Blog Post

Two Reporting Clocks on One AI Product, Only One Running

September 20, 2026

Table of Contents

An AI product sold in Europe is described as facing two incident reporting duties. One under product security rules and one under AI rules, with different triggers and different deadlines.

Only one of them is running. Article 14 of the Cyber Resilience Act has applied since 11 September 2026. The AI duty moved, and coverage published in the last few weeks still describes it as live.

Which Clock Is Running Today?

The product security one, and it started this month.

Manufacturers of products with digital elements must notify actively exploited vulnerabilities and severe incidents affecting product security, simultaneously to the European cybersecurity agency and the coordinating national response team, through a single reporting platform. An early warning within 24 hours of awareness, a fuller notification within 72 hours, and a final report at 14 days for a vulnerability or a month for an incident.

The Platform Arrived the Same Day as the Duty

The reporting platform was not operational before the obligation began, becoming available on the same date. Only mandatory reporting is accepted at launch, with voluntary reporting unavailable initially. So the infrastructure and the deadline arrived together rather than the first preceding the second.

Why Isn't the AI Reporting Duty Live?

Because the section of the AI Act containing it was deferred, which is the fact most current coverage has not absorbed.

Regulatory landscape table listing each applicable regime with its jurisdiction, who it applies to and the assessed exposure level
One product can sit under several regimes at once, and a per-regime record is what keeps their different dates distinguishable.

Regulation (EU) 2026/1744, in force since July 2026, rewrote the application dates in the AI Act and deferred Chapter III Sections 1 to 3 to December 2027 for standalone high-risk systems and August 2028 for high-risk AI embedded in regulated products. Article 73, the serious incident reporting duty, attaches to providers of high-risk systems and is treated as part of that deferred regime.

What Did Not Move

The transparency obligations in Article 50, which sit in a different chapter and have applied since August 2026. The AI literacy duty. The prohibited practices, in force since early 2025. The obligations on general-purpose model providers also stayed. A program that treated August 2026 as one deadline for everything has the wrong picture in both directions, which sequencing the obligations by date sets out.

What Would the AI Duty Require When It Arrives?

Worth knowing now because the preparation overlaps with what is already required, and because the triggers are not versions of each other.

The serious incident trigger covers death, serious health harm, disruption of critical infrastructure, breach of fundamental rights, and serious property or environmental damage. The deadline runs to 15 days by default, tightening to 10 where a death may have been caused and 2 for a widespread infringement or serious and irreversible disruption of critical infrastructure.

The Triggers Barely Overlap

The product security duty fires on exploitation whether or not anybody was harmed. The AI duty fires on harm whether or not any security failure was involved. So an exploited vulnerability with no harm triggers one, a model malfunction that injures somebody triggers the other, and only a security compromise causing a listed harm would trigger both.

Was the Overlap Deconflicted?

Partly, and the part that was missed is worth flagging because it will matter in December 2027.

Assessment setup showing how many evidence requirements can be satisfied from connected systems against the total the assessment requires
Where two regimes ask for overlapping evidence on different timetables, what matters is whether the underlying record serves both.

The AI Act contains provisions written to handle overlap with existing reporting regimes, and they were drafted before the product security reporting duty was agreed. So the deconfliction covers what its drafters could see and not the duty that arrived afterward. When the AI clock starts, an organization facing both will be reconciling them without a provision that contemplates the combination.

Which Argues for One Record, Not Two Processes

The reports go to different institutions, since product security notifications reach the cybersecurity agency and a response team while AI notifications reach a market surveillance authority per member state. What can be shared is the underlying record of what happened, when it was determined and on what evidence, and storing observations rather than filings is the principle that makes that possible.

What Does the Live Duty Reach?

The installed base, which is the provision most likely to catch a manufacturer out and has nothing to do with AI.

The general transitional rule puts products placed on the market before December 2027 outside the regulation unless substantially modified. The reporting obligation is expressly carved out of that, so it applies to all in-scope products already on the market whether or not they are ever modified. A product shipped years ago and never touched needs a working 24-hour capability now.

Is There a Retroactive Element?

No. Active exploitation a manufacturer already knew about before the obligation began does not have to be notified, since the duty attaches to becoming aware and runs forward from the date it applied. A backlog review is not required, and anything learned from that date onward is.

What Should Be Built Now?

Four things for the live duty, three of which serve the AI duty later as well.

A component record per shipped product version, since awareness requires determining that a product is affected. Platform access arranged before it is needed. A named individual who can declare active exploitation, with a stated evidence threshold. Then supplier notification timing in contract, because the fastest internal process cannot outrun a supplier who tells you next quarter.

Which of Those Transfer?

The determination owner, the evidence threshold and the supplier terms all apply to either regime. What does not transfer is the platform access and the recipient mapping, since the AI duty reaches a market surveillance authority in each member state where an incident occurred rather than a single platform, and other clock-based regimes add further recipients again.

Does the Deferral Change What to Do Now?

Less than it appears, and treating it as sixteen months of relief is the error the deferral invites.

The AI Act requirements were not reduced, narrowed or made optional. The reason given for moving the dates was that harmonized standards, notified body capacity and national supervisory infrastructure were not ready, so the deferral addressed the machinery rather than the substance. Classification work in particular has no reason to wait, since knowing which of your systems would be high-risk determines what the later date will cost.

Which Work Is Worth Doing in the Interval?

Anything that takes longer than the notice period. A conformity assessment engagement plus the technical documentation typically runs twelve to eighteen months, and notified bodies are still being designated, so sixteen months is roughly one cycle rather than a comfortable margin. The deferral removed the crisis and not the lead time.

What Is the Reporting-Specific Version?

Build the determination capability against the live product security duty and it will serve the AI duty when that arrives. An organization that can establish what happened, when it knew and on what evidence inside 24 hours can meet a 15-day deadline comfortably, and producing evidence on somebody else's timeline is the capability both regimes are testing.

What Is the Exposure?

Penalties reaching fifteen million euro or two and a half percent of worldwide turnover under the product security regulation, and the useful figure is the probability of missing the deadline rather than the ceiling.

A manufacturer with a component record and a named decision owner will meet a 24-hour deadline in most cases. One lacking either misses it whenever an advisory requires investigation. Take the last three significant advisories affecting your component stack and time how long it took to establish whether your products were affected, since where that exceeds 24 hours the capability does not exist regardless of what has been documented. Cyber risk quantification converts that interval into a figure somebody can fund.

One Clock, Not Two, For Now

The product security reporting duty has applied since 11 September 2026 and reaches products shipped years ago, with a 24-hour early warning running from a determination that a product is affected and that exploitation is occurring. The AI serious incident duty was deferred with the rest of the high-risk regime to December 2027 or August 2028, and coverage published recently still describes it as live. The triggers barely overlap when both do apply, since one fires on exploitation regardless of harm and the other on harm regardless of security. The provisions written to deconflict the AI duty from other regimes predate the product security duty entirely. What transfers between the two is the determination owner, the evidence threshold and the supplier terms, and what does not is the recipient mapping. Kovrr's AI compliance readiness tracks which obligations reach which systems and on what date.

To see which reporting obligations attach to each of your products and systems, book a demo mapped to your own estate.

Or Amir

Product & Customer Growth Manager

Incident Reporting Duty FAQs

Speak to an Expert

Does CRA Article 14 reporting apply from September 2026?

Is EU AI Act Article 73 serious incident reporting deferred?

Does the CRA reporting duty cover products already on the market?

Do the CRA and EU AI Act reporting triggers overlap?

Where do you file a CRA Article 14 report?

What are the penalties for missing a CRA reporting deadline?