
← Business of Tech: Daily 10-Minute IT Services Insights4 sep · 13 min
Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents
Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents
A structural shift in regulatory accountability now places incident notification and liability directly on the operators or deployers of AI-powered and software tools, rather than on technology vendors or model developers. This mechanism is made explicit by the requirements of the EU’s Cyber Resilience Act (CRA), Digital Services Act (DSA), and the upcoming Machinery Regulation. Incidents such as the Cursor AI coding agent breach at a Belgian chemical company underline that compliance timelines and regulatory scrutiny target the entity deploying the technology.