CRA vs. AI Act: How companies can expand their AIMS

25. September 2026 Vincent KI-Compliance CRA AI Act AIMS

The Cyber Resilience Act (CRA) and the AI Act are two central regulations that shape the handling of digital technologies and AI systems in Europe. Both laws aim to increase the security and transparency of software and AI, but they focus on different areas: The CRA focuses on the cyber security of products, while the AI Act regulates the development and deployment of AI systems. Although the requirements differ, there is overlap, especially with regard to the need to implement a robust AI management system (AIMS). Manufacturers can extend existing AIMS to meet both the CRA and the AI Act. This includes measures such as documenting risks, ensuring transparency and complying with compliance requirements.

The AI Act requires that AI systems be used transparently and responsibly. Companies must therefore develop clear guidelines for the use of AI and ensure that these systems are not discriminatory or dangerous. At the same time, the CRA focuses on product security, especially with regard to cyberattacks and vulnerabilities. Companies that develop AI systems or digital products must therefore ensure both the security and ethical responsibility of their technologies.

An AIMS is a system that helps companies manage and monitor their AI systems. It helps identify risks, meet compliance requirements and increase the efficiency of AI systems. To comply with the CRA, an AIMS must also include safety measures and risk assessments. At the same time, it must comply with the requirements of the AI Act by ensuring transparency and responsibility in dealing with AI. Extending an existing AIMS therefore requires a comprehensive analysis of current systems and the integration of additional functions covering both security and ethical aspects.

## What does this mean for your company? As an entrepreneur or employee, you need to ensure that your AI systems and digital products meet the requirements of CRA and AI Act. This means identifying risks, implementing security measures and creating clear guidelines for using AI. At the same time, you must ensure the transparency and responsibility of your technologies to build trust with customers and partners. It is important that you regularly review and adjust your systems in order to always follow the latest legal requirements.

## How ISN/xynap supports this The AI and compliance capabilities in xynap can help organizations meet the requirements of CRA and AI Act. With built-in tools for risk assessment, transparency and security, users can efficiently monitor and customize their systems to meet compliance requirements.

Sources (2)

  1. www.activemind.de
  2. www.heise.de