Computing is undergoing an unprecedented regulatory transformation in Europe. Two major texts, the Cyber Resilience Act and the AI Act, entered their implementation phase in 2026, significantly altering the obligations of manufacturers, software publishers, and companies deploying artificial intelligence systems. These changes are reshaping priorities: compliance is becoming as much a technical issue as a legal one.
Cyber Resilience Act: What the Reporting Phase Changes in September 2026
Since September 11, 2026, the Cyber Resilience Act requires manufacturers of products containing digital elements to provide rapid notification. Any actively exploited vulnerability must be reported within 24 hours, followed by a complete notification within 72 hours.
This requirement applies to products marketed in the European Union, including some already on the market. The scope is broad: connected objects, embedded software, network equipment. For technical teams, this means establishing incident detection and reporting processes that comply with these tight deadlines.
Following computing on Geek Gazette allows one to gauge how these obligations are transforming the daily lives of product and security teams in European companies.
Field feedback on this point varies: some organizations had anticipated these obligations thanks to established responsible disclosure practices, while others are discovering the complexity of structured reporting within such short timelines. The maturity of internal processes varies significantly from one sector to another.

AI Act Effective Since August 2026: Concrete Obligations by Risk Level
August 2, 2026 marks the entry into force of a large part of the European AI Act. The obligations now cover transparency, technical documentation, traceability, human oversight, cybersecurity, and incident notification. Each requirement applies according to the risk category of the concerned AI system.
Implementation remains gradual. Some requirements for high-risk systems extend into 2027 and 2028. This staggered timeline creates a particular situation: companies must simultaneously comply with already active rules and prepare for those that will come into effect in the following months.
What This Implies for Technical Teams
Technical documentation becomes a deliverable in its own right. A high-risk AI system requires training traces, performance evaluations, and human oversight protocols. These documents must be accessible to regulatory authorities.
Human oversight raises practical questions: who validates automated decisions, how often, and based on what criteria? The available data does not yet allow for conclusions on stabilized best practices, with each sector (healthcare, finance, recruitment) developing its own approaches.
Cybersecurity and AI: European Funding Opened in September 2026
The Digital Europe program opened a call for projects on September 1, 2026, dedicated to AI-assisted cybersecurity tools. This funding targets the development of tools capable of detecting and responding to threats in an automated manner, reflecting a broader trend in European public investments.
This type of program directs research and development priorities. Companies and laboratories wishing to participate must articulate their projects around concrete use cases:
- Automated detection of vulnerabilities in cloud infrastructures and distributed systems, with response times compatible with the requirements of the Cyber Resilience Act
- Behavioral analysis of network flows to identify novel attacks (zero-day) that traditional signatures do not capture
- Decision support tools for incident response teams, capable of prioritizing alerts based on their actual criticality
However, these calls for projects do not cover the costs of regulatory compliance itself. The funding focuses on technical innovation, not on adapting to legal obligations.

Protection of Minors Online: The EU Kids Act Proposed in September 2026
The European Commission proposed the EU Kids Act on September 17, 2026, a text aimed at restricting children’s access to social media platforms and strengthening moderation obligations. This draft regulation is part of a series of European texts redefining the responsibilities of digital actors.
The text targets platforms whose interfaces exploit retention mechanisms (notifications, infinite scroll, algorithmic recommendations) among minor audiences. The obligations would focus on age verification, limiting certain features, and transparency of recommendation algorithms.
A Text That Crosses Several Existing Regulations
The EU Kids Act does not replace the GDPR or the Digital Services Act. It adds to them, creating an overlap of legal frameworks that platforms will need to integrate simultaneously. For development teams, compliance becomes an exercise in coordination among several texts with sometimes differing requirements on closely related topics (personal data, moderation, algorithmic transparency).
IT Monitoring in 2026: Areas to Watch Beyond the Headlines
IT news often focuses on product announcements and fundraising. Regulatory developments receive less attention, even though they are permanently altering technical and organizational practices.
Three areas deserve active monitoring in the last quarter of 2026:
- The precise implementation timeline of the AI Act for high-risk systems, with some requirements coming into effect in 2027
- The first feedback on vulnerability notifications under the Cyber Resilience Act, which will reveal real operational challenges
- The results of the Digital Europe call for projects on AI-assisted cybersecurity, which will provide an indication of priority technologies for the European Union
European regulation is redefining what it means to “do computing” in 2026. Teams that treat compliance as a technical subject in its own right, rather than as an administrative constraint, will be better positioned to absorb the upcoming waves of obligations without operational disruption.



