September 11, 2026 is the date Article 14 of the EU Cyber Resilience Act — Regulation (EU) 2024/2847 — started forcing manufacturers of "products with digital elements" to report actively exploited vulnerabilities. I checked the calendar against the coverage. The date falls on a Friday, not the Thursday most write-ups repeated. One day of drift tells you how carefully the compliance narrative is being sourced. More important: the ENISA Single Reporting Platform opened without an API and in English only, and it now governs companies that must file within 24 hours of "becoming aware" of a defect they cannot technically define.
I have spent years pricing risk nobody wanted to name. In 2017 I tracked Status Network SNT insider wallets for weeks and found 40% of supply clustered in a handful of addresses the whitepaper never mentioned. On-chain data beat the roadmap every time. The CRA is the same problem wearing a legal mask. The rules are published. The reporting infrastructure is not.
Context: what the regulation actually demands
Set the structure. The CRA is a regulation, which means direct applicability across the EU — no member-state transposition, no domestic gap to hide in. Any manufacturer placing a product with digital elements on the EU market is bound, and US vendors are not exempt. They must appoint an EU authorized representative and answer to member-state market surveillance authorities.
The obligation schedule is dual-track. Reporting under Article 14 applies from September 11, 2026. The remaining core obligations — Annex I essential cybersecurity requirements, conformity assessment, technical documentation — apply from December 11, 2027. Everything smart-home with an embedded agent now sits in a half-compliant state, theoretically exposed and practically unreached.
The manufacturer checklist is specific: a 24-hour early warning, a 72-hour vulnerability notification, a 14-day final report; free security updates for the supported lifetime; a minimum five-year support window; a machine-readable software bill of materials. Smart locks, cameras, and baby monitors fall under Annex III "important products," which triggers stricter conformity assessment. That last category matters. When a regulated device touches physical safety and a family's privacy, any agent failure moves from a technical incident to a liability event.
Core: the trigger point is a black hole
Here is where the smart-home AI crowd is flying blind, and it is structural, not lazy.
The CRA was drafted for deterministic code. Its reporting trigger is built on "becomes aware" — a knowing-or-should-have-known standard. An autonomous agent that fails after deployment does not map cleanly onto that phrase. If a network of assistants cascades tokens, misroutes commands, or leaks memory context, is that a "vulnerability" that must be filed in 72 hours? The regulation does not say. The European Commission's 67-page implementation guidance from July 2026 mentions AI agents exactly zero times. There is no CJEU case law. Harmonized CEN/CENELEC standards have not entered the Official Journal, which means no presumption of conformity exists for any vendor.
The market is therefore running a compliance deficit with real teeth on the downside. Penalties reach €15 million or 2.5% of global turnover, whichever is higher. Supplying incorrect or incomplete information caps at €5 million or 1%. For a large manufacturer, 2.5% of global revenue is existential exposure. For a small vendor, the €15 million floor is fatal on its own. The fine schedule is regressive, and the structural effect is consolidation — exactly what compliance regimes do to thin-margin players. Filing defensibly is strategy, and strategy is the art of surviving your own leverage.
Read the identity mismatch carefully. These smart-home firms believe they are "AI providers" and that the AI Act is their primary problem. Legally, they are manufacturers of products with digital elements under the CRA. They are governed by a hardware-and-supply-chain instrument while their actual product behavior is probabilistic and evolving. That is not "no regulation." That is the wrong tool applied with full force. The companies convinced they are exempt because they "only ship software" are the ones about to learn otherwise.
Contrarian: OWASP cannot hand you a defense
The industry reflex is to point at the OWASP Top 10 for Agentic Applications 2026 — goal hijacking, memory poisoning, cascading failures, rogue agents. Good taxonomy. It maps onto the CRA's reportable-vulnerability concept almost not at all. OWASP is non-binding consensus; the CRA is enforceable law. You cannot file an OWASP category and call it a report, and you cannot cite a framework as a safe harbor that no regulator has recognized.
Meanwhile the enforcement reality is thinner than the penalty column implies. The ENISA platform has no API and operates in English only. That is an early-stage posture: collect first, investigate later. Every filing a company submits now becomes self-incriminating material waiting for a future audit. The asymmetry is the least-discussed feature of this regime — heavy theoretical liability paired with light practical tooling.

There is also the transatlantic split. The US NIST agent-security framework is voluntary. The CRA is mandatory, with no mutual recognition. US vendors now run one product against two safety philosophies: a forced reporting architecture for Europe, a voluntary disclosure posture for America. That dual-track cost gets internalized into pricing, and the smaller the vendor, the harder it bites.
Takeaway: watch the interpretation window
The next 12 to 18 months decide the real rules. Harmonized standards entering the Official Journal will break the current no-presumption deadlock. Commission guidance will likely stretch "vulnerability" to cover some agent failure modes, and Annex III enforcement on locks and monitors will set the tone. Whoever files a defensible interpretation first helps set the benchmark the rest will be measured against. I am not waiting for the verdict.
Impermanence is the only permanent yield — in collateral, in code, and in regulatory certainty. Waiting for the final guidance is arbitrage, and arbitrage is just patience wearing a math mask. The compliance countdown is not a deadline. It is an opening bid.