Published September 29, 2026 · Added September 29, 2026

Eclipse Foundation on AI, open source, and CRA compliance

Electronic Specifier interviews Mikaël Barbero, Head of Security at the Eclipse Foundation, about AI in open source security and the EU Cyber Resilience Act now that manufacturers' reporting obligations began on 11 September 2026, while open source software stewards' Article 24(3) duties apply from 11 December 2027. Barbero says the foundation's work on Project Glasswing shows AI can uncover credible vulnerabilities but that remediation capacity is the bottleneck, argues that a manufacturer incorporating an open source component into a commercial product does not transfer its responsibility upstream, and points to the Open Regulatory Compliance Working Group and the OCCTET readiness toolkit.

Electronic Specifier interviews Mikaël Barbero, Head of Security at the Eclipse Foundation, about AI in open source security and the EU Cyber Resilience Act now that manufacturers’ reporting obligations began on 11 September 2026, while open source software stewards’ Article 24(3) duties apply from 11 December 2027. Barbero says the foundation’s work on Project Glasswing shows AI can uncover credible vulnerabilities but that remediation capacity is the bottleneck, argues that a manufacturer incorporating an open source component into a commercial product does not transfer its responsibility upstream, and points to the Open Regulatory Compliance Working Group and the OCCTET readiness toolkit.

Read the original story.

Source: Electronicspecifier