into the standardisation process by working as a key partner with ETSI, who are responsible for the Standards developers must adhere to to comply with the CRA. ETSI recently announced the availability of the 17 vertical final draft standards developed in the framework of the CRA and which are currently under Public Enquiry.

The second milestone is the coming into force of most of the provisions of the EU’s AI act. The law introduces a risk-based framework for artificial intelligence, with obligations being introduced progressively. Among other areas, the regulation includes provisions related to general-purpose AI models, transparency, documentation, and governance.

Here, again, the OSI has been deeply involved. Most recently, we were invited by the European Commission to support the development of the AI Act & AI Transparency Code of Practices, which set out ways by which AI developers can meet the requirements of the AI act, in particular the transparency requirements, which have just recently come into force.

Open Source communities have an important role to play in these discussions. Not every developer or maintainer will have the same responsibilities under these frameworks, and understanding where obligations apply is key to ensuring that regulation supports innovation while protecting users and developers.

As implementation of the EU AI Act progresses, OSI will continue working with European policymakers and the broader Open Source community to provide education, share expertise, and advocate for approaches that recognize the importance of Open Source AI for innovation, transparency, and collaboration.

With regards to the CRA, the OSI will also continue to collaborate with organizations across the Open Source ecosystem, while also engaging with and educating policymakers. Through ETSI and ORC WG, OSI and the community have been collecting resources, facilitating discussions, and developing practical guidance related to Open Source compliance and emerging European regulations.

EU AI Act Timeline:

DateWhat happens
1 Aug 2024AI Act enters into force
2 Feb 2025Definitions, AI literacy, and prohibited AI practices apply
2 Aug 2025General-purpose AI (GPAI) obligations apply; EU AI governance becomes operational
2 Aug 2026Majority of the Act applies; enforcement begins; Article 50 transparency rules apply
2 Dec 2026Additional prohibitions and certain transition requirements apply
2 Aug 2027Member States should have AI regulatory sandboxes operational
2 Dec 2027Rules for certain high-risk AI systems (Annex III) apply
2 Aug 2028Rules for high-risk AI embedded in regulated products (Annex I) apply

EU CRA Timeline:

DateWhat happens
10 Dec 2024CRA enters into force
11 Jun 2026Provisions on notification of conformity assessment bodies apply
27 Jul 2026European Commission publishes practical implementation guidance
August 2026Vertical standards start public review
11 Sep 2026Vulnerability and severe incident reporting obligations begin
11 Dec 2026Member States should have sufficient conformity assessment bodies notified
30 Oct 2027Further standards expected
11 Dec 2027Full application of the CRA; main obligations apply

Resources: