The Latest Trends and Essential Tips in the World of Computing

Two European regulations will come into effect between 2026 and 2028, reshaping the obligations of companies that design, sell, or use digital products. The Cyber Resilience Act (CRA) and the AI Act impose specific technical and organizational constraints. Measuring their respective scope allows us to understand which budget items and internal processes will be prioritized in the IT landscape.

Cyber Resilience Act and AI Act: a comparison of timelines and penalties

The two texts do not target the same actors, do not come into force on the same dates, and do not foresee the same penalty ceilings. The table below summarizes the differences.

You may also like : Discover the latest news and tips for success in entrepreneurship

Criterion Cyber Resilience Act (CRA) AI Act
First binding deadline September 11, 2026 August 2, 2025 (prohibitions), then August 2, 2026 (AI culture obligations)
Full application December 11, 2027 August 2, 2027 (high-risk systems)
Scope Any product containing digital elements sold in the EU AI systems placed on the market or used in the EU
Maximum penalty €15 million or 2.5% of global revenue €35 million or 7% of global revenue (prohibited practices)
Key documentation obligation SBOM (Software Bill of Materials) Transparency register, compliance assessment

The CRA primarily impacts software publishers and manufacturers of connected hardware. The AI Act, on the other hand, concerns any company deploying an AI system, including internally. However, both texts share a common logic: document, trace, update.

Several sector analyses published in the IT section of The Web Brains detail the concrete implications of these regulations for French IT teams.

You may also like : Discover the latest high-tech trends and innovations of the moment

IT technician assembling the components of a desktop computer in a home workshop

SBOM and digital CE marking: what the CRA changes for developers

Starting in September 2026, any manufacturer of digital products sold in the EU will be required to report any actively exploited vulnerability or any serious security incident within 24 hours. This notification deadline, modeled after the GDPR for data breaches, necessitates a redesign of monitoring and incident response processes.

The most structuring constraint remains the SBOM. This comprehensive document lists all software dependencies of a product, including open-source libraries. Keeping an SBOM up to date requires three concrete changes in development practices:

  • Integrate a Software Composition Analysis (SCA) tool into the CI/CD pipeline to automatically detect outdated or vulnerable dependencies
  • Formalize a policy for managing free security updates throughout the product’s support lifecycle, a commitment that the manufacturer must document before market launch
  • Prepare the technical file necessary for the cybersecurity CE marking, which will become mandatory by December 11, 2027, for all products containing digital elements

For SMEs that publish software, the cost of compliance is less about tooling (open-source SCA solutions exist) and more about human time: documenting, testing restorations, formalizing notification procedures.

AI Act and the obligation of AI culture in companies: beyond technical compliance

The AI Act is not limited to classifying AI systems by risk level. Starting in August 2025, AI practices deemed unacceptable (social scoring, subliminal manipulation) are prohibited. The next deadline, August 2026, imposes an obligation of “AI culture” on any organization deploying or developing an AI system.

This training obligation covers a broad spectrum. It does not only target data scientists or machine learning engineers. Business teams using a scoring tool, automatic candidate sorting, or customer recommendation are also affected.

The text requires that individuals involved in the operation or supervision of an AI system possess a sufficient level of technical understanding. Concretely, this means building training programs tailored to each profile, documenting acquired skills, and being able to prove them in case of an audit.

Unlike the CRA, which targets manufacturers, the AI Act also holds professional users of high-risk AI systems accountable. A company that purchases AI-assisted recruitment software must verify that the software is compliant, but it must also train its recruiters on its operation and limitations.

Two young professionals discussing IT trends around a laptop in a coworking space

Cybersecurity and cloud: budgetary trade-offs for French companies

The accumulation of these regulatory obligations weighs on IT budgets. The most affected budget items fall into three categories:

  • Application security (code audit, SCA, penetration testing), driven by the requirements of the CRA and the general tightening of attacks on software supply chains
  • AI training and governance, driven by the AI Act, which require dedicated human resources rather than heavy technological investments
  • Cloud infrastructure and data management, where the choice of provider (sovereign cloud or American hyperscaler) conditions both GDPR compliance and the ability to meet CRA traceability requirements

The French cloud market is undergoing a repositioning. Several providers offer SecNumCloud labeled offers, qualified by ANSSI. For companies handling sensitive data, the choice of a qualified cloud becomes a regulatory compliance criterion and not just a commercial argument.

The trade-offs are not solely financial. Recruiting a profile capable of simultaneously managing CRA and AI Act compliance remains challenging. Skills in cybersecurity, data governance, and digital regulation overlap, but training that covers all three areas remains rare in the French market.

The gap between the two regulations is also measured in terms of company maturity. Most organizations already have an IT security policy, even a minimal one. AI governance, however, often starts from scratch in SMEs and mid-sized enterprises. This is where the adaptation effort will be most visible by 2027.

The Latest Trends and Essential Tips in the World of Computing