By Callie Reis, VP Industrial Automation Advisory Services, Schneider Electric

From September 11, 2026, the EU Cyber Resilience Act (EU CRA) requires manufacturers of products with digital elements placed on the EU market to report actively exploited vulnerabilities and severe security incidents affecting those products. The reporting clock is short: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available for a vulnerability, or within one month of the notification for a severe incident.

The obligations do not fall on every industrial operator. They apply to manufacturers, and they can reach vendors and system integrators that supply or substantially modify connected hardware or software placed on the EU market, including products used in critical infrastructure across oil and gas, chemicals, mining, water utilities and energy grids.[1] The EU’s separate NIS2 directive adds further obligations for the operators of that infrastructure directly. Between the two, early visibility, vulnerability handling and incident detection now carry regulatory weight. At the same time, however, many industrial systems and networks were built for control, not for visibility.

Industrial AI and autonomous operations do not scale without managed cyber risk

Autonomous operations and industrial AI can support productivity as industrial complexity increases, but neither scales without a clear view of cyber risk. That view depends on breaking down industrial data silos and putting AI to work on threat detection.

Our own representative market survey data shows that over a third (39.8 percent) of global CPG manufacturers say AI already plays a significant or critical role in their approach to cyber compliance,[2] suggesting that cyber readiness and the adoption of AI and autonomous operations are converging priorities.

Threat detection starts with identifying and breaking down data silos

Much industrial data still sits locked in systems that were never designed to communicate. The major AI players have demonstrated that once they have access to contextualized, real-time data, they identify anomalies faster than ever before. A security team’s ability to detect a threat, and a company’s ability to report one can be significantly improved with an end-to-end cyber monitoring system, enabled by AI.

In Schneider Electric’s 2026 Industrial AI in CPG global study, respondents point to legacy automation systems and infrastructure (37.5 percent) and a lack of contextualized operational data (36.3 percent) among the biggest obstacles to scaling industrial AI, both data problems rather than technology gaps.[3] In a study of 400 senior energy and chemicals executives across 12 countries for Schneider Electric’s Global Autonomous Maturity Report almost a third of leaders cite legacy systems, and a quarter cybersecurity concerns, as key barriers to autonomous adoption.[4]

Investment in managing cyber risk needs to keep pace with investment in autonomous, AI enabled operations

Cyber resilience investment should keep pace with investment in autonomous, AI-enabled operations to support CRA readiness.

Schneider Electric’s Global Autonomous Maturity Report shows the energy and chemicals industry ramping up investment in autonomous operations by 2030 as AI reshapes performance, with a third ranking advancing autonomy a ‘critical’ priority in the next five years. Organizations report operating at 70 percent autonomy today, with plans to reach 80% by 2030, moving from level 3 to level 4 maturity on ARC’s Autonomous Operations Maturity Model.

More than half (54.2 percent) of global CPG decision makers call advancing autonomous operations a critical or high priority by 2027, yet only 13 percent say AI is embedded end to end in core operations today.[5]

Connected data is the same foundation for autonomy and for compliance

One response to this convergence of pressures is to connect industrial data across the plant, then build cybersecurity into that connected environment from the design stage. Continuous monitoring, delivered by teams that understand both the process and the threat, allows cyber and operational anomalies to be identified and acted on as operations run.

That same visibility that supports predictive maintenance and self-optimizing production lines can also help a manufacturer identify an intrusion or an anomaly earlier. SE Advisory Services works with industrial organizations to harden OT assets, apply zero trust principles and maintain continuously monitored environments, using an approach aligned with IEC 62443. Managed well, cybersecurity supports operational continuity and productivity rather than sitting on the balance sheet as a cost of operating in a regulated market.

Other experts from Schneider Electric, added:

Cécile Vercellino, SVP Services & Advisory, Industrial Automation, Schneider Electric: “Technology was never the hard part of digital industrial transformation, and cyber compliance is no different. The programs that succeed pair platforms and tools with equal investment in change management and workforce capability. Building that capability alongside the technology is what turns a compliance obligation into a lasting operational advantage.”

Zakarya Drias, Head of Cybersecurity Portfolio, Schneider Electric: “Cybersecurity is what makes digital transformation possible. Once your data becomes monetizable, it becomes valuable, and it needs to be managed accordingly. Cybersecurity is the trust layer for digital transformation. It gives organizations the confidence to adopt AI, cloud and automation, and to connect their systems at scale. The scale and speed of threats is outgrowing human capacity. AI can analyze large volumes of data, identify patterns and surface risk far faster than a human team can. But cybersecurity is about managing risk, and that requires judgment. The most effective model is AI accelerated and human led, where AI augments human expertise rather than replacing it. Look at detection and response. We moved from organizations not noticing incidents at all, to knowing about them but taking a long time to respond. What AI brings is speed of response, because it processes a much wider set of context, not just security data but operational data as well. AI becomes part of the autonomous operations stack, which means it is now an asset you have to manage. The risk around the AI itself, the data and the models belongs in the risk register alongside everything else.”

Neil Smith, President, CPG, Schneider Electric: “Cyber regulation is the single highest-cited top-three business pressure in the 2026 AI in CPG global study (39.4%). Today, regulatory and compliance costs reach 11.6% of product price for CPG manufacturers globally, on par with manufacturer margin (11.0%). The Cyber Resilience Act’s September deadline lands exactly as CPG manufacturers are moving from AI pilots to embedding AI end-to-end in their operations. Meeting the regulation and scaling industrial AI run on the same foundation of real-time, trustworthy operational data. Manufacturers who build that foundation now unlock the AI-driven productivity gains the industry needs to overcome increasing operational complexity.”

 


[2]  Source: Global 2026 Industrial AI in CPG Survey underlying data, 1,453 C-suite and senior manufacturing decision-makers, food & beverage and life sciences, 14 countries, fieldwork 26.02.2026–24.03.2026.
[3] Source: Global 2026 Industrial AI in CPG Survey underlying data, 1,453 C-suite and senior manufacturing decision-makers, food & beverage and life sciences, 14 countries, fieldwork 26.02.2026–24.03.2026.
[4] Source: Schneider Electric Global Autonomous Maturity Report, 400 senior energy & chemicals executives, 12 countries, published 23/03/2026 — a separate study, energy & chemicals sector, included here as external benchmark only.

[5] Source: Global 2026 Industrial AI in CPG Survey underlying data, 1,453 C-suite and senior manufacturing decision-makers, food & beverage and life sciences, 14 countries, fieldwork 26.02.2026–24.03.2026.