EU Unveils Comprehensive Action Plan on Cybersecurity and AI

Última actualización: 07/10/2026
  • The EU Action Plan on Cybersecurity and AI, published July 7, 2026, establishes four pillars to address risks and opportunities from advanced AI.
  • It leverages existing laws (AI Act, NIS2, DORA) and introduces new measures like a European AI evaluation capability and a secure testing platform.
  • Investments of €200M from EU programs and €100M from EIC Fund will support sovereign AI cybersecurity capabilities.
  • International cooperation with G7, bilateral partners, and NATO is a key component.

EU Cybersecurity and AI Action Plan

On July 7, 2026, the European Commission released its Communication COM(2026) 577 final, establishing the Action Plan on Cybersecurity and Artificial Intelligence. This initiative is a direct response to the challenges and opportunities posed by advanced AI in the cybersecurity domain, covering both defensive and offensive aspects.

The plan acknowledges that frontier AI models can significantly enhance threat detection, incident response, and overall cyber resilience. However, it also warns that the same capabilities—especially in open-source models—can be weaponized by malicious actors to launch more automated, scalable, and sophisticated cyberattacks. The EU aims to strike a balance by leveraging its existing legal framework, including the AI Act, the Cyber Resilience Act, NIS2 Directive, and DORA.

Riesgos de ciberseguridad en modelos de inteligencia artificial avanzada
Related article:
The Global Power Shift: Navigating the Cybersecurity Frontier of Advanced AI Models

A Framework Built on Existing EU Legislation

Starting August 2, 2026, the Commission will exercise its supervisory powers under the AI Act to oversee general-purpose AI models, particularly those posing systemic cybersecurity risks. This includes requesting information, conducting evaluations, demanding risk mitigation measures, and imposing fines of up to 3% of global annual turnover. The AI Act’s Code of Practice for general-purpose AI further specifies compliance requirements for advanced model providers.

Complementing this, the Cyber Resilience Act (applicable by end of 2027) mandates security-by-design for hardware and software products. The NIS2 Directive strengthens cybersecurity in critical sectors like energy and transport, while DORA focuses on the financial sector. The Cyber Solidarity Regulation enhances EU-wide detection, preparedness, and response to large-scale cyber threats.

EU Cybersecurity and AI Action Plan

Pillar One: Making Frontier AI Safe and Accessible

The first pillar focuses on ensuring the EU has the technical capacity to evaluate frontier AI models before deployment, facilitate access to advanced AI for European stakeholders, and coordinate secure testing environments. The Commission will launch a dedicated call to establish a European AI evaluation capability covering cybersecurity, expected to be operational by 2027. This will support the AI Office’s regulatory function by providing independent third-party assessments of model capabilities and risks.

In collaboration with ENISA, the Commission will develop a European Blueprint for structured access to advanced AI for cybersecurity purposes. This guidance will outline criteria for granting access to EU institutions, member state authorities, critical infrastructure operators, cybersecurity providers, and research entities. It will also include contingency measures if a third-country provider restricts or withdraws access.

plataforma de seguridad para código y nube
Related article:
Complete Guide to Code and Cloud Security Platforms

Additionally, ENISA and the Joint Research Centre (JRC) will set up a secure testing platform for AI in cybersecurity use cases, allowing operators of critical infrastructure to test advanced cyber-AI capabilities in simulated environments without exposing real systems.

EU Cybersecurity and AI Action Plan

Pillar Two: Preparing the EU Cyber Ecosystem for the AI Era

The second pillar addresses the need to prepare the European cyber ecosystem for AI-powered threats, with a focus on critical sectors and SMEs. The plan urges member states to transpose and implement NIS2 and DORA as a baseline, and to update risk management frameworks to anticipate more frequent and large-scale AI-driven attacks.

ENISA will issue guidance, recommendations, and best practices for protecting against AI-enhanced threats and for securely integrating AI tools into cybersecurity operations. In vulnerability management, ENISA will ensure that the European Vulnerability Database (EUVD) is adapted for AI-assisted vulnerability discovery. Member states are expected to update their coordinated vulnerability disclosure policies to address AI-enabled exploitation.

A key initiative is the Open Source Software Resilience Campaign, a pilot program where ENISA, the Commission, member states, and open-source communities will sponsor critical open-source projects to support their maintenance and security. ENISA will also build a catalog of AI-driven services to help patch vulnerabilities in open-source software.

ataque Shai-Hulud a la cadena de suministro de npm
Related article:
Shai-Hulud: el ataque que sacude la cadena de suministro de npm

Pillar Three: Scaling European AI Capabilities for Cybersecurity

The third pillar focuses on developing and deploying European AI-based cybersecurity solutions at scale. The EU is already investing around €200 million through Horizon Europe and Digital Europe programs until the end of the current Multiannual Financial Framework. By the end of 2026, the Commission will facilitate €100 million in EIC Fund investments in cybersecurity and AI startups as part of strategic defense technology investments.

The plan also highlights the need for sovereign frontier AI capabilities to avoid new strategic dependencies. Existing AI Factories and future Gigafactories will serve as part of a sovereign European AI and cybersecurity infrastructure. The Commission will support the development of sovereign European cyber-AI capabilities, including for defense, through the European Competitiveness Fund. Additionally, the EU Grand Challenge on AI for Cybersecurity will be launched to bring together companies, researchers, and organizations to develop innovative AI-driven cybersecurity solutions.

Pillar Four: International Cooperation

The fourth pillar recognizes the global nature of AI cybersecurity implications. The Commission will continue active engagement in the G7 to promote its approach and invite international partners to join efforts on open-source software security and vulnerability management adaptation. Bilaterally, the EU will deepen exchanges with partner countries on advanced AI and cybersecurity, prioritizing model evaluation, critical infrastructure protection, vulnerability mitigation, and cyber resilience improvement. Cooperation with NATO will also be strengthened regarding the opportunities and risks of frontier AI capabilities in the cyber domain.

Overall, the Action Plan represents a comprehensive effort to harness the benefits of advanced AI for cybersecurity while mitigating its risks. By building on existing regulations, creating new evaluation and testing infrastructures, investing in sovereign capabilities, and fostering international collaboration, the EU aims to ensure that its digital environment remains resilient in the face of rapidly evolving AI-powered threats. The measures are set to roll out from August 2026 onwards, with key milestones including the operational evaluation capacity by 2027 and the open-source resilience campaign in the third quarter of 2026.

guía de seguridad para dispositivos
Related article:
Ultimate Device Security Guide: Protecting Your Digital Life
Related posts: