Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents episode artwork

EPISODE · Sep 4, 2026 · 12 MIN

Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents

from Business of Tech: Daily 10-Minute IT Services Insights · host Dave Sobel

A structural shift in regulatory accountability now places incident notification and liability directly on the operators or deployers of AI-powered and software tools, rather than on technology vendors or model developers. This mechanism is made explicit by the requirements of the EU’s Cyber Resilience Act (CRA), Digital Services Act (DSA), and the upcoming Machinery Regulation. Incidents such as the Cursor AI coding agent breach at a Belgian chemical company underline that compliance timelines and regulatory scrutiny target the entity deploying the technology.CrowdStrike and Okta both reported that increased enterprise security spending is being driven by heightened AI-generated attacks, according to their quarterly results. Gartner forecasts AI security spending will reach $4.8 billion by 2027, up 68.7% from this year, with usage control as the most dynamic segment. A public letter signed by over 100 vendors—including OpenAI, Anthropic, AWS, and Microsoft—warns of urgent defensive needs but does not shift responsibility to software suppliers.Recent breaches and vulnerabilities illustrate how accountability remains with the service provider or end-user implementer. The Cursor breach assigned notification duties to AnySphere (the product vendor) and the breached organization, not to upstream model providers. Likewise, after N-able's Passportal bug, MSPs were accountable for client-facing remediation. In each case, the “accountability line” lands on the party deploying the tool.For MSPs and IT service providers, these trends require updating agreements, operations, and client communications. Service structures must prioritize regulatory response timelines, documentation, and clear reporting obligations. Providers serving EU clients, or those linked to global supply chains, will encounter business risk if they do not proactively address these regulatory demands before mandated deadlines.00:00 Prevention Got A New Price 03:25 The Half That Doesn't Move05:50 Where The Call Lands09:27 Why Do We Care? Supported by:Proofpoint GoTo(LogMeIn)  💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecureSupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Episode metadata supplied by the publisher feed · Published Sep 4, 2026

Embed this episode

A structural shift in regulatory accountability now places incident notification and liability directly on the operators or deployers of AI-powered and software tools, rather than on technology vendors or model developers. This mechanism is made explicit by the requirements of the EU’s Cyber Resilience Act (CRA), Digital Services Act (DSA), and the upcoming Machinery Regulation. Incidents such as the Cursor AI coding agent breach at a Belgian chemical company underline that compliance timelines and regulatory scrutiny target the entity deploying the technology.

Distinct summary based on available episode metadata or transcript content.

Ready to play

Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents

0:00 12:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Business of Tech: Daily 10-Minute IT Services Insights?

This episode is 12 minutes long.

When was this Business of Tech: Daily 10-Minute IT Services Insights episode published?

This episode was published on September 4, 2026.

Can I download this Business of Tech: Daily 10-Minute IT Services Insights episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!