From obligation to enforcement: mapping EU AI act and CRA cybersecurity requirements to technical controls for LLM-based autonomous agents

Abstract Large language model (LLM) agents (systems that couple a language model with tools, memory, and orchestration so that they can plan and act with limited supervision) are entering production just as the European Union’s Artificial Intelligence Act (AI Act) and Cyber Resilience Act (CRA) begin to apply. Both instruments impose binding cybersecurity duties, yet both articulate outcome-oriented obligations rather than implementable safeguards, leaving providers, auditors, and market-surveillance authorities without a shared technical baseline. This article bridges that gap. Using doctrinal analysis, we decompose the cybersecurity-relevant provisions of the AI Act (Articles 9–15, 53, 55, and 72–73) and the CRA (Articles 13–14 and Annex I) into discrete obligation atoms, and we map each atom to concrete technical controls for LLM-based autonomous agents drawn from established control catalogues and recent agent-security research. The mapping is organised around an agent-specific threat model (prompt injection, tool poisoning, memory and retrieval poisoning, excessive agency, privacy attacks, and supply-chain compromise) and specifies, for every control, the verification evidence that supports conformity assessment and enforcement. We show how the CRA’s deemed-compliance mechanism can operationalise the AI Act’s cybersecurity requirement, analyse the enforcement timeline as amended in 2026, and identify residual gaps where neither instrument nor pending harmonised standards adequately captures agentic behaviour. The resulting obligation-to-control matrix offers a testable baseline for demonstrating, and enforcing, compliance.

Authors

Publication Details

Journal
International Journal of Information Security
Published
2026-09-18
DOI
https://doi.org/10.1007/s10207-026-01336-9
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

From obligation to enforcement: mapping EU AI act and CRA cybersecurity requirements to technical controls for LLM-based autonomous agents

Abayomi Ogayemi
International Journal of Information Security
Ethics and Social Impacts of AI
article

From obligation to enforcement: mapping EU AI act and CRA cybersecurity requirements to technical controls for LLM-based autonomous agents

Abayomi Ogayemi
article en

Abstract

Abstract Large language model (LLM) agents (systems that couple a language model with tools, memory, and orchestration so that they can plan and act with limited supervision) are entering production just as the European Union’s Artificial Intelligence Act (AI Act) and Cyber Resilience Act (CRA) begin to apply. Both instruments impose binding cybersecurity duties, yet both articulate outcome-oriented obligations rather than implementable safeguards, leaving providers, auditors, and market-surveillance authorities without a shared technical baseline. This article bridges that gap. Using doctrinal analysis, we decompose the cybersecurity-relevant provisions of the AI Act (Articles 9–15, 53, 55, and 72–73) and the CRA (Articles 13–14 and Annex I) into discrete obligation atoms, and we map each atom to concrete technical controls for LLM-based autonomous agents drawn from established control catalogues and recent agent-security research. The mapping is organised around an agent-specific threat model (prompt injection, tool poisoning, memory and retrieval poisoning, excessive agency, privacy attacks, and supply-chain compromise) and specifies, for every control, the verification evidence that supports conformity assessment and enforcement. We show how the CRA’s deemed-compliance mechanism can operationalise the AI Act’s cybersecurity requirement, analyse the enforcement timeline as amended in 2026, and identify residual gaps where neither instrument nor pending harmonised standards adequately captures agentic behaviour. The resulting obligation-to-control matrix offers a testable baseline for demonstrating, and enforcing, compliance.

International Journal of Information SecurityVol. 25(5)
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.