AI Act, Cyber Resilience Act, Résilience bill: the same missing inventory
Three European texts land on the same calendar and do not do the same thing to demand: one has just slipped by eighteen months, the next bites in six weeks, the third holds budgets back until it passes. What they ask for, though, looks very much alike.
These texts get talked about as a block, “compliance”, and that is what makes people miss the only dates that matter. They do not point the same way. On 1 August 2026, one has just receded, another is six weeks out, a third still does not exist. An independent tuning their practice to the regulatory calendar is therefore better off reading it line by line than in bulk.
The European regulation on artificial intelligence was to impose its “high-risk” obligations from 2 August 2026: tomorrow. The simplification regulation known as the Digital Omnibus, in force since 27 July, has pushed them to 2 December 2027 for stand-alone Annex III systems, and to 2 August 2028 for AI embedded in already-regulated products. The stated reason is the delay on harmonised standards and on the designation of national authorities.
What remains on 2 August 2026 is the transparency obligation: telling a person they are dealing with a machine. It is real and it is light. The wave of governance, audit and documentation work the date was to trigger has moved by eighteen months, and that is market information rather than legal information. Budgets that had formed for this summer will unwind elsewhere.
The cyber resilience regulation sets its first binding deadline on 11 September 2026: any manufacturer of a product with digital elements must report actively exploited vulnerabilities and severe incidents. The delays are those of an on-call rota, not of a project: early warning within twenty-four hours, fuller notification within seventy-two, final report within fourteen days. The main obligations follow on 11 December 2027, with penalties up to fifteen million euros or 2.5 % of worldwide turnover.
Twenty-four hours is the number that decides everything, and it turns a legal obligation into an engineering problem. You do not report an actively exploited vulnerability in a day if you do not know what is inside your product: which libraries, in which version, in which shipped version of the product, at which customers. That question is not a question of law, it is a question of inventory.
The French transposition of the European cybersecurity directive, carried by the bill known as Résilience, would take the number of entities under obligation from about five hundred to fifteen thousand. Passed by the Senate in March 2025, it has been postponed several times and its examination is expected in the autumn. Until it passes it produces the opposite of the effect ascribed to it: management waits for the text before deciding, and demand stays suspended rather than firing.
These three texts ask, each in its own vocabulary, for the same thing. The cyber regulation wants a software bill of materials kept current, a declared support period and a record of fixes. The AI regulation wants, for a high-risk system, to know what data fed it, what it produces, and what was logged. The cyber directive wants an entity to know which systems it runs and which are critical.
Three times over, that is an inventory kept, dated, queryable, and joined to what is actually deployed. It is not law and it is not security: it is a data problem. Collection, freshness, joining two registers that share neither their grain nor their cut-off date. It is exactly the difficulty described elsewhere on this site about public files, and it is settled with the same moves.
It is also why I distrust the reading that turns these texts into a market for legal advice. The part a lawyer settles is short and comes up once: am I in scope, and on what basis. The part that lasts is producing an exact picture of an estate on a given date, every day, without anybody maintaining it by hand, and that part has never been solved by a legal memo.
I am not a lawyer and nothing above says whether you fall within the scope of any of these texts: that is the one question needing qualified advice, and the one I do not address. Nor do I say anything about the harmonised standards, whose absence is precisely what justified July’s postponement: they will decide what “compliant” concretely means, and they are not written.
And a reservation about this piece’s shelf life. It is dated 1 August 2026 because one of these dates moved four days earlier. A text that postpones its own deadlines can do it again, and the calendar above holds for today. That is what legal.commutator.io is for, where I keep these deadlines current: that tool gets revisited, this page will not. Where the two disagree, the tool is the one to trust.