惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
D
Docker
IT之家
IT之家
博客园_首页
罗磊的独立博客
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
美团技术团队
Y
Y Combinator Blog
博客园 - 聂微东
量子位
阮一峰的网络日志
阮一峰的网络日志
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
博客园 - Franky
Martin Fowler
Martin Fowler
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
月光博客
月光博客
G
Google Developers Blog
B
Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿

Open Source Initiative

OSI brings the State of the Source to All Things Open 2026 OSI Governance Survey Why Openness Matters More Than Ever The AI Era Arcs Toward Openness Preliminary agenda announced for the Open Technology Research Symposium 2026 Openness Made All of This Possible UN Open Source Week, AI Fellowship, and 2025 Annual Report Open Source AI Fellowship Announced at UN Open Source Week Engaging on Age Attestation Policy in Brazil The OSI 2025 Annual Report Is Now Available From G7’s Vision on AI Openness to EU’s Tech Sovereignty Package OSI welcomes the European Union’s “Tech Sovereignty” package Open Source Initiative Helps G7 Deliver Vision On AI Openness Open Source Organizations Weigh in on Age Attestation Open Technology Research Symposium 2026 Opens Call for Proposals Listening, Learning, and Building Together at OSI Maintainer Month 2026: Celebrating the People Who Keep Open Source Running The 2026 State of Open Source Report Hello From The New Executive Director Welcoming the New Executive Director! Welcoming Duane O’Brien as Executive Director of the Open Source Initiative Open Source Initiative Appoints Duane O’Brien as Executive Director ClearlyDefined: A Three-Year Roadmap for Sustainability and Growth
EU AI Act and CRA: Timelines and Resources
August 13, 2026 News Jordan Maris · 2026-08-13 · via Open Source Initiative

Summer is normally quiet in Brussels, but this year might just be the exception: over the last month, the EU has passed two milestones in implementing its Cyber Resilience (CRA) and AI acts. The OSI has been engaged with European policymakers over the past two years to ensure those laws don’t inadvertently harm Open Source.

For Open Source developers, maintainers, and organizations, these developments raise important questions about how new regulatory frameworks apply across the software ecosystem. Clear, practical information is essential to help the community understand new requirements, distinguish applicable obligations, and continue building and sharing open technologies.

The first milestone comes in the form of Commission guidance on the Cyber Resilience Act. The law establishes cybersecurity requirements for products with digital elements, including vulnerability handling, security updates, and lifecycle responsibilities. The European Commission’s guidance provides answers to many of the burning questions about the CRA. The guidance contains sections both on Open Source software and Open Source software stewards, which both offer important clarifications on how the CRA will impact Open Source in practice.

Since it was proposed in 2022, the OSI has been working with European policymakers to ensure the CRA is written with Open Source in mind. The guidance is a direct result of the dialogue Open Source communities have had with the Commission, both bilaterally, and through Eclipse’s Open Regulatory Compliance Working Group (ORC WG). In combination with ORC WG’s own resources, this guidance now gives Open Source developers, communities, and companies an overview of what the CRA means for them.

The OSI has also sought to make it easier for Open Source developers who have to comply with the CRA to do so, bringing Open Source voices into the standardisation process by working as a key partner with ETSI, who are responsible for the Standards developers must adhere to to comply with the CRA. ETSI recently announced the availability of the 17 vertical final draft standards developed in the framework of the CRA and which are currently under Public Enquiry.

The second milestone is the coming into force of most of the provisions of the EU’s AI act. The law introduces a risk-based framework for artificial intelligence, with obligations being introduced progressively. Among other areas, the regulation includes provisions related to general-purpose AI models, transparency, documentation, and governance.

Here, again, the OSI has been deeply involved. Most recently, we were invited by the European Commission to support the development of the AI Act & AI Transparency Code of Practices, which set out ways by which AI developers can meet the requirements of the AI act, in particular the transparency requirements, which have just recently come into force.

Open Source communities have an important role to play in these discussions. Not every developer or maintainer will have the same responsibilities under these frameworks, and understanding where obligations apply is key to ensuring that regulation supports innovation while protecting users and developers.

As implementation of the EU AI Act progresses, OSI will continue working with European policymakers and the broader Open Source community to provide education, share expertise, and advocate for approaches that recognize the importance of Open Source AI for innovation, transparency, and collaboration.

With regards to the CRA, the OSI will also continue to collaborate with organizations across the Open Source ecosystem, while also engaging with and educating policymakers. Through ETSI and ORC WG, OSI and the community have been collecting resources, facilitating discussions, and developing practical guidance related to Open Source compliance and emerging European regulations.

EU AI Act Timeline:

DateWhat happens
1 Aug 2024AI Act enters into force
2 Feb 2025Definitions, AI literacy, and prohibited AI practices apply
2 Aug 2025General-purpose AI (GPAI) obligations apply; EU AI governance becomes operational
2 Aug 2026Majority of the Act applies; enforcement begins; Article 50 transparency rules apply
2 Dec 2026Additional prohibitions and certain transition requirements apply
2 Aug 2027Member States should have AI regulatory sandboxes operational
2 Dec 2027Rules for certain high-risk AI systems (Annex III) apply
2 Aug 2028Rules for high-risk AI embedded in regulated products (Annex I) apply

EU CRA Timeline:

DateWhat happens
10 Dec 2024CRA enters into force
11 Jun 2026Provisions on notification of conformity assessment bodies apply
27 Jul 2026European Commission publishes practical implementation guidance
August 2026Vertical standards start public review
11 Sep 2026Vulnerability and severe incident reporting obligations begin
11 Dec 2026Member States should have sufficient conformity assessment bodies notified
30 Oct 2027Further standards expected
11 Dec 2027Full application of the CRA; main obligations apply

Resources: