Skip to content

AI law comparison · Data verified 2026-08-22

EU AI Act vs EU Cyber Resilience Act

EU AI Act and EU Cyber Resilience Act are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.

Find which laws apply to my business

Side by side

Attribute
EU AI Act
EU Cyber Resilience Act
Region
EU
EU
Effective date
2024-08-01
2024-12-10
Enforcement begins
2026-08-02
2026-09-11
Who must comply
Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third countries when output used in EU, (4) importers and distributo…
Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use includes a data connection) that is made available on the E…
Maximum penalty
€35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities
€15,000,000 or 2.5% of global annual turnover for essential requirement violations
Compliance requirements
10 tracked
4 tracked
Enforcement actions on record
2
None on record yet
Data last verified
2026-08-22
2026-08-22

Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

The key difference

EU AI Act takes effect first, so it is usually the more urgent of the two. EU AI Act tracks 10 compliance requirements and EU Cyber Resilience Act tracks 4. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.

EU

EU Artificial Intelligence Act

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement), limited-risk (transparency obligations for chatbots and deepfakes), minimal-risk (most AI tools). Providers AND deployers have obligations. Extraterritorial: applies when the AI s…

Full EU AI Act requirements
EU

EU Cyber Resilience Act (CRA) — Software & AI Products

The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and publishers of any software or hardware "product with digital elements" sold or made available in the EU to meet essential cybersecurity requirements. This includes SaaS products, AI applications, connected devices, and any software deployed by EU users. Phase 1 reporting obligations (vulnerability…

Full EU Cyber Resilience Act requirements

Common questions

Could both EU AI Act and EU Cyber Resilience Act apply to my business?

Yes. EU AI Act and EU Cyber Resilience Act are separate regulations with separate scopes — a business can fall under both at once. EU AI Act covers Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third co… EU Cyber Resilience Act covers Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.

Which has the higher maximum penalty — EU AI Act or EU Cyber Resilience Act?

EU AI Act: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities EU Cyber Resilience Act: €15,000,000 or 2.5% of global annual turnover for essential requirement violations Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.

When does each law take effect?

EU AI Act — effective 2024-08-01, enforcement from 2026-08-02. EU Cyber Resilience Act — effective 2024-12-10, enforcement from 2026-09-11. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.

Related comparisons

See all law comparisons

Stop guessing which laws apply

Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.

Start free compliance scan