# EU Action Plan on Cybersecurity and AI

> Source: https://aiwiki.ai/wiki/eu_cybersecurity_and_ai_action_plan
> Updated: 2026-07-27
> Categories: AI Policy & Regulation, AI Safety
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution to "AI Wiki (aiwiki.ai)".

The **EU Action Plan on Cybersecurity and Artificial Intelligence** is a European Commission Communication, published as COM(2026) 577 final and adopted in Strasbourg on 7 July 2026, setting out how the European Union intends to handle the cybersecurity consequences of frontier AI models [1]. It is addressed to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions, and was presented by Executive Vice-President Henna Virkkunen, who holds the Tech Sovereignty, Security and Democracy portfolio [2][18]. The Commission's own summary describes the plan as bringing together EU countries, industry and EU-level organisations to strengthen the cybersecurity of the digital landscape against the vulnerabilities posed by advanced AI [14]. The Communication organises nine key actions under three pillars, most of them due in the third or fourth quarter of 2026, and reserves one, an EU capacity for pre-release evaluation of AI models, for 2027.

The single most important thing to understand about the document is what it is not. A Commission Communication is a policy instrument, not a legal one. It creates no new obligations for any company, imposes no new deadlines on Member States, and cannot be enforced against anyone. The Brussels law firm Van Bael & Bellis, in a 13 July 2026 client alert, put it plainly: rather than introducing new legislative obligations, the Action Plan builds on the EU's existing legal and regulatory framework [3]. Every binding requirement the plan discusses already exists somewhere else, principally in the [EU AI Act](/wiki/eu_ai_act), the NIS2 Directive and the Cyber Resilience Act. What the Action Plan adds is coordination, money, guidance documents and a set of deliverables owned by named EU bodies.

## Why the Commission acted when it did

The Communication opens with a diagnosis rather than a threat inventory. Frontier AI, defined in the document as the most advanced models available or under development, is described as bringing "unprecedented opportunities to enhance cyber resilience" while simultaneously becoming "a defining element of the threat landscape" [1]. The Commission cites research from the UK AI Security Institute suggesting that in controlled cybersecurity tests the length of tasks the most advanced models can complete without human help has been doubling over months rather than years, and a CERT-EU advisory from April 2026 arguing that AI is changing the economics of vulnerability discovery [1]. At the launch, Virkkunen said that "these advanced AI models can now build cyber exploits in minutes or hours at a fraction of the cost of vulnerability discovery by trained humans" [4].

Timing also mattered for enforcement reasons. As of 2 August 2026 the Commission begins exercising the supervisory and enforcement powers the AI Act gives it over general-purpose AI models, including models whose systemic risks relate to cybersecurity [1][2]. The plan lands four weeks before that date and reads in places like a statement of how the Commission intends to use those powers.

A third driver was access. Frontier models with the strongest offensive and defensive cyber capabilities are built almost entirely outside the EU, and in mid-2026 European institutions had a direct experience of what that dependency costs. ENISA, the EU Agency for Cybersecurity, was admitted in June 2026 to Project Glasswing, [Anthropic](/wiki/anthropic)'s controlled-access programme for critical infrastructure defenders, and was the first EU agency to join it [12]. Anthropic said on 2 June that it was extending the programme to approximately 150 new organisations based in more than 15 countries, among them operators in power, water, healthcare and telecommunications [5]. On 12 June the US government issued an export control order restricting foreign nationals' access to Anthropic's Fable 5 and [Claude Mythos 5](/wiki/claude_mythos_5) models, and Anthropic cut off access for non-US users [6]. Commission tech sovereignty spokesperson Thomas Regnier said at the time that "contingency measures taken in this light should not be discriminatory against partners" [6]. The controls were lifted on 30 June, though Mythos 5 remained restricted to vetted US organisations through Glasswing [7]. The Communication does not name any company, but its language about access being "determined by non-transparent, foreign-led processes" and its call for contingency measures in case access is "restricted or withdrawn" is difficult to read without that episode in mind [1].

## The three pillars

### Pillar 1: making frontier AI safe, accessible and deployable

The first pillar is about knowing what frontier models can do before they ship, and then getting European defenders lawful access to them. The Commission says it will launch a dedicated call to establish an EU evaluation capacity for AI models that must include cybersecurity, expected to be operational in 2027 [1][2]. The document is explicit that most leading third-party pre-deployment evaluators are currently based outside the EU and that this expertise and its infrastructure should sit inside the Union. The capacity is described as supporting compliance with the General-Purpose AI Code of Practice; a footnote states it will not be a conformity assessment body [1].

The second element is a **European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes**, to be defined by the Commission in coordination with ENISA by the fourth quarter of 2026 [1]. The Blueprint is a guidance document. It will set out criteria under which providers can grant access to EU institutions, Member State authorities, critical infrastructure operators, cybersecurity providers and research actors, and will include contingency measures for the case where access is restricted or withdrawn by a provider or a third-country authority. The Communication states directly that the Blueprint "will not introduce new obligations for providers" [1]. Where timely access is needed for general use, the Commission says it will explore joint procurement with Member States.

Third, ENISA and the Commission's Joint Research Centre are to build a secure testing platform for AI in cybersecurity use cases by the fourth quarter of 2026, extending existing cyber ranges rather than duplicating them. Participants would bring their own model access keys and cover their own costs; ENISA, in coordination with the JRC, is to govern access and aggregate outcomes [1]. The plan draws a careful distinction here: this platform tests whether a model is operationally suitable for a security task, which is a different exercise from evaluating a model for AI Act compliance.

### Pillar 2: preparing the EU's cyber ecosystem

The second pillar is largely a call to finish implementing rules that already exist. NIS2 and the Digital Operational Resilience Act "must therefore be transposed and implemented by Member States as a matter of urgency", and Member States "must consider the risks from advanced AI in their supervisory work" [1]. Critical sector operators and financial entities "should" review their risk management frameworks, reduce time-to-patch and anticipate AI-powered attacks at higher frequency and scale. These are exhortations attached to obligations that already bind their addressees under other instruments, not new duties created by the plan.

Vulnerability management gets the sharpest treatment. The Communication argues that existing handling processes must be upgraded for an era of AI-assisted discovery, that ENISA should ensure the European Union Vulnerability Database and the CRA Single Reporting Platform are fit for purpose, and that Member States should update national coordinated vulnerability disclosure policies to address AI-enabled exploitation. It also suggests the EU review whether the ISO/IEC standards underpinning CVD frameworks remain fit for purpose [1].

The concrete deliverable is a **Critical Open Source Resilience Campaign**, a pilot to be launched by ENISA in the fourth quarter of 2026 with the Commission, Member States, [open-source](/wiki/open_source_ai) communities, Union entities and industry. It takes the form of a voluntary sponsorship scheme matching open source projects with organisations willing to support their maintainers, plus an ENISA service catalogue of AI-powered services for patching and remediation. The Communication justifies the focus by citing the 2026 Black Duck Open Source Security and Risk Analysis report to the effect that 98% of the total codebase contains open source and that about 80% of codebases in critical infrastructure industries carry a high-risk or critical-risk vulnerability. The plan's own footnote gives the per-sector figures it draws on: 87% for aerospace, aviation, automotive, transport and logistics, 88% for manufacturing and for healthcare, 89% for energy, and 80% for internet and software infrastructure [1].

### Pillar 3: scaling European AI capabilities for cyber

The third pillar is industrial policy. The Commission points to roughly EUR 200 million committed by the end of the current Multiannual Financial Framework under Horizon Europe and Digital Europe for homegrown AI-enabled cybersecurity technologies and for the cybersecurity of AI, with three flagship Horizon Europe projects to launch at the end of 2026 [1]. By the end of 2026 it will enable European Innovation Council Fund investments into cyber and AI tech companies as part of EUR 100 million earmarked for strategic defence tech startups and scaleups, with similar support planned for 2027 [1][3].

Set against that, the Communication concedes that building sovereign frontier capability "will entail hundreds of billions of euro investment needs which can only be partly covered by public finances" [1]. Its answer is the new European equity capacity floated in the Tech Sovereignty Package of 3 June 2026, on which the Commission has opened consultations with Member States and the EIB Group. Other named vehicles include existing AI Factories and future Gigafactories, the European Competitiveness Fund, and the Scaleup Europe Fund. The Communication also points to steps already taken, among them the Frontier AI Grand Challenge, awarded on 19 June 2026 to the EUROPA consortium led by the Italian company Domyn to build an open-source frontier model of more than 400 billion parameters covering all 24 official EU languages, with access to EuroHPC computing capacity [1][15].

The pillar also lists a dedicated **EU Grand Challenge on AI-assisted vulnerability remediation**, to be launched in the fourth quarter of 2026 with the European Cybersecurity Competence Centre and ENISA. The rationale is a specific asymmetry: AI-enabled vulnerability discovery is advancing faster than AI-assisted remediation, which the plan says creates a structural imbalance favouring attackers [1]. On skills, the Commission and Member States are to develop training modules for cybersecurity professionals under the EU Cybersecurity Skills Academy by the fourth quarter of 2026, and ENISA is to fold AI competencies into the European Cybersecurity Skills Framework.

## Key actions and timelines

| # | Action | Owner | Target |
|---|---|---|---|
| 1 | EU evaluation capacity for AI models, including cybersecurity | Commission | 2027 |
| 2 | European Blueprint for structured access to advanced AI cyber capabilities | Commission with ENISA | Q4 2026 |
| 3 | Secure testing platform for AI in cybersecurity use cases | ENISA and the JRC | Q4 2026 |
| 4 | Guidance, advisories and best practices on AI-powered threats | ENISA with Union entities | As of Q3 2026 |
| 5 | Make vulnerability management practices fit for the AI age | Commission, Member States, ENISA, industry | As of Q3 2026 |
| 6 | Critical Open Source Resilience Campaign (first pilot) | ENISA with Commission, Member States, communities, industry | Q4 2026 |
| 7 | EU Grand Challenge on AI-assisted vulnerability remediation | Commission with ECCC and ENISA | Q4 2026 |
| 8 | Access to AI Factories compute for cyber resilience workloads | Commission with Member States | No date given |
| 9 | Training modules under the Cybersecurity Skills Academy | Commission with Member States and industry | Q4 2026 |

Source: COM(2026) 577 final, key action boxes in sections 2, 3 and 4 [1]; the Commission's factsheet reproduces the same dates in graphical form [13].

## How it sits in the EU legal framework

The Action Plan is a layer on top of instruments that are already law. It restates their status rather than changing it.

| Instrument | Reference | Status relevant to the plan |
|---|---|---|
| [AI Act](/wiki/eu_ai_act) | Regulation (EU) 2024/1689 | Commission supervisory and enforcement powers over general-purpose AI models apply from 2 August 2026; fines up to 3% of global annual turnover for systemic-risk providers |
| Cyber Resilience Act | Regulation (EU) 2024/2847 | Fully applicable 11 December 2027; secure-by-design and vulnerability management for products with digital elements |
| NIS2 Directive | Directive (EU) 2022/2555 | Risk management baseline across 18 critical sectors; transposition urged |
| DORA | Regulation (EU) 2022/2554 | Operational resilience for the financial sector |
| Cyber Solidarity Act | Regulation (EU) 2025/38 | EU Cybersecurity Reserve and large-scale incident response |
| Cybersecurity of Union entities | Regulation (EU, Euratom) 2023/2841 | Baseline for EU institutions, supported by CERT-EU and the IICB |
| Cloud and AI Development Act (proposed) | COM(2026) 502 final | Would expand EU data centre, cloud and AI capacity; not yet adopted |
| EU Open Source Strategy | COM(2026) 503 final | Frames the Critical Open Source Resilience Campaign |

The plan does not touch the AI Act's substance. Separately, the Commission's [Digital Omnibus](/wiki/eu_ai_act_digital_omnibus) package proposed amendments to AI Act timing and administrative requirements; the Action Plan assumes the AI Act's general-purpose AI provisions as they stand and does not reopen them.

## Three problems the plan treats as one

Policy documents in this area routinely blur three distinct issues. The Communication does discuss all three, but a reader benefits from separating them.

**AI as a cyber threat.** Offensive capability in frontier models, and the misuse of that capability by criminal or state actors, is the plan's opening argument. It is handled through AI Act systemic-risk supervision, pre-release evaluation, the Blueprint's access criteria, and preparedness measures under NIS2 and DORA. This is the same class of risk documented in incidents such as the [GTG-1002 AI-orchestrated espionage campaign](/wiki/anthropic_gtg_1002_espionage).

**AI as a cyber tool.** Using models for vulnerability discovery, triage, threat intelligence, detection and automated remediation is the subject of the testing platform, the Grand Challenge, the open source campaign and the skills work. The Commission repeatedly nudges organisations toward models that are already available, "including through open source", rather than waiting for frontier access. This is the ground covered on the wiki by [AI in cybersecurity](/wiki/ai_in_cybersecurity).

**Security of AI systems themselves.** Data and model poisoning, adversarial attacks and [prompt injection](/wiki/prompt_injection) are named explicitly in the plan, which says they "must also be carefully assessed and mitigated in line with relevant provisions of the AI Act" [1]. This receives the least dedicated machinery of the three. There is no key action assigned specifically to it, and the plan folds it into Cyber Resilience Act secure-by-design practice.

## International dimension

The final substantive section commits the Commission to pursuing the plan's objectives in bilateral and multilateral fora. Named channels include the G7 Digital and Tech and Cybersecurity Working Groups, where the Commission will promote cooperation on standards and model evaluation; the United Nations; bilateral digital and cyber dialogues; and the Network of Advanced AI Measurement, Evaluation and Science, coordinated by the UK AI Security Institute in collaboration with partner countries' [AI safety institutes](/wiki/ai_safety_institute) and the Commission's AI Office [1]. The plan also says the EU will strengthen exchanges with NATO, including through NATO's forthcoming Centre of Excellence on Artificial Intelligence. Separately, in the third pillar rather than this section, it commits the Commission to setting up a working group with ENISA, the European Defence Agency and Member States on the security risks of deploying frontier AI models in defence and dual-use critical systems [1].

## Reception

Reaction split along a predictable line: the diagnosis was widely accepted, the response was judged thin.

MEP Bart Groothuis (Renew, Netherlands) framed the stakes operationally, telling the plenary debate that "it's not business as usual anymore. Your software and IT systems will be tested by hackers, aided by the latest AI models. Hackers will operate at the speed of light and will try to put you out of business" [4]. MEP Aura Salla (EPP, Finland) redirected the sovereignty argument, saying that "our dependency is not primarily about AI models. It is about the infrastructure they rely on" [4]. Euronews itself characterised the Commission as having "little to offer beyond recommendations and an attempt to negotiate early access with US AI companies" [4].

Laurent Hausermann, writing at Cyber Builders on 13 July 2026, credited the Commission for acknowledging that frontier capability sits outside the EU and can be withdrawn, then attacked the arithmetic: the plan admits to investment needs in the hundreds of billions while allocating figures in the hundreds of millions. His summary of the Blueprint approach was "don't ask for access to foreign capabilities. Build capabilities that create balanced partnerships", and he argued that an evaluation capacity arriving in 2027 is late [8].

Luke O'Grady of the Center for Cybersecurity Policy and Law, writing on 16 July 2026, raised a structural problem the plan does not solve: the Cyber Resilience Act's vulnerability reporting framework was designed before AI-accelerated discovery, and a sharp rise in reports could overwhelm ENISA's processing capacity. He also warned that if EU evaluation processes diverge significantly from US ones, labs face inconsistent requirements and the result is fragmentation rather than assurance [9].

Industry bodies were mostly non-committal in the first weeks. techUK told members on 10 July that it would monitor implications and take a cyber-focused delegation to Brussels on 8 and 9 September [10]. ENISA had published its own report, "ENISA's view on Cybersecurity in the Frontier AI Era", on the same day as the Communication, describing an initial set of recommendations for building operational capability against machine-speed threats and saying it would align them with the Commission's plan [11].

The plan also arrived against a live grievance in the European Parliament. At an IMCO committee hearing on 14 July 2026, MEP Brando Benifei noted that when Anthropic gave 50 organisations early access to Project Glasswing in April 2026, not one was European; committee chair Anna Cavazzini and MEP Reinier Van Lanschot criticised the company for sending a technical staff member unable to answer policy questions on digital sovereignty [12].

## Comparison with the United States

The contrast with [America's AI Action Plan](/wiki/ai_action_plan), released by the White House on 23 July 2025, is instructive precisely because the two documents share a genre. Both are executive policy statements rather than legislation. Both assign work to agencies. Neither creates obligations on private parties by itself.

They differ in what they sit on top of. The US plan, subtitled "Winning the Race", is explicitly deregulatory in orientation and was accompanied by executive orders; its cybersecurity content centres on an AI Information Sharing and Analysis Center, Department of Homeland Security guidance on AI-specific vulnerabilities and threats, and promotion of secure-by-design AI [16][17]. Its authority derives from executive direction, because there is no federal AI statute underneath it. The EU plan derives its force from binding regulations already on the books, and much of its text consists of urging Member States and operators to implement law they are already subject to. The result is that the American document is trying to create a policy where none exists, while the European one is trying to make an existing legal framework operational. Both, on the cybersecurity side, converge on similar instruments: threat information sharing, secure-by-design, agency guidance and public funding.

The other structural difference is dependency. The US plan is written from the position of hosting the frontier labs. The EU plan is written from the position of negotiating access to them, and says so.

## Follow-up

The Communication closes by stating that the Commission "will regularly assess the implementation of the Action Plan and adapt actions where necessary" [1]. No review date, no reporting mechanism and no indicator set are specified. Because a Communication is not law, the plan's effect will be measured by whether the nine key actions ship on the quarters given and whether the funding described is actually committed, not by any compliance process.

## See also

- [EU AI Act](/wiki/eu_ai_act)
- [EU AI Act Digital Omnibus](/wiki/eu_ai_act_digital_omnibus)
- [AI in Cybersecurity](/wiki/ai_in_cybersecurity)
- [America's AI Action Plan](/wiki/ai_action_plan)
- [AI regulation](/wiki/ai_regulation)
- [Council of Europe Framework Convention on AI](/wiki/eu_coe_ai_convention)
- [Red teaming](/wiki/red_teaming)

## References

1. "Communication from the Commission: Action Plan on Cybersecurity and Artificial Intelligence, COM(2026) 577 final." European Commission, 2026-07-07. https://ec.europa.eu/newsroom/dae/redirection/document/130848
2. "Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence (IP/26/1544)." European Commission press release, 2026-07-07. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1544
3. "Commission presents Action Plan on Cybersecurity and Artificial Intelligence." Van Bael & Bellis client alert, 2026-07-13. https://vbb.com/wp-content/uploads/2026/07/13-7-26-Commission-presents-Action-Plan-on-Cybersecurity-and-Artificial-Intelligence.pdf
4. "Brussels pitches AI cybersecurity plan amid dependence on US models." Euronews, 2026-07-07. https://www.euronews.com/my-europe/2026/07/07/brussels-pitches-ai-cybersecurity-plan-amid-dependence-on-us-models
5. Geller, Eric. "Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators." Cybersecurity Dive, 2026-06-02. https://www.cybersecuritydive.com/news/ai-anthropic-claude-mythos-project-glasswing-expand/821714/
6. "US export controls on Anthropic 'should not be discriminatory,' EU Commission warns." Euronews, 2026-06-14. https://www.euronews.com/my-europe/2026/06/14/us-export-controls-on-anthropic-should-not-be-discriminatory-eu-commission-warns
7. "US lifts export controls on Anthropic's frontier cybersecurity AI models." The Record (Recorded Future News), 2026-07-01. https://therecord.media/us-lifts-export-controls-anthropic-cyber-models
8. Hausermann, Laurent. "Europe Must Sell Intelligence, Not Electrons." Cyber Builders, 2026-07-13. https://cyberbuilders.substack.com/p/europe-must-sell-intelligence-not
9. O'Grady, Luke. "European Commission Announces New Action Plan To Confront Cybersecurity Challenges in the Age of AI." Center for Cybersecurity Policy and Law, 2026-07-16. https://www.centerforcybersecuritypolicy.org/insights-and-research/european-commission-announces-new-action-plan-to-confront-cybersecurity-challenges-in-the-age-of-ai
10. Maiziere, Theo. "EU Commission publishes Action Plan on Cybersecurity and Artificial Intelligence." techUK, 2026-07-10. https://www.techuk.org/resource/eu-commission-publishes-action-plan-on-cybersecurity-and-artificial-intelligence.html
11. "ENISA's view on Cybersecurity in the Frontier AI Era." ENISA, 2026-07-07. https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era
12. Baker, Jennifer. "Brussels asked policy questions. Anthropic sent newcomer tech guy to answer." EU Perspectives, 2026-07-15, reporting the IMCO committee hearing of 2026-07-14. https://euperspectives.eu/2026/07/brussels-asked-policy-questions-anthropic-sent-newcomer-tech-guy-to-answer/
13. "Factsheet: Action Plan on Cybersecurity and Artificial Intelligence." European Commission, 2026-07. https://digital-strategy.ec.europa.eu/en/library/factsheet-action-plan-cybersecurity-and-artificial-intelligence
14. "New EU plan to address the risks and opportunities of advanced AI for cybersecurity." European Commission, 2026-07-07. https://commission.europa.eu/news-and-media/news/new-eu-plan-address-risks-and-opportunities-advanced-ai-cybersecurity-2026-07-07_en
15. "Commission selects EUROPA consortium as the winner of the Frontier AI Grand Challenge." European Commission, Shaping Europe's digital future, 2026-06-19. https://digital-strategy.ec.europa.eu/en/news/commission-selects-europa-consortium-winner-frontier-ai-grand-challenge-project-build-european-open
16. "Winning the Race: America's AI Action Plan." The White House, 2025-07. https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf
17. "White House unveils comprehensive AI strategy: Winning the race, America's AI action plan." White & Case LLP, 2025-07. https://www.whitecase.com/insight-alert/white-house-unveils-comprehensive-ai-strategy-winning-race-americas-ai-action-plan
18. "EU Action Plan on Cybersecurity and Artificial Intelligence." European Commission, Shaping Europe's digital future library entry, 2026-07-07. https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence

