IoT is, by nature, a major producer of data, and it is therefore no surprise that it benefits from the convergence of IoT and AI, one of the most discussed technology trends right now and arguably two of the closest BFFs of digitalisation. As these technologies move closer together, the boundaries between them are becoming increasingly blurred.
A connected sensor device is no longer just a sensor connected to a network. A platform is no longer merely a dashboard presenting data. Intelligence is being embedded throughout the entire solution stack, from edge devices to cloud platforms, and AI is becoming an integral part of almost every aspect of connected systems.
At the same time, regulators have not been standing still. This summer, three important European regulations will enter the IoT market as major milestones, marking a set of changes that will reshape the future regulatory landscape for connected devices.
While they address different domains, they share a common theme: they will influence how connected products are designed, operated and maintained across their entire lifecycle.
A turning point for IoT: three EU regulations arriving this summer
The first date is August 2, when provisions of the AI Act begin to apply. For organisations integrating AI into products (think edge devices with real embedded ai) and services, this marks the transition from discussing responsible AI to demonstrating it in practice. While some high-risk applications have longer transition periods, many obligations start becoming relevant now.
IoT just entered its compliance era — and this is the second trigger dates
The second date is September 11, when key reporting obligations under the Cyber Resilience Act (CRA) take effect.
For manufacturers of connected products, cybersecurity no longer ends when the product ships. From this date, organisations must be prepared to report actively exploited vulnerabilities and severe security incidents within defined timelines.
In practice, this means that vulnerability management can no longer be handled informally. Manufacturers need processes for identifying, tracking and assessing vulnerabilities, monitoring products in the field and maintaining the capability to deliver security updates throughout a clearly defined product support lifetime. For many IoT vendors, the challenge is not the reporting itself. The challenge is establishing the internal processes required to detect and assess incidents quickly enough to meet the new obligations.

The third date follows immediately after. On September 12, the Data Act begins to apply more directly to newly introduced connected products and related services. The regulation changes the relationship between manufacturers, customers and the data generated by connected products. Users must be able to access data generated by the devices they use and, under certain circumstances, request that the data is shared with third parties. For manufacturers, this means that data ownership can no longer be treated as a purely commercial decision.
Product architecture, APIs, cloud platforms and data management strategies increasingly need to be designed with data portability and accessibility in mind. For organisations building connected products, these requirements are likely to influence both technical design choices and future business models.
Individually, these regulations address different aspects of connected products. Together, they provide a useful indication of where the European market is heading.
For manufacturers, the implications are practical rather than theoretical. AI functionality must be documented and governed, cybersecurity incidents must be managed and reported, and users will gain stronger rights to access the data generated by connected products.
Whether you are building devices, platforms or complete solutions, these are three dates worth keeping on your radar.
The convergence of IoT and AI is creating new opportunities. This summer also reminds us that it brings new responsibilities.

