EU CRA AI Risk Assessment: A Product-Level Method for LLM Calls
Article 13 of the EU Cyber Resilience Act requires manufacturers to assess and document cybersecurity risks throughout a product's lifecycle. For a product that depends on hosted LLM inference, the assessment must connect intended purpose, foreseeable use, assets, request paths, third-party components, and Annex I controls. This article provides a product-level method without treating every standalone model API or cloud service as directly regulated by the CRA.