CRA Compliance

Does AI vulnerability discovery change CRA Article 14 reporting?

By CVD Portal
••Last updated 2026-10-06••6 min read

AI vulnerability discovery does not change the CRA Article 14 trigger. A manufacturer notifies a vulnerability only when there is evidence of active exploitation. AI-found reports change the volume and speed of vulnerability handling under Annex I Part II.

Key takeaways

  • The first episode of ENISA on Air discussed how frontier AI shortens the time between vulnerability discovery and exploitation.
  • Article 14 vulnerability notification starts on active exploitation. A report found with an AI tool does not start the 24-hour clock by itself.
  • Commission guidance C(2026) 5252 puts an initial assessment before awareness. More reports mean more assessments, and each one must be prompt.
  • ENISA's stakeholders named duplicate reports as a new handling cost, mainly for small and medium maintainers.
  • A CVD policy written for a few human reports a year needs clauses for AI-assisted reports, duplicates and shorter disclosure windows.

What did ENISA say about frontier AI and vulnerability disclosure?

ENISA published the first episode of its podcast, ENISA on Air, on frontier AI and cybersecurity. The episode makes four points that matter to a manufacturer under the Cyber Resilience Act.

First, the time between the discovery of a vulnerability and its exploitation is getting shorter. The episode says current coordinated vulnerability disclosure and patch processes may not keep pace.

Second, Razvan Gavrila, Head of Sector at ENISA, reported what ENISA's stakeholders told the agency. The quality of vulnerability reports improved towards the end of 2025. The new problem is duplication. The same issue arrives many times in different forms, and each maintainer must check whether it is already known.

Third, fixes proposed by AI models tend to change only the code next to the vulnerability. The correct fix is sometimes in a different part of the architecture.

Fourth, one open-source maintainer told ENISA that it treats any vulnerability found with a language model as public. The reasoning is that other people with the same tools can find the same vulnerability.

Does an AI-found vulnerability start the Article 14 clock?

No. Article 14 vulnerability notification applies to an actively exploited vulnerability. Active exploitation means evidence of real-world attacks that use the vulnerability. The tool that found the vulnerability is not part of the test.

The clock starts at awareness. Commission guidance C(2026) 5252 describes awareness as the point where, after an initial assessment, there is a reasonable degree of certainty that a vulnerability contained in the product is being actively exploited. Receipt of a report does not by itself start the clock. The Article 14 explainer gives the three deadlines and the awareness test in full.

The maintainer's position in the episode is a disclosure decision, not a legal trigger. A vulnerability that is public, or that the maintainer treats as public, has a higher chance of exploitation. Publication alone is not evidence of exploitation. The difference between exploitable and exploited decides which obligation applies.

What changes for vulnerability handling?

The pressure moves to Annex I Part II, the vulnerability handling requirements. Annex I Part II(2) requires manufacturers to address and remediate vulnerabilities in relation to the risks posed by the product. Annex I Part II(4) requires public disclosure of fixed vulnerabilities including the affected product, the impact, the severity, and remediation information.

PressureWhat the episode describedWhat a manufacturer can change
VolumeMore vulnerability reports arrive, and more of them are validGive every report a tracking ID and a triage deadline
DuplicatesThe same issue arrives in different formsLink each duplicate to one record, one fix and one advisory
SpeedLess time between discovery and exploitationAssess each report for signs of exploitation on the day it arrives
Fix qualityAI-proposed fixes tend to be localReview a proposed fix against the product architecture before release
Legacy productsSome products cannot be re-engineeredPlan compensating security measures around the product

What should a CVD policy say now?

Annex I Part II(5) requires a coordinated vulnerability disclosure policy. A policy written before AI-assisted research needs four more clauses.

  1. Accept AI-assisted reports, and ask the reporter to state the tools used and to supply a reproducible proof.
  2. Explain how duplicate reports are handled and how the first reporter is credited.
  3. State the target disclosure date and the conditions that move it earlier, for example independent discovery or evidence of exploitation.
  4. Name the security contact in a security.txt file so that reports reach the correct team.

The CRA-compliant CVD policy template is a starting point. The coordinated vulnerability disclosure guide explains the full process.

How does CVD Portal support this?

CVD Portal gives each manufacturer a public submission portal. Every report gets a tracking ID. The portal tracks triage deadlines, flags a submission as actively exploited, and starts the Article 14 timeline when a manufacturer escalates it. Every action is written to an audit trail that serves as compliance evidence.

Frequently asked questions

Does a vulnerability found by an AI tool start the CRA Article 14 clock?

No. Article 14 vulnerability notification applies to an actively exploited vulnerability. The way the vulnerability was found does not matter. The clock starts when the manufacturer becomes aware of active exploitation.

Is a publicly known vulnerability an actively exploited vulnerability under the CRA?

No. Public knowledge raises the chance of exploitation. Active exploitation needs evidence of real-world attacks that use the vulnerability. A manufacturer should assess a public vulnerability quickly, because exploitation can follow soon.

What should a CVD policy say about AI-assisted vulnerability reports?

A CVD policy should accept AI-assisted reports, ask the reporter for a reproducible proof, explain how duplicate reports are handled, and state the conditions under which the disclosure date can move earlier.

Stay compliant with the Cyber Resilience Act

Check your readiness with the Cyber Resilience Act checklist, or compare plans on pricing.

Create my free CVD portalCreate your free CVD portal

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.