Companies that develop, supply or use AI and digital products face new requirements relating to risk management, documentation, cybersecurity and management oversight. The AI Act regulates the development, supply and use of AI systems and AI models. The Cyber Resilience Act imposes cybersecurity requirements on software, hardware and other products with digital elements throughout the product lifecycle. Both are EU regulations and therefore apply directly in the Member States.
How do they differ?
| AI Act | Cyber Resilience Act | |
|---|---|---|
| Focus | Responsible development, supply and use of AI. | Cybersecurity in products with digital elements. |
| Typically covers | AI systems, general-purpose AI models and solutions that incorporate AI as a function. | Software, hardware, apps, components and other digital products placed on the EU market. |
| Relevant companies | Providers, deployers (users), importers and distributors of AI systems and AI models. | Manufacturers, importers and distributors of software, hardware and digital components. |
| Risk approach | The requirements depend, among other factors, on the AI system's risk level and the company's role. | The requirements are based on the product's cybersecurity risks and intended use. |
| Key areas | Classification, governance, transparency, human oversight, documentation and AI literacy. | Secure product development, vulnerability management, security updates, incident reporting and product documentation. |
The AI Act follows a risk-based model, while the Cyber Resilience Act imposes mandatory cybersecurity requirements on covered products throughout their lifecycle. A company may be affected by one or both regulations. This may be the case, for example, where a software company develops a digital product that contains AI functionality.
How we help you
Gain an overview
We map your AI systems, digital products, suppliers and roles and determine which requirements are relevant.
This may include:
- an inventory of AI systems and digital products
- clarification of the company's regulatory roles
- classification and risk assessment
- mapping of third-party solutions and components
- delineation against GDPR, NIS 2 and other regulation
Identify gaps
We assess your existing governance, processes and controls against the relevant requirements.
You receive a prioritised roadmap showing:
- what is already in place
- where the most significant gaps are found
- which activities should be prioritised
- who should be responsible
- how compliance can be documented
Establish an operational framework
If required, we help establish or improve the necessary processes and controls.
For the AI Act, this may include:
- AI governance and policies
- approval and risk assessment of AI use cases
- transparency and human oversight
- supplier management
- documentation and monitoring
- training and AI literacy
For the Cyber Resilience Act, this may include:
- cybersecurity risk assessments
- secure development and change management
- vulnerability handling and disclosure
- security updates and support periods
- incident reporting
- technical documentation and preparation for conformity assessment
The Cyber Resilience Act covers both security properties in the product itself and the manufacturer's processes for areas including risk assessment, maintenance and vulnerability handling.
Do you need to provide customers with assurance regarding your controls?
Technology and software providers may face customer requirements to demonstrate how they manage AI risks and cybersecurity in their products and services.
When customers request independent assurance, an ISAE 3000 report can be tailored to specifically defined controls relating to areas such as:
- governance and accountability
- risk assessment and classification
- secure development
- supplier and component management
- human oversight
- vulnerability and incident management
- documentation and ongoing monitoring
An ISAE 3000 report is not a certification under the AI Act or the Cyber Resilience Act. It can, however, provide relevant customers with independent assurance that the agreed controls have been established and, where the engagement covers a defined period, operated throughout that period.
Advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements.
A targeted engagement
- Mapping: We create an overview of AI systems, digital products and regulatory roles.
- Classification: We determine which requirements apply to each system and product.
- GAP assessment: We identify gaps in governance, processes, controls and documentation.
- Roadmap and implementation: You receive a prioritised plan and assistance with the necessary measures.
- Assurance: Where required by customers, a separate ISAE 3000 report may be the next step.
Find out what will create the most value for you
Contact us for an initial discussion about your AI systems, digital products and most significant regulatory gaps.