Abayomi Ogayemi · International Journal of Information Security 2026 · 2026
DOI: 10.1007/s10207-026-01336-9
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Large language model (LLM) agents (systems that couple a language model with tools, memory, and orchestration so that they can plan and act with limited supervision) are entering production just as the European Union’s Artificial Intelligence Act (AI Act) and Cyber Resilience Act (CRA) begin to apply. Both instruments impose binding cybersecurity duties, yet both articulate outcome-oriented obligations rather than implementable safeguards, leaving providers, auditors, and market-surveillance authorities without a shared technical baseline. This article bridges that gap. Using doctrinal analysis, we decompose the cybersecurity-relevant provisions of the AI Act (Articles 9–15, 53, 55, and 72–73) and the CRA (Articles 13–14 and Annex I) into discrete obligation atoms, and we map each atom to concrete technical controls for LLM-based autonomous agents drawn from established control catalogues and recent agent-security research. The mapping is organised around an agent-specific threat model (prompt injection, tool poisoning, memory and retrieval poisoning, excessive agency, privacy attacks, and supply-chain compromise) and specifies, for every control, the verification evidence that supports conformity assessment and enforcement. We show how the CRA’s deemed-compliance mechanism can operationalise the AI Act’s cybersecurity requirement, analyse the enforcement timeline as amended in 2026, and identify residual gaps where neither instrument nor pending harmonised standards adequately captures agentic behaviour. The resulting obligation-to-control matrix offers a testable baseline for demonstrating, and enforcing, compliance.
No comments yet — start the discussion below.