Friday, September 4, 2026

Cyber Resilience Act Compliance: 24-Hour Clock

The vulnerability report lands on a Friday afternoon. Someone on a security mailing list has proof that a bug in your firmware is being exploited in the wild, on customer devices, right now. Before 11 September 2026 that started a conversation with engineering. After it, it starts a stopwatch. Cyber Resilience Act compliance turns that moment into a filing deadline measured in hours, and the clock does not care that your incident lead is on a plane.

Timeline showing cyber resilience act compliance deadlines of 24 hours, 72 hours, 14 days
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to their national CSIRT: an early warning inside 24 hours, a fuller notification inside 72, and a final report once a fix exists. The rest of the Act follows in December 2027.

Why Does The 11 September Deadline Matter?

The 11 September 2026 date matters because it is the first Cyber Resilience Act obligation with real enforcement behind it, arriving well ahead of the full application of the Act at the end of 2027.

The mechanism is narrower than the headlines suggest. You file once, through the CRA Single Reporting Platform, to the computer security incident response team in the country where your main establishment sits, and that team passes it on to every other CSIRT where the product is sold. ENISA sees it at the same time. One filing, one platform, twenty-seven markets covered. Set against the patchwork most manufacturers already handle under other EU rules, including the transparency duties that came into force under the EU AI Act in August, this part is a real simplification.

The common advice right now is to wait for the harmonised standards before doing anything. That advice is wrong for reporting. Wrong for most of the Act, actually, but reporting is where it costs you soonest. Standards govern how you demonstrate that a product meets the essential requirements, and those obligations arrive more than a year later. Article 14 reporting does not wait for a standard. It needs a named person, a monitored inbox and a decision rule about what counts as evidence of exploitation, all of which you can build this month.

Cost is where this stops being an engineering conversation. The European Commission's 2022 impact assessment, the document that underpins the Act, priced compliance at roughly 2% of the €1.485 trillion of EU turnover the rules touch. That is the same order of magnitude producers found when packaging EPR reporting landed across seven US states this year, and the pattern rhymes. A rule written for accountability produces, first, a data collection problem.

Early warning

24 hours

To your national CSIRT

Average cost

€47,000

Per manufacturer, one-off

Firms in scope

615,272

The Commission's own count

Development uplift

30.5%

Added to build cost

Look at the development uplift on its own. It is not a fee you pay at the end, and it is not something a certification body sells you. It is threat modelling, dependency hygiene, a signed update channel and someone whose job is to say no to a shipping date. Firms already doing that will barely feel the Act. Firms treating security as a pre-launch audit will find that the money was never the hard part.

"

Twenty-four hours is not an incident response window. It is a notification window that opens before you know what you are dealing with, and the two are not the same thing.

What Cyber Resilience Act Compliance Costs

The Act charges a manufacturer twice, once to prove a product is secure before it ships and then continuously for its whole supported life, which is why the assessment fee everyone quotes understates the bill.

The numbers below are the ones a finance lead asks for first. Two of them are choices rather than fixed costs, namely the assessment route you take and how long you commit to supporting the product.

Category Detail Insight
Scope Cyber Resilience Act scope covers any product with digital elements sold in the EU, hardware and standalone software alike Software counts, not only devices
Trigger CRA reporting obligations fire on an actively exploited vulnerability or a severe incident, not on a routine CVE Evidence of exploitation, not suspicion
Second filing Actively exploited vulnerability reporting needs a fuller notification within 72 hours of awareness Two filings before day four
Final report 14 days after a corrective measure is available; one month for a severe incident The clock outlives the patch
Top fines Cyber Resilience Act fines reach €15m or 2.5% of worldwide annual turnover, whichever is higher Turnover test bites larger firms hardest
Lower tiers €10m or 2% for vulnerability handling failures; €5m or 1% for misleading information to authorities Paperwork errors carry their own tier
Assessment €18,400 per product to self-assess, against €25,000 for third-party conformity assessment Route choice moves the per-product bill
Support At least five years of security updates under Article 13(8), longer where expected lifetime is longer Cost runs long after launch day
Full effect The cyber resilience act deadline for everything else is 11 December 2027 Reporting is only the opening move

Read the fines rows twice. Each tier is an amount or a percentage of worldwide turnover, whichever is higher, so the ceiling scales with the company rather than with the product. A small firm's exposure sits near the cash figure. A large one's does not, and that asymmetry is deliberate.

EUR 13.13bn · Secure product development EUR 8.10bn · Conformity assessment EUR 7.80bn · Documentation, reporting, CE marking

Where the EUR 29 billion goes: the three shares of the total Cyber Resilience Act bill, from the same 2022 European Commission impact assessment.

How Do Manufacturers Comply Without Tripping Up?

Manufacturers comply by deciding now who files, from which legal entity, and on what evidence, because most first-year failures will be procedural rather than technical: the right facts, reported by the wrong entity, after the window closed.

Start with the definition, because it is doing more work than people expect. A vulnerability counts as actively exploited when there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. Reliable evidence, not a proof of concept, and not a scanner finding. A severe incident is one affecting the product's ability to protect sensitive data or functions, or one that has led to malicious code being introduced or executed. Both definitions are broad enough that your triage rule matters more than your detection tooling.

Small manufacturers feel this hardest, for the same reason they felt AI adoption hardest: the fixed cost of doing something properly does not shrink with headcount. The arithmetic in the real costs and honest ROI of AI agents for small business has the same shape here. What nobody can tell you yet is how proportionately enforcement will land on a small firm whose exposure arrived through an unmaintained dependency it did not write. The Act has language for open source stewards. Whether a market surveillance authority reads that language generously in year one is a guess, and the likelier outcome is that early enforcement targets firms that ignored a report rather than firms that filed a clumsy one.

  • End-of-life components. If a dependency stopped receiving fixes, you inherit the reporting duty for whatever it does next.
  • Entity confusion. The filing comes from the manufacturer, which in a group structure is often not the company whose name sits on the support portal.
  • Clock start. The window opens when you become aware, not when you finish investigating.
  • Contract gaps. Suppliers who owe you nothing on disclosure timing will quietly consume a window you cannot extend.

Three things to settle before the deadline

Name the filer. One person, one deputy, both reachable on a weekend, both with authority to submit without a legal review first.

Register early. Get onto the Single Reporting Platform before you need it, not during an incident at two in the morning.

Write the triage rule down. What counts as reliable evidence should be a document that survives an argument, not the argument itself.

If you make anything with software in it and sell it in Europe, the useful step this week is small. Find out which legal entity is the manufacturer, and give that entity a monitored address a CSIRT filing can come from. Most of the rest can wait a month. That cannot.

Thursday, August 27, 2026

Packaging EPR In 2026: What PPWR And Seven States Cost

The pallet shipped in June. The bill for it arrived in a completely different shape: a producer registration number, an annual report with a hard filing date, and a fee schedule keyed to the exact multi-layer laminate somebody specified back in 2019. On 12 August 2026 the European Union's Packaging and Packaging Waste Regulation began to apply, and seven US states already had live programs pulling data from producers. Packaging quietly stopped being a procurement line and became a filing obligation.

Packaging EPR In 2026: What PPWR And Seven States Cost

TL;DR: PPWR now applies across the EU, and seven US states run live packaging EPR programs. Recyclability, labelling and registration bite today. Recycled content and single use bans are deferred. Fees are eco-modulated, so the format you ship decides the bill, not the tonnage alone.

Why It Matters

Start with what is enforceable right now, because that is a much shorter list than the trade press suggests. PPWR's first tranche is design and paperwork. Every unit has to be recyclable. Heavy metals are capped across lead, cadmium, mercury and hexavalent chromium. Material composition travels on the pack as a pictogram now, not buried in a spec sheet. Producers must appear in a national register before anything is sold, distributors verify that they did, and online marketplaces assess the same evidence before listing. Brussels ran the identical staging pattern it used for the EU AI Act obligations that went live earlier this month: transparency duties first, the expensive structural rules years later.

The American side is messier, and messier is more expensive. Seven states now run packaging EPR, and 31 May 2026 dragged annual producer reports and pre program simplified reports into the same fortnight for six of them. That single clustered date is the part most teams underestimated. A filing is not a sustainability report. It wants unit counts, material weights and format detail per SKU, which means the material substitutions that have been reshaping supply chains since 2024 now have to be documented at the pack level rather than described in a slide.

And here is where the money actually sits. Eco-modulation means the fee is set by how hard your format is to recycle, not by how much of it you ship. Resource Recycling's April 2026 read of Colorado's interim base dues put more than $1.50 a pound between the cheapest and the most punished format, which is a bigger swing than most packaging teams have ever seen on a raw material line. So the cheapest option on the purchase order stops being the cheapest option on the year. It is the same shape as AI unit prices collapsing while enterprise bills climbed: the per unit number improves, the invoice does not.

Oregon Lifecycle Report

31 Dec 2026

Top 25 producers file

Late Filing Exposure

$10,000s / day

Reported penalty range

Separate PCR Filings

5 states

Outside the EPR reports

EU Recycled Content

10% to 35%

Plastic packaging from 2030

The penalty figure is the one that changes behaviour, and it changes it in an unhelpful direction. Because exposure accrues daily rather than per filing, a late or bounced submission turns into a running meter instead of a fine you can budget once and forget. That pushes teams toward filing something defensible on time rather than filing something accurate, and regulators have already started sending submissions back where the numbers do not line up. Nobody has built the audit capacity to catch that at scale yet.

"

The penalty runs by the day, not by the filing season. A late report is not a rounding error on your packaging spend. It is a meter.

What Actually Changed, Line By Line

Below is the part worth printing and taping to a wall, because the obligations arrived from four different directions and none of them share a vocabulary. Read it as a scope check rather than a calendar.

Category Detail What It Decides
EU Register National registers such as Germany's LUCID must list the producer before any sale No register entry, no legal EU sale
Green Claims Environmental claims permitted only where performance beats the PPWR minimum Generic recyclable wording stops working
Scope 3 formats pulled in: tea bags, coffee bags and permeable bags now count as packaging Previously exempt lines need labels
PCR Dates Connecticut, Maine and Washington file 1 April; New Jersey files 31 December Three states share one April date
Fee Logic Multi layer film, foam service ware and formats under two inches price highest Format choice sets the invoice
Litigation Oregon's program was enjoined in February 2026; SB 343 was challenged on 17 March 2026 Rules can move mid compliance cycle
Data Owner Pack specifications sit with suppliers while sales volumes sit in internal systems Filings bounce when the two disagree

Read that table again and notice how little of it is about recycling. Most of it is about evidence: who holds it, and how fast it can be produced when a program office asks. The calendar underneath is just as lopsided.

1 Aug 2026 4 Oct 2026 1 March 1 Jan 2030 California source reduction plans due SB 343 recyclability labelling enforced California annual recycled content report Annex V single use formats banned in EU

Four fixed points on the compliance calendar, running from California's source reduction plans through to the EU's single use bans at the start of 2030.

Friction Points

The standard advice this year is to hold off on redesign until the fee schedules settle. That advice is wrong, and it is wrong for a boring reason: the lead time on a format change is longer than the gap between fee announcements. Requalifying a laminate, revalidating a seal, retooling a line and clearing a customer's own spec review runs past a year in most categories. Wait for certainty and you will be paying the punitive rate through the whole requalification window you could have started in 2026.

The second problem is that eco-modulation is being sold as a recycling policy when it behaves like an industrial policy. That is my read, not a finding, and it is genuinely unsettled. If the fee gap is large enough to move material choice, it works. If it is small enough to pass through to the shelf price, it just becomes a consumption tax with extra paperwork, which is roughly what happened to every compliance regime that ended up squeezing whoever actually files. Nobody has a clean answer yet. Or rather, nobody outside the producer responsibility organisations does, and they are not publishing the elasticity data.

Then there is the software question. Compliance platforms are being pitched hard right now, and the honest arithmetic looks a lot like the real cost and ROI maths for small business automation: the tool is cheap, the data cleanup around it is not. Watch for these:

  • Supplier specification gaps. If your vendors cannot give you gram weights and layer structures per component, no platform will fix that for you.
  • SKU level mapping. Programs want packaging tied to units sold in that jurisdiction, which most ERP setups do not natively express.
  • Claims already printed. Artwork approved before October carries recyclability wording that becomes a legal exposure the moment enforcement starts.
  • Jurisdiction drift. An injunction in one state does not pause the filing clock in the other six.

Key Takeaways

One dataset, many owners. The filing needs supplier held specifications joined to internally held sales volumes. Whoever owns that join owns your compliance risk, and in most companies right now nobody does.

Cheapest on the PO is not cheapest on the year. Purchase price and fee exposure now point in opposite directions for exactly the formats procurement historically favoured.

Artwork is a legal document. Recyclability wording approved under the old rules does not grandfather in. Treat the label file as regulated content, not marketing content.

Pull your top twenty packaging formats by volume this week and score each one on two columns only: can a supplier give you the full material breakdown by weight, and would you defend its recyclability claim in front of a state program office. Anything scoring badly on both is your 2027 budget problem, and it is cheaper to find it now than in a bounced filing.

Thursday, August 20, 2026

AI Token Prices Collapsed In 2026 But Your Bill Grew

AI Token Prices Collapsed In 2026 But Your Bill Grew

Your finance lead forwards the August invoice with one question attached: why is this bigger than July when every vendor spent the summer cutting prices? Both halves of that question are true at once, which is exactly why nobody on the engineering side has a clean answer ready.

TL;DR: Per-token AI prices fell hard through mid-2026, and total AI bills went up anyway. Agentic workloads eat far more tokens per task than the chat queries most budgets were sized on, inference now outspends training, and few teams can see the meter running.

Why It Matters

The cuts were real, not marketing. Jefferies, working from Silicon Data's pricing index, tracked average inference pricing down to a 2026 low in the first week of August, crediting reductions of up to 80% on OpenAI's flagship rates plus constant downward pressure from cheap Chinese open-source models. Back in March this site argued that cheap AI model API pricing could not survive real serving economics. Half right, at best. The floor did not hold, but it fell instead of rising.

So the unit got cheaper and the bill got bigger. That only looks like a contradiction if you assume the unit of consumption stayed still, and it did not. Gartner's 2026 numbers show inference overtaking training spend for the first time in the industry's history, which is what happens when models stop being projects and start being production traffic that runs every minute of every day. On top of that shift, the shape of a single request changed. EY's 2026 analysis priced one agentic interaction at roughly $1.20 against $0.04 for a simple linear workflow, about thirty times the cost for what a budget line still calls "a request." Where the industry is still guessing, in my view, is whether that premium is a transitional inefficiency that better routing and caching will grind away, or the permanent price of letting software think in loops. Nobody has the data to settle it yet, and anyone claiming otherwise is selling something.

Average inference price

$1.16

Per million tokens, 8 August

Time to that low

10 weeks

Measured from 31 May

Agentic coding token use

1,000x

Versus code chat tasks

Inference share of AI cloud

55%

First year above training

That third number is the one that quietly wrecks a forecast. The researchers behind it, a Stanford Digital Economy Lab and Microsoft Research group publishing in April 2026, found the cost sits on the input side rather than the output side: an agent re-reads its own accumulated history into context at every step, so a task that produces four lines of code may have read a small library to get there. Charge that pattern at last year's prices and you still lose, because the workload grew faster than the discount. It also explains why the honest ROI maths on small-business AI agents looked so tight even when the sticker price per million tokens was falling every quarter.

"

Ten weeks took a million tokens down to $1.16. Your agents burn a thousand times more of them than a chat box ever did. The discount never had a chance.

What The 2026 Numbers Actually Say

Strip out the vendor blogs and the figures that survive come from three places: an investment bank reading a pricing index, an analyst house forecasting cloud spend, and a peer-reviewed measurement of what agents actually consume. Here is the short version worth having on one screen before the next budget review.

Category Detail Insight
Price index Average inference sat at $2.04 per million tokens on 31 May 2026 (Jefferies, Silicon Data index) Unit cost stopped being the binding constraint
Spend mix Gartner puts 2026 AI-optimised IaaS at $42 billion, of which inference takes $23.3 billion Running models now outspends building them
Token appetite Gartner's March 2026 work found agentic models use five to thirty times more tokens per task than a standard chatbot query Demand grows faster than prices fall
Forecast risk Models predict their own token consumption at correlations of only 0.39, and systematically guess low Estimates fail in the expensive direction
Visibility Only 31% of the 512 IT professionals in Flexera's 2026 State of ITAM survey report accurate visibility into AI software spend Most teams cannot see the bill forming
Next year Gartner sees the same category reaching $66 billion in 2027, with inference at 59% of it Budget pressure gets worse, not better

Read the rows together and the pattern is plain. Every line that describes price is improving. Every line that describes consumption, forecasting accuracy or visibility is getting harder to manage. A cost problem you can measure is an engineering problem. A cost problem nobody can see until the invoice arrives is a governance problem, and those get solved much later and much more expensively.

49% delaying or cutting AI work on cost · 51% pressing ahead KPMG, 2026, against an average planned AI budget of $188 million per organisation

Roughly half of surveyed organisations are already slowing or shrinking AI programmes on cost grounds, which is what a price war looks like from the buyer's side of the invoice.

Friction Points

The uncomfortable part is that most of this spending is not waste in the obvious sense. It is work getting done at a price nobody quoted. Flexera's 2026 survey found 59% of respondents reporting more wasted software spend year over year, and wasted is doing heavy lifting in that sentence, because a retry storm, an over-eager retrieval step and a genuinely useful agent all look identical on a token meter. You cannot tag what you cannot attribute.

Compliance adds its own quiet overhead, and it landed this month. The EU AI Act transparency duties that switched on in August mean disclosure text, logging and audit trails riding along with production traffic, and every one of those is tokens or storage or both. Small per call. Not small at a million calls. And it arrives in the same quarter finance decided to start asking questions, which is either bad luck or a useful forcing function depending on how your quarter is going.

Watch for these before the next invoice cycle:

  • Context growth, not call growth. Track average input tokens per task weekly. A flat call count with rising input size is the classic silent doubling.
  • Retries billed as work. Failed agent runs consume the full context before they fail (and yes, that includes the one that failed silently last Thursday). Meter them separately or they hide inside your success numbers.
  • Model choice by habit. The same task on two frontier models can differ by more than a million tokens. Route by task class, not by whichever model the team liked in January.
  • Estimates written by the model. If your capacity plan came from asking an assistant what a workload would cost, assume it guessed low and rebuild the estimate from logged runs.

Key takeaways

Gartner expects worldwide AI spending to reach $2.52 trillion in 2026, up 44% year over year, so the money is not going back in the box.

Cheaper tokens make experiments affordable and production expensive at the same time, and the second effect is larger.

Attribution beats negotiation right now. A per-team, per-workflow token view is worth more this year than another round of vendor discounts.

Stop treating the price sheet as the story. Pull last month's logs, split token spend by workflow rather than by vendor, and find the three workflows carrying the largest input growth. If you cannot produce that split by Friday, that gap is your actual problem, not the price per million tokens.