Jump to content

AI Law Wiki News for September 11, 2026

From AI Law Wiki

AI-generated text. This page was generated using artificial intelligence.

September 11, 2026 — EU Cyber Resilience Act reporting duties begin for manufacturers of covered digital products, including relevant AI products.[1][2] U.S. senators negotiate AI safety duties, federal intervention powers and limits on state laws; terms remain unsettled.[3]

EU Cyber Resilience Act reporting duties begin

Manufacturers of products with digital elements within the Cyber Resilience Act’s scope must begin reporting actively exploited vulnerabilities and severe incidents affecting product security from September 11. The Commission identifies this as the start of reporting obligations, ahead of the Act’s broader application in December 2027.[1][4]

An early warning is due without undue delay and within 24 hours of awareness, followed by a notification within 72 hours. Article 14 sets different final-report deadlines: for an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure is available; for a severe incident, within one month after submission of the 72-hour incident notification.[5][4]

The duties cover in-scope products already placed on the market, as well as new products. ENISA identifies its Single Reporting Platform as the mandatory reporting route and distinguishes manufacturers’ duties starting today from open-source software stewards’ reporting duties, which begin December 11, 2027.[4]

The development matters for AI products as well as conventional software and connected devices. CMS’s analysis explains that integrating an AI model into a product marketed under a business’s own name can bring manufacturer responsibilities under the CRA. The reporting trigger concerns qualifying vulnerabilities or incidents affecting an in-scope product, rather than every AI error or output.[2][1] See European Union AI Law for related EU coverage.

U.S. Senate talks consider AI safety duties and state-law preemption

Reuters reported on September 11 that negotiators led by John Thune, Ted Cruz and Amy Klobuchar were discussing a duty of care for developers of the most capable AI models, intended to prevent catastrophic risks. Options included federal power to block unsafe models, with court challenges available to developers, and preemption of some state AI-risk laws. Reuters attributed these details to people involved in or familiar with the talks and said the provisions remained under negotiation.[3]

Klobuchar told Reuters she supported developers working with government experts on model verification and testing.[3] Semafor’s September 10 reporting independently documented the bipartisan talks and said the draft had not been publicly released. This is coverage of ongoing negotiations, not an enacted requirement or a verified introduced bill.[6] See United States Federal Authorities for federal AI legislation and policy coverage, and United States policy on catastrophic AI risk for a comparison of approaches.

References