EDIH, EEN, Interreg: the platform for European programmes.Find out more

Analyses

AI Act, CRA, CEMAC overhaul: turning a stack of texts into one action plan

Within the same July 2026 fortnight, three regulators moved: the AI Act's 2 August milestone, ENISA's CRA maturity model, the overhaul of CEMAC's banking framework. Three texts, three calendars. And one choice: three separate compliance projects, or a single prioritised action plan.

26 July 2026 · 5 min read

All articles
Michael Aim

Michael Aim

Founder & CEO

Three signals, one fortnight

July 2026's regulatory calendar reads like a digest of the decade. On 2 August, a new stage of the European AI regulation enters into application: Article 50 transparency obligations (labelling generated content, conversational systems, deepfakes) and Commission enforcement powers over general-purpose models, with fines up to 15 million euros or 3% of worldwide turnover.

Three weeks earlier, on 13 July, ENISA published a self-assessment model for SME cyber-resilience maturity, aligned with the Cyber Resilience Act: five assessed domains, from governance to product lifecycle, a downloadable tool, and a classification into basic, intermediate or advanced maturity. And in Libreville, COBAC opened the bids of an international tender to revise its organic texts and draft a single banking law for the six CEMAC countries, set to replace the framework inherited from the 1990 and 1992 conventions.

The agency has since spelled out the reporting mechanism itself: a factsheet and two step-by-step guides to its single reporting platform, published in July 2026 and last updated on the 31st, while the platform is not yet open. It is due to go live on 11 September, the very day the obligation starts. For a manufacturer the practical consequence fits in one line: the EU Login account that opens access can be created now, whereas the testing window cannot be ordered.

Three regulators, three geographies, three subjects. Seen from an executive committee: three new projects on top of the existing ones, NIS2, CSRD, EUDR, depending on the sector. This is what compliance departments call, with growing weariness, the stack.

The silo reflex, and what it costs

Faced with each new text, the institutional reflex is always the same: a dedicated project, a dedicated owner, a dedicated consultancy, a dedicated spreadsheet. The reflex has a logic, since each text has its own regulator and its own sanctions. It mostly has a cost, which few organisations measure.

The first cost is redundancy: the same teams answer the same questions three times, give or take a phrasing. Who owns this system? Where is the inventory? How do you handle incidents? An industrial SME's CISO can spend a significant share of the year feeding questionnaires that overlap by two thirds.

The second cost is inconsistency: three separate projects produce three separate baselines, which quickly diverge. Executive management receives three severity levels, three budgets, three calendars, with no way to arbitrate between them. And the third cost is strategic: forever chasing each deadline, the organisation never builds the base that would let it absorb the next one.

What these texts require in common

Yet read July's three signals with a practitioner's eye. The AI Act first requires an inventory of AI systems and their uses, clear governance, provable documentation. The CRA, as ENISA's model breaks it down, assesses governance, risk management, vulnerability handling, product lifecycle, skills. A future CEMAC prudential framework will require, like every Basel-inspired framework, risk governance, documented arrangements, demonstrable internal control.

In other words: under different vocabularies, a large share of the requirements overlaps. Knowing what you operate (inventory of systems, products, processes). Knowing who decides (governance, responsibilities). Knowing what can go wrong (risk management). Knowing how to react (incidents, vulnerabilities, continuity). Knowing how to prove it (documentation, traceability). Five base capabilities, which each text then declines in its own domain.

It is precisely because this base is common that silo treatment is waste: each separate project rebuilds, at its own expense, an inventory, a risk map and a governance that the neighbouring project just paid for.

The method: one measured base, per-framework views

The alternative is not merging compliances into a single file, regulators would not allow it. It is separating two things the silo reflex conflates: the base, measured once, and the regulatory views, declined per text.

Concretely: a single maturity diagnostic assesses the base capabilities, inventory, governance, risks, incidents, documentation. Each assessed criterion is mapped to the texts it serves: this inventory control feeds both the AI Act and the CRA; that risk governance requirement serves the CRA and the future CEMAC framework. Measurement then reveals what silos hide: the collisions, those single actions that advance two or three compliances at once.

This is the audit-crossing principle: instead of stacking assessments, you make them talk to each other. An organisation measuring itself on three frameworks from a common base almost always discovers that its real backlog holds in a handful of transverse capabilities, not in three hundred distinct requirements.

Prioritising by deadline and by yield

What remains is ordering the action plan. Two criteria suffice, provided you cross them. Deadline first: 2 August 2026 is past or imminent depending on the reading, the CRA's main obligations arrive in late 2027, the future CEMAC text will follow its adoption procedure. Yield second: an action serving three texts is worth, at equal effort, three times an action serving one.

Crossing the two yields a natural sequence. Up front, the high-yield base capabilities: the inventory of AI systems and software products, risk governance, the incident arrangement. Then the specific deltas per deadline: Article 50 transparency marking for AI, the CRA's product requirements, prudential adjustments once the CEMAC text is published. At the tail, what can safely wait, documented as such.

This sequencing has a political virtue as much as a technical one: it gives executive management a single budget arbitration, a single trajectory, instead of three competing requests each claiming priority.

What it changes for steering

Steered this way, the stack changes nature. The base diagnostic becomes a reusable asset: when the next text arrives, and it will, the organisation will not start from zero, it will measure the delta. Reports decline per audience from the same data: the AI Act view for the relevant regulator, the CRA view for the buyers who will ask for it, the prudential view for the supervisor, the consolidated view for the executive committee.

And repeated measurement over time turns compliance into a trajectory: you no longer say "we are compliant", an unverifiable and perishable claim, but "here is our maturity, its progression and its plan", a dated and defensible demonstration.

Regulatory stacking is a reality that will not slow down; fragmented responses, however, are a choice. Organisations that make the opposite choice, one measured base, per-text views, one prioritised plan, do not face fewer texts than the others. They absorb them better, and cheaper.

The deadline cascade, August 2026 to 2028

  1. 1 May 2026

    EU·Mercosur agreement: provisional application, tariffs start falling.

  2. 8 Jul 2026

    NIS2: France referred to the CJEU for non-transposition, sanctions requested.

  3. 27 Jul 2026

    AI Act: the Digital Omnibus regulation (EU 2026/1744) enters into force.

  4. 2 Aug 2026

    AI Act: Article 50 transparency and sanctions on general-purpose models apply.

  5. 11 Sep 2026

    CRA: notification of actively exploited vulnerabilities and incidents to ENISA within 24 hours, on a platform due to open that same day.

  6. Autumn 2026

    France: expected examination of the Resilience law (NIS2 transposition).

  7. 24 Nov 2026

    CRMA: the Critical Raw Materials Act's sanctions leg activates.

  8. 30 Dec 2026

    EUDR: applies to large and medium companies (deforestation traceability).

  9. During 2027

    CS3D: final due diligence guidelines expected.

  10. 2 Dec 2027

    AI Act: obligations for Annex III high-risk systems (HR, scoring, education).

  11. 11 Dec 2027

    CRA: main obligations for connected-product manufacturers and software publishers.

  12. Aug 2028

    AI Act: high-risk systems embedded in regulated products (Annex I).