Kilde › Updates: what changed, dated and sourc…
Current to 12 September 2026 · updates land in the changelog.
Dated, sourced updates on the regimes we cover — published when something actually changes, not on a content calendar. Each entry links the guides it affects; deadline changes also land on the radar. Subscribe via RSS.
As of 11 September 2026 the Cyber Resilience Act's Article 14 duty applies: an actively exploited vulnerability or a severe incident in an in-scope product must reach ENISA and the designated CSIRT as an early warning within 24 hours of awareness, with a notification at 72 hours and a final report after that — and by Article 69(3) that covers every in-scope product already on the EU market. We have not re-verified the reporting platform's go-live status against ENISA's page today; the obligation to notify does not depend on it. The CRA guides and radar now read in the present tense. The 24-hour early warning, in detail.
We read Directive (EU) 2024/2853 verbatim at EUR-Lex today. Three anchors: it applies to products placed on the market or put into service after 9 December 2026; Member States must transpose by 9 December 2026; and the 1985 directive is repealed with effect from the same date. The definition settles the software question in five words — 'product' means all movables and includes electricity, digital manufacturing files, raw materials and software — with free and open-source software outside a commercial activity carved out. For software and device makers this is the next fuse after the CRA's reporting duty; a guides cluster is in preparation. See it on the radar.
We verified the Cyber Resilience Act's important and critical product lists word for word against the Official Journal text at EUR-Lex: 19 Class I categories, 4 Class II, 3 critical. One guide per category is now live, each carrying the verbatim listing plus what the tier changes — and what it doesn't (the 11 September reporting duty is class-blind). All 26 category guides.
The first-citation timeline for CRA harmonised standards moved to around 30 October 2026 (it has slipped before — treat as an estimate). Until a citation lands, Class I products cannot use the self-assessment route: conformity budgeting should assume a notified body, with the citation treated as good news if it arrives. Conformity routes by class.
The Assigned Representative notification guide was revised again (summarized from the revision notes; ENISA marks all platform documentation subject to change). Notable mechanics: a notification cap for unverified ARs, drafts private per representative, and CSIRT-side handling details. The platform itself remains pre-launch, targeted operational by 11 September. The platform, explained.
Anthropic announced model-level text watermarking plus C2PA on file outputs under its Code of Practice commitment. Read the announcement's tense: future models will generate watermarked text, with detection tooling 'soon'. Until a go-live is verified, treat current outputs as unmarked — compliance evidence is what your pipeline actually emits, not what a vendor intends. The marking stack that exists today.
The Commission's icon set went live: three icons (AI interaction, fully AI-generated, partially AI-modified) in four variants, free to use without attribution. Two framing facts from the Commission itself: the icons are voluntary while the labelling requirements are not, and icon-plus-text outperforms either alone. They serve the visible disclosure duties — they do nothing for machine-readable marking. Wording, placement, icons.
The Commission's application guidance for the Cyber Resilience Act landed, covering scope boundaries (remote data processing, open source) and interplay questions. Still outstanding at our verification date: the SME technical-documentation form and the first harmonised-standard citation. Scope, software, SaaS.
Regulation (EU) 2026/1744 published (in force 27 July). Its entire effect on AI transparency: generative systems placed on the market before 2 August 2026 get until 2 December 2026 for machine-readable marking. New systems get no runway, and the disclosure duties get no grace at all. The high-risk delays (Annex III to December 2027, Annex I to August 2028) are separate provisions. The transition's exact scope.
The Commission adopted the final Article 50 guidelines (51pp, non-binding, 24 languages). The load-bearing deltas: AI agents must disclose their artificial nature and whose behalf they act on; the text exemption requires deliberate substance review with editorial responsibility (cursory sign-off insufficient, post-review AI edits void it); wholly fantastical content is excluded from deepfake scope but the boundary reads broadly; assistive exclusions now expressly include AI translations, source code and short outputs; and Article 50 attaches to systems, not models — the wrapper provider carries the marking duty. All Article 50 guides.
The Commission (8 July) and AI Board (9 July) endorsed the transparency Code of Practice: signatories can rely on its measures to demonstrate compliance for Articles 50(2), (4) and (5). Not conclusive proof, but the cleanest demonstration route available — and late accession remains open. Where the CoP fits.
KYC-SA opened for attestations against CSCF v2026: 26 mandatory + 6 advisory controls, control 2.4 (Back Office Data Flow Security) newly mandatory, and customer connectors now in-scope components of 14 controls — the redefinition that moves some browser-only institutions to Architecture A4. Window, roles, consequences.
The Council Presidency was reported to have abandoned negotiations on the Green Claims Directive proposal — stalled, not withdrawn, not law. The rules actually rewiring EU green marketing remain EmpCo's twelve banned practices, applying 27 September 2026 on a date that does not move. GCD vs EmpCo, untangled.
The SFC's circular set zero tolerance for questionable or forged documents in onboarding and ongoing relationships, with risk-based, on-request dormant-account measures (not a blanket closure mandate). The practical read for legitimate customers under review: honest gaps explained survive; papered gaps don't. The company review file.
General information only — not legal advice. Every row and entry traces to an in-house verified source: our audited product research files (checked against primary sources on the stated dates) or same-day verbatim reads of the Official Journal text at EUR-Lex. Status labels are load-bearing: confirmed = in the instrument's text; estimate = published timeline that can slip; announced = stated intent, not in force. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com