Over the past three months, the same source sent the same warning twice. In May it was a signal — “the buyer’s questions have changed.” In July it was confirmation — “now that signal has a date on it.” Put the two scenes together and only one conclusion remains — the ability to read and respond to regulation is now a line in the export contract.
The buyer’s questions have changed
The story that came out of the ‘2026 AI & Cybersecurity Regulatory Response Seminar’, held by the Korean Agency for Technology and Standards (KATS) under the Ministry of Trade, Industry and Energy, was simple. Buyers used to ask only about a product’s features, price, and delivery; now, before signing, they check the scope of AI use, whether customer data is used for training, the security-update process, and the vulnerability-response procedure. The very language of inspection has changed.
What matters more is not ‘where you are’ but ‘whom you sell to.’ Even if your headquarters is in Korea, the moment you offer products and services to users in the EU or China, that country’s regulations apply directly.
The CRA countdown
Two months later, the European Commission released guidance detailing the scope of the Cyber Resilience Act (CRA). If May’s warning was a vague worry, July’s guidance was a concrete clock. The CRA places cybersecurity obligations on “products with digital elements,” reaching standalone software, connected devices, remote servers, and cloud functions.
Reporting is a race against the clock. An exploited vulnerability must be notified in stages, each within the next deadline.
Note the scope of responsibility. Even if a vulnerability originates in an external component or open source, if it is exploited in my finished product, I am the one who reports it. Security support runs for at least five years, and longer if the product is used for longer.
A map of four regulations and industries
The CRA is only one wave. Exporters face four regulations at once.
EU AI Act
Domains that affect individual rights — hiring, education, finance, healthcare. Transparency, non-discrimination, and human-review procedures are mandatory.
EU CRA (Cyber Resilience Act)
Every product with digital elements. Security requirements apply at every stage, from planning through maintenance.
NIS2
Broad reach — energy, transport, finance, health, manufacturing, digital services. Supply-chain security and incident-reporting duties.
AI Basic Act
Effective Jan 22, 2026. Sets obligations for high-impact AI, generative AI, and trustworthiness.
| Industry | What is regulated | Key issues |
|---|---|---|
| Beauty devices | Networked products | Data flows, security features, vulnerability response |
| Games | Recommendation algorithms, chatbots, generated content | Protecting minors, governing AI content |
| Manufacturing | AI process-control systems | Cross-border data transfer, remote-access controls |
| HR & matching | High-risk AI systems | Preventing discrimination and denial of opportunity |
| Home appliances | Networked products | Remote control, security updates, incident response |
| Logistics | AI dispatch and routing decisions | Human review and the ability to override |
The 45-day response playbook
You break through the fog with a sequence. In 45 days, CRA readiness can be raised to a ‘provable’ state.
Classify your products
- Judge whether the CRA and the AI Act apply to each product
- Inventory your products and the external components and open source they use
Build operational controls
- Stand up a chain from vulnerability intake → impact analysis → internal approval → EU notification
- Pre-assign an owner and an emergency contact line for each product
Prove it
- Check your notification forms and technical documentation
- Run a realistic drill and prove your controls through records
Two articles, one conclusion
May’s warning and July’s clock — across both stories, one voice ran through: the real gate in regulatory response is not a thick document but an unbroken operational flow.
“What matters is not so much whether our company sits in Korea, but which country’s users we provide our products and services to,” as that same executive put it, a structure is already forming in which regulatory-response capability becomes export competitiveness.
CONNECT AI sees this shift through the lens of sales intelligence. Regulatory response is not a cost; it is the strongest trust signal you can send a buyer. In an era where which regulation you passed, in which market, becomes the persuasive force of your proposal, MORI helps you read that signal, organize it, and translate it for the buyer.
