Two areas are particularly relevant to CMYKForge:
- the EU Cyber Resilience Act, which introduces cybersecurity and vulnerability-reporting requirements for covered digital products;
- and the EU AI Act, which introduces transparency requirements for certain AI systems and AI-generated content.
CMYKForge is based outside the European Union, but we expect the software to be available to customers in Europe.
Because of that, our location outside the EU does not automatically remove these requirements. Where EU law applies to CMYKForge, we intend to comply with it.
Cyber Resilience Act Reporting Requirements
Beginning September 11, 2026, new reporting obligations under the EU Cyber Resilience Act apply to covered manufacturers of products with digital elements.
These requirements focus on specific cybersecurity events rather than ordinary software bugs.
Covered manufacturers may be required to report:
- actively exploited vulnerabilities;
- and severe security incidents affecting their products.
For qualifying events, an early warning may be required within 24 hours of becoming aware of the issue, followed by a more detailed notification within 72 hours. Additional final reporting requirements may also apply depending on the type of incident. Digital Strategy EU
CMYKForge is beginning to prepare the processes needed to support these obligations.
That includes work around:
- vulnerability reporting;
- incident triage;
- preserving relevant records and timestamps;
- identifying affected versions;
- coordinating fixes;
- and determining when an issue may need to be escalated through the EU reporting system.
This does not mean every CMYKForge bug becomes a regulatory report.
Most normal software defects will not meet the threshold.
The focus is on qualifying cybersecurity vulnerabilities and serious security incidents.
A Public Reporting System
As part of this work, we are also considering a more formal reporting area on the CMYKForge website.
The goal would be to make it easier for users and researchers to:
- report ordinary bugs;
- privately report security vulnerabilities;
- review known product issues;
- and eventually view published security advisories after issues have been appropriately addressed.
Security reports would not automatically be published while a vulnerability is still exploitable. The purpose of transparency is to help users, not provide instructions for attacking unpatched systems.
AI Act Transparency Requirements
The second area involves CMY-AI.
Article 50 of the EU AI Act includes transparency requirements for certain AI systems beginning August 2, 2026. Digital Strategy EU
One of the clearest requirements is that people interacting directly with an AI system should know that they are interacting with AI.
For CMY-AI, our intention is to make that clear directly in the product rather than relying only on the name.
CMY-AI will be presented as an AI assistant, and users should be able to understand when AI-generated reasoning, recommendations, or responses are involved.
AI-Generated Content and Marking
The AI Act also includes requirements around certain AI-generated or manipulated content.
Providers of systems generating synthetic text, images, audio, or video may need to ensure those outputs contain machine-readable markings that allow their AI-generated origin to be detected. AI Act Service Desk
This does not mean every CMYKForge project, 3MF file, preview, or physical print automatically needs a visible AI watermark.
CMYKForge's ordinary color-processing, geometry-generation, and 3MF-generation systems are not automatically transformed into generative-AI content simply because CMY-AI exists elsewhere in the application.
The relevant requirements need to be applied to the specific AI-generated outputs that fall within the law.
For CMY-AI, the marking work is intended to cover generated text and any future features that create or substantially manipulate media where applicable. My development goal is a detectable watermark that remains useful after some editing, but resistance to removal has not been established. Removing or weakening a signal may still be possible with enough effort.
The dedicated watermark page explains the current limitations: the experimental checker runs locally, detection accuracy has not been established, and public checking is not available. Supported third-party formats would be added only where verification tools are available. This research is not a guarantee of detection, removal resistance, or regulatory compliance.
We are reviewing how those requirements should be implemented technically before CMY-AI is released to customers in the EU.
A Consistent Experience Across Regions
As of today, we do not plan to create a separate version of CMYKForge solely for the European Union.
Where practical, transparency, security, and reporting improvements introduced to meet regional requirements will be incorporated into CMYKForge more broadly rather than restricted only to users in that region. We believe users should receive a consistent experience wherever possible, and maintaining one core product also simplifies development, testing, and long-term support.
Different jurisdictions can impose different requirements, so there may be situations where regional differences are necessary. If our approach changes materially, we intend to communicate that rather than making significant changes silently.
What We Are Not Claiming
We want to be careful with the word compliance.
The Cyber Resilience Act and AI Act contain broader obligations than the specific requirements discussed here. CMYKForge is not claiming that every future obligation under either law has already been completed.
Instead, our position is straightforward:
Where EU cybersecurity and AI transparency requirements apply to CMYKForge, we intend to meet them.
That means building the processes before they are urgently needed.
For security, that means having a reporting and response system in place before a qualifying incident occurs. For CMY-AI, that means making AI involvement clear and designing the system around applicable transparency and marking requirements before public release.
Why We Are Addressing This Now
CMYKForge is still approaching its broader public release.
That makes this the right time to establish these systems.
It is much easier to design security reporting, AI transparency, and compliance processes into a product before large numbers of customers depend on it than to retrofit them later. Reliability has always been one of CMYKForge's core priorities.
Security and transparency are part of that same responsibility.
As CMYKForge expands into additional markets, we intend to keep adapting the product and its internal processes to the requirements that come with operating there.