Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents
Business of Tech: Daily 10-Minute IT Services InsightsSeptember 04, 2026
2047
00:12:5711.94 MB

Accountability Shifts to Deployers as EU Sets Timelines for AI and Security Incidents

A structural shift in regulatory accountability now places incident notification and liability directly on the operators or deployers of AI-powered and software tools, rather than on technology vendors or model developers. This mechanism is made explicit by the requirements of the EU’s Cyber Resilience Act (CRA), Digital Services Act (DSA), and the upcoming Machinery Regulation. Incidents such as the Cursor AI coding agent breach at a Belgian chemical company underline that compliance timelines and regulatory scrutiny target the entity deploying the technology.

CrowdStrike and Okta both reported that increased enterprise security spending is being driven by heightened AI-generated attacks, according to their quarterly results. Gartner forecasts AI security spending will reach $4.8 billion by 2027, up 68.7% from this year, with usage control as the most dynamic segment. A public letter signed by over 100 vendors—including OpenAI, Anthropic, AWS, and Microsoft—warns of urgent defensive needs but does not shift responsibility to software suppliers.

Recent breaches and vulnerabilities illustrate how accountability remains with the service provider or end-user implementer. The Cursor breach assigned notification duties to AnySphere (the product vendor) and the breached organization, not to upstream model providers. Likewise, after N-able's Passportal bug, MSPs were accountable for client-facing remediation. In each case, the “accountability line” lands on the party deploying the tool.

For MSPs and IT service providers, these trends require updating agreements, operations, and client communications. Service structures must prioritize regulatory response timelines, documentation, and clear reporting obligations. Providers serving EU clients, or those linked to global supply chains, will encounter business risk if they do not proactively address these regulatory demands before mandated deadlines.

00:00 Prevention Got A New Price 

03:25 The Half That Doesn't Move

05:50 Where The Call Lands

09:27 Why Do We Care?

 

Supported by: 

Proofpoint 

GoTo(LogMeIn) 

💼 All Our Sponsors

MSP Radio is supported by our partners:

ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure

Supporting the IT services community through insights, analysis, and transparency.

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

[00:00:02] A chemical company in Belgium was breached last week. Not by a phishing email, not by a stolen password, but by an AI coding tool their engineers were already using. Somebody at that company now has 24 hours to notify a regulator, and it's not the company that built the tool. This is the Business of Tech. I'm Dave Sobel. Three groups voted independently on the price of security software, and none of them asked an MSP.

[00:00:32] We'll start with the market. CrowdStrike had its best trading day ever after a fiscal second quarter report that beat expectations. Okta rose nearly 29% of the same day after its own beat. Both CEOs attributed the numbers to the same thing. Enterprise customers are expanding security spending because artificial intelligence agents are increasing the volume and sophistication of the attacks landing on them.

[00:01:00] CrowdStrike said Falcon platform usage doubled year over year. Okta said new AI-related products are now close to a third of total bookings. The market took those two beats as forward-looking and repriced the whole sector inside a single trading session.

[00:01:18] Then the analyst. Gartner's forecast for the market that secures AI, reported by ARN this month, put spending at $4.8 billion by 2027, a 68.7% jump from this year and reaching nearly $7.7 billion by 2028. Inside that number, the fastest-growing slice is AI usage control, projected to grow 73% in a single year.

[00:01:44] That is analyst pricing on a market that did not exist 18 months ago. And every one of those figures is a number the buyer has already been told to plan against. And then the vendors themselves. More than 100 companies signed an open letter, signed by OpenAI, Anthropic, Amazon Web Services, Microsoft, and more than 100 others, saying organizations have months to strengthen defenses against AI-enabled attacks on critical infrastructure.

[00:02:11] That letter is a hundred companies telling their own customers to spend money. Take it as what it is. It also names the buying window with a specificity a vendor rarely uses in public. Months. Three votes. Same direction. Nobody consulted the MSP delivering any of it. None of them touched the other half of the bill for a different reason. If you're listening to this and haven't hit follow yet, on Apple Podcasts, search Business of Tech.

[00:02:40] Takes five seconds, and you'll get the next episode automatically. Here's a reality every MSP knows. Native Microsoft 365 security leaves gaps. Those gaps land on your desk. Proofpoint 365 Total Protection closes them. It's an MSP-first platform that unifies Microsoft 365 security backup and compliance into one integrated console.

[00:03:06] High security efficacy, less operational friction, and multi-tenant management that scales as you grow. Protect clients against modern threats and stop stitching point tools together. Built on Hornet security, now part of Proofpoint. See it at proofpoint-total-protection.com

[00:03:27] Nine days from now, on September 11th, Europe's Cyber Resilience Act begins requiring manufacturers to report actively exploited vulnerabilities within 24 hours of discovery. Full notifications go in within 72. A corrective report is due 14 days after a fix is available, and severe incidents get a one-month deadline.

[00:03:50] All of it flows through a single reporting platform coordinated by the European Union Agency for Cybersecurity, which comes online that same day. The Act covers every product with digital elements sold into the EU, so any global vendor with a European customer inherits the clock. That's one clock. There are two others.

[00:04:12] The European Commission has designated ChatGPT under the highest scrutiny tier of the Digital Services Act at 159 million European users. The designation triggers annual systemic risk assessments on illegal content, on minors, on mental well-being, on electoral processes. And OpenAI's first assessment is due by the end of November. Fines run to 6% of global turnover.

[00:04:38] That is a second clock, running against a different vendor with a different set of obligations. The third is further out. On January 20th of 2027, the European Union Machinery Regulation extends safety function oversight to AI-controlled equipment. Anthropic has already released a research preview standard describing how a model should safely operate a piece of hardware, encoding what a robot arm can and can't do, and its own answer to that regulation.

[00:05:08] So the vendors already know the calendar. They are writing the pre-answer. Notice what all three clocks have in common. Each of them names a specific party who owes something to a regulator by a specific hour. And in every case, the party named is not the model provider. It is whoever deployed the thing. That's the mechanism. The market can reprice the tool. The vendors can consolidate the tool.

[00:05:35] Neither of them can consolidate a name on a disclosure report. Because the whole point of naming it is that the name doesn't move. That name has to land on someone. This is what it looks like when it does. Last week, hackers weaponized an AI coding agent called Cursor. The product used across the industry to write code and reportedly deployed at SpaceX. And used it to breach a Belgian chemical company and six other firms.

[00:06:05] Not through phishing. Not through a stolen password. Through the agent itself. Which was already inside the environment doing the work it was hired to do. Now think about where September 11th's clock lands on that story. Under the CRA, any sphere, which makes Cursor, has 24 hours to notify a regulator of the actively exploited vulnerability. And 72 hours to file the full report. And under the EU's separate incident notification regime for critical sector operations,

[00:06:35] the Belgian chemical company has its own reporting duty on its own clock. Two specific parties. Two specific reports. Neither of them is Anthropic, whose model powers the tool. Neither of them is SpaceX, whose engineers were using it. In every case, the regulator named someone specific. And that someone is not the party that shipped the model. That is what the accountability call looks like when it arrives.

[00:07:02] Now scale it down to the MSP business, where it looks the same but comes at a smaller invoice. Two weeks ago, a critical bug in Enable's Passportal browser extension, the password vault used by more than 73,000 MSP techs each week, got rated a 9.4 out of 10. Enable patched it within 24 hours. Their internal security response team was credited for the speed. And then something else happened, worth naming out loud. Nobody moved off Passportal.

[00:07:31] There was no ripple. The MSPs running it read the advisory, applied the update, rotated where they had to, and stayed. Which is another way of saying, whatever discount the market once put on Enable for having been part of SolarWinds when Sunburst hit, several years ago, is measurably gone. The vendor sold, the customer stayed. The prevention half of the bill treats vendor history as a rounding error now. But note what did not go away. Every MSP running Passportal had a follow-on action they owed their own clients.

[00:08:01] Invalidate sessions, rotate high-value credentials, review vault activity. That's the shape of accountability landing on the delivery point. The vendor patched, the deployered answered. So here's your choice. And it's the same choice regardless of which side of the Atlantic you sit on. Rebuild your security book around the line that carries the name, the person who owns the disclosure clock, the number the client calls at 2 in the morning, the incident package that gets handed to a regulator or an insurer.

[00:08:31] Or keep pricing the install line in a market whose price is being set by an earnings day rally, a 100 signatory letter, and a September 11th deadline that all landed without asking. There is an objection to all of that a client will raise on the first call. It's worth saying explicitly. Here's a question MSPs don't ask often enough. How secure is the tool that has the keys to every one of your client endpoints?

[00:09:01] Your RMM is the most powerful and most targeted software you run. LogMeIn and Resolve was built with a zero-trust architecture specifically to close gaps that other RMMs leave open. If the security of your remote management platform is on your mind, and after the last few years it should be, LogMeIn is worth evaluating on exactly that. Visit LogMeIn.com

[00:09:30] Why do we care? The obvious objection is that clients do not pay for what they cannot see. And until they get an actual incident, an accountability line item looks like padding and the install line looks like service. But the point of the CRA calendar is that every client with EU exposure now has a fixed date after which they will absolutely see it. September 11th is the day the invisible half becomes the audited half,

[00:09:55] and every provider who spent this month billing on install alone is going to be renegotiating that renewal without a compelling answer for what they are doing about the reporting scene. So what to consider? Anchor the pitch on the date, not the incident. The pitch that lands in September is the one that names September 11th out loud, because it's the only pitch that flips the objection from we haven't had an incident to we don't have to wait for one.

[00:10:22] Send a one-page brief this week to every client with EU exposure, and every client whose largest supplier has EU exposure, and put the date and the 24-hour reporting cadence in the first paragraph. The window where naming the date is novel closes the date arrives. Bring an incident that's already happened. The Belgian chemical company breach is a public example a client can Google in 30 seconds.

[00:10:48] You didn't have to invent it, and the deployer named in the story is the same shape of party your client is. Use it. Walk into the review, save a sentence, and let the client picture their own name in the position the company is now in. The objection dies at the moment they see the shape of the party who owes the report and realize the shape is theirs. Price the pilot around the report, not the retainer. Do not open the accountability line by adding a fee to the existing agreement.

[00:11:17] Open it by pricing a single deliverable once at a real number. A tabletop exercise ending in a written incident package the client can hand to counsel or an insurer priced against the CRA cadence. That converts padding into artifact in one purchase. And if you get the price right, they buy the retainer next quarter for less than they would have negotiated a fee against a blank page.

[00:11:45] If this trend continues, by the middle of 2027, when the machinery regulation lands and the DSA assessment cycle has completed a full lap, the accountability line will be a standard schedule inside every professional services agreement in the sector. And the providers who did not open this one in September will be adding it against a benchmark price set by whoever moved first. This is the business of tech.

[00:12:11] What would you fix in your business with the right playbook? Small Biz Thoughts members get a library of templates and operational resources, recorded member calls, and classes through IT Service Provider University. Operational education built specifically for independent MSPs. Start at smallbizthoughts.org Interested in advertising? Head to mspradio.com slash engage.

[00:12:40] The business of tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network.