Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents

A structural shift in regulatory accountability now places incident notification and liability directly on the operators or deployers of AI-powered and software tools, rather than on technology vendors or model developers. This mechanism is made explicit by the requirements of the EU’s Cyber Resilience Act (CRA), Digital Services Act (DSA), and the upcoming Machinery Regulation. Incidents such as the Cursor AI coding agent breach at a Belgian chemical company underline that compliance timelines and regulatory scrutiny target the entity deploying the technology.

CrowdStrike and Okta both reported that increased enterprise security spending is being driven by heightened AI-generated attacks, according to their quarterly results. Gartner forecasts AI security spending will reach $4.8 billion by 2027, up 68.7% from this year, with usage control as the most dynamic segment. A public letter signed by over 100 vendors—including OpenAI, Anthropic, AWS, and Microsoft—warns of urgent defensive needs but does not shift responsibility to software suppliers.

Recent breaches and vulnerabilities illustrate how accountability remains with the service provider or end-user implementer. The Cursor breach assigned notification duties to AnySphere (the product vendor) and the breached organization, not to upstream model providers. Likewise, after N-able’s Passportal bug, MSPs were accountable for client-facing remediation. In each case, the “accountability line” lands on the party deploying the tool.

For MSPs and IT service providers, these trends require updating agreements, operations, and client communications. Service structures must prioritize regulatory response timelines, documentation, and clear reporting obligations. Providers serving EU clients, or those linked to global supply chains, will encounter business risk if they do not proactively address these regulatory demands before mandated deadlines.

00:00 Prevention Got A New Price

03:25 The Half That Doesn’t Move

05:50 Where The Call Lands

09:27 Why Do We Care?

Supported by:

Proofpoint

GoTo(LogMeIn)

💼 All Our Sponsors

MSP Radio is supported by our partners:

ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure

Supporting the IT services community through insights, analysis, and transparency.

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews

Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Leave a Reply