EU Action Plan on Cybersecurity and AI
The EU Action Plan on Cybersecurity and Artificial Intelligence is a European Commission Communication, published as COM(2026) 577 final and adopted in Strasbourg on 7 July 2026, setting out how the European Union intends to handle the cybersecurity consequences of frontier AI models [1]. It is addressed to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions, and was presented by Executive Vice-President Henna Virkkunen, who holds the Tech Sovereignty, Security and Democracy portfolio [2][17]. The Commission's own summary describes the plan as bringing together EU countries, industry and EU-level organisations to strengthen the cybersecurity of the digital landscape against the vulnerabilities posed by advanced AI [14]. The Communication organises nine key actions under three pillars, most of them due in the third or fourth quarter of 2026, and reserves one, an EU capacity for pre-release evaluation of AI models, for 2027 [1][13].
The document's legal status is central to interpreting it. Van Bael & Bellis wrote that the Action Plan does not itself introduce new legislative obligations and instead builds on the EU's existing legal and regulatory framework [3]. The binding requirements discussed by the plan arise from other instruments, principally the EU AI Act, the NIS2 Directive and the Cyber Resilience Act [1][3]. The Action Plan focuses on coordination, funding, guidance and deliverables assigned to named EU bodies [1].
Why the Commission acted when it did
The Communication opens with a diagnosis rather than a threat inventory. Frontier AI, defined in the document as the most advanced models available or under development, is described as bringing "unprecedented opportunities to enhance cyber resilience" while simultaneously becoming "a defining element of the threat landscape" [1]. The Commission cites research from the UK AI Security Institute suggesting that in controlled cybersecurity tests the length of tasks the most advanced models can complete without human help has been doubling over months rather than years, and a CERT-EU advisory from April 2026 arguing that AI is changing the economics of vulnerability discovery [1]. At the launch, Virkkunen said: "These advanced AI models can now build cyber exploits in minutes or hours at a fraction of the cost of vulnerability discovery by trained humans" [4].
Timing also mattered for enforcement reasons. As of 2 August 2026 the Commission begins exercising the supervisory and enforcement powers the AI Act gives it over general-purpose AI models, including models whose systemic risks relate to cybersecurity [1][2]. The plan lands just under four weeks before that date and reads in places like a statement of how the Commission intends to use those powers.
A third driver was access. The Communication says that frontier capabilities are mainly developed outside of the EU and that their availability is often determined by non-transparent, foreign-led processes [1]. In mid-2026 European institutions experienced the practical implications of relying on access controlled elsewhere. ENISA, the EU Agency for Cybersecurity, was admitted in June 2026 to Project Glasswing, Anthropic's controlled-access programme for critical infrastructure defenders, and was the first EU agency to join it [12]. Anthropic said on 2 June that it was extending the programme to approximately 150 new organisations based in more than 15 countries, among them operators in power, water, healthcare and communications [5]. On 12 June the US government issued an export control order restricting foreign nationals' access to Anthropic's Fable 5 and Claude Mythos 5 models [6]. Anthropic consequently suspended both models for all users [7]. Commission tech sovereignty spokesperson Thomas Regnier said at the time that "contingency measures taken in this light should not be discriminatory against partners" [6]. The controls were lifted on 30 June. Anthropic restored Mythos 5 to a set of US organisations and said it was working to expand access to domestic and international Glasswing partners [7]. The Communication does not name Anthropic or Project Glasswing. It calls for contingency measures if access is restricted or withdrawn by a provider or third-country authority [1].
The three pillars
Pillar 1: making frontier AI safe, accessible and deployable
The first pillar is about knowing what frontier models can do before they ship, and then getting European defenders lawful access to them. The Commission says it will launch a dedicated call to establish an EU evaluation capacity for AI models that must include cybersecurity, expected to be operational in 2027 [1][2]. The document is explicit that most leading third-party pre-deployment evaluators are currently based outside the EU and that this expertise and its infrastructure should sit inside the Union. The capacity is described as supporting compliance with the General-Purpose AI Code of Practice; a footnote states it will not be a conformity assessment body [1].
The second element is a European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes, to be defined by the Commission in coordination with ENISA by the fourth quarter of 2026 [1]. The Blueprint is a guidance document. It will set out criteria under which providers can grant access to EU institutions, Member State authorities, critical infrastructure operators, cybersecurity providers and research actors, and will include contingency measures for the case where access is restricted or withdrawn by a provider or a third-country authority. The Communication states directly that the Blueprint "will not introduce new obligations for providers" [1]. Where timely access is needed for general use, the Commission says it will explore joint procurement with Member States.
Third, ENISA and the Commission's Joint Research Centre are to build a secure testing platform for AI in cybersecurity use cases by the fourth quarter of 2026, extending existing cyber ranges rather than duplicating them. Participants would bring their own model access keys and cover their own costs; ENISA, in coordination with the JRC, is to govern access and aggregate outcomes [1]. The plan draws a careful distinction here: this platform tests whether a model is operationally suitable for a security task, which is a different exercise from evaluating a model for AI Act compliance.
Pillar 2: preparing the EU's cyber ecosystem
The second pillar is largely a call to finish implementing rules that already exist. NIS2 and the Digital Operational Resilience Act "must therefore be transposed and implemented by Member States as a matter of urgency", and Member States "must consider the risks from advanced AI in their supervisory work" [1]. Critical sector operators and financial entities "should" review their risk management frameworks, reduce time-to-patch and anticipate AI-powered attacks at higher frequency and scale. These are exhortations attached to obligations that already bind their addressees under other instruments, not new duties created by the plan.
Vulnerability management gets the sharpest treatment. The Communication argues that existing handling processes must be upgraded for an era of AI-assisted discovery, that ENISA should ensure the European Union Vulnerability Database and the CRA Single Reporting Platform are fit for purpose, and that Member States should update national coordinated vulnerability disclosure policies to address AI-enabled exploitation. It also suggests the EU review whether the ISO/IEC standards underpinning CVD frameworks remain fit for purpose [1].
The concrete deliverable is a Critical Open Source Resilience Campaign, a pilot to be launched by ENISA in the fourth quarter of 2026 with the Commission, Member States, open-source communities, Union entities and industry. It takes the form of a voluntary sponsorship scheme matching open source projects with organisations willing to support their maintainers, plus an ENISA service catalogue of AI-powered services for patching and remediation. The Communication justifies the focus by citing the 2026 Black Duck Open Source Security and Risk Analysis report to the effect that 98% of the total codebase contains open source and that about 80% of codebases in critical infrastructure industries carry a high-risk or critical-risk vulnerability. The plan's own footnote gives the per-sector figures it draws on: 87% for aerospace, aviation, automotive, transport and logistics, 88% for manufacturing and for healthcare, 89% for energy, and 80% for internet and software infrastructure [1].
Pillar 3: scaling European AI capabilities for cyber
The third pillar is industrial policy. The Commission points to roughly EUR 200 million committed by the end of the current Multiannual Financial Framework under Horizon Europe and Digital Europe for homegrown AI-enabled cybersecurity technologies and for the cybersecurity of AI, with three flagship Horizon Europe projects to launch at the end of 2026 [1]. By the end of 2026 it will enable European Innovation Council Fund investments into cyber and AI tech companies as part of EUR 100 million earmarked for strategic defence tech startups and scaleups, with similar support planned for 2027 [1][3].
Set against that, the Communication concedes that building sovereign frontier capability "will entail hundreds of billions of euro investment needs which can only be partly covered by public finances" [1]. Its answer is the new European equity capacity floated in the Tech Sovereignty Package of 3 June 2026, on which the Commission has opened consultations with Member States and the EIB Group. Other named vehicles include existing AI Factories and future Gigafactories, the European Competitiveness Fund, and the Scaleup Europe Fund. The Communication also points to steps already taken, among them the Frontier AI Grand Challenge, awarded on 19 June 2026 to the EUROPA consortium led by the Italian company Domyn to build an open-source frontier model of more than 400 billion parameters covering all 24 official EU languages, with access to EuroHPC computing capacity [1][15].
The pillar also lists a dedicated EU Grand Challenge on AI-assisted vulnerability remediation, to be launched in the fourth quarter of 2026 with the European Cybersecurity Competence Centre and ENISA. The rationale is a specific asymmetry: AI-enabled vulnerability discovery is advancing faster than AI-assisted remediation, which the plan says creates a structural imbalance favouring attackers [1]. On skills, the Commission and Member States are to develop training modules for cybersecurity professionals under the EU Cybersecurity Skills Academy by the fourth quarter of 2026, and ENISA is to fold AI competencies into the European Cybersecurity Skills Framework.
Key actions and timelines
| # | Action | Owner | Target |
|---|---|---|---|
| 1 | EU evaluation capacity for AI models, including cybersecurity | Commission | 2027 |
| 2 | European Blueprint for structured access to advanced AI cyber capabilities | Commission with ENISA | Q4 2026 |
| 3 | Secure testing platform for AI in cybersecurity use cases | ENISA and the JRC | Q4 2026 |
| 4 | Guidance, advisories and best practices on AI-powered threats | ENISA with Union entities | As of Q3 2026 |
| 5 | Make vulnerability management practices fit for the AI age | Commission, Member States, ENISA, industry | As of Q3 2026 |
| 6 | Critical Open Source Resilience Campaign (first pilot) | ENISA with Commission, Member States, communities, industry | Q4 2026 |
| 7 | EU Grand Challenge on AI-assisted vulnerability remediation | Commission with ECCC and ENISA | Q4 2026 |
| 8 | Access to AI Factories compute for cyber resilience workloads | Commission with Member States | No date given |
| 9 | Training modules under the Cybersecurity Skills Academy | Commission with Member States and industry | Q4 2026 |
Source: COM(2026) 577 final, key action boxes in sections 2, 3 and 4 [1]; the Commission's factsheet reproduces the same dates in graphical form [13].
How it sits in the EU legal framework
The Communication situates its actions alongside several EU instruments and initiatives. The table reports only how COM(2026) 577 final describes their role; it does not independently restate each instrument's full legal scope [1].
| Instrument mentioned by the Communication | Role described in the Communication |
|---|---|
| AI Act | Framework the plan invokes for general-purpose AI supervision and model-security risk mitigation [1] |
| Cyber Resilience Act | Secure-by-design and vulnerability-management context used by the plan [1] |
| NIS2 Directive | Existing cybersecurity risk-management framework that the plan urges Member States and covered entities to implement [1] |
| DORA | Operational-resilience framework the plan invokes for financial entities [1] |
| Cyber Solidarity Act | EU-level incident-preparedness and response context referenced by the plan [1] |
| Cybersecurity of Union entities | Framework under which Union entities are expected to strengthen capabilities and issue guidance [1] |
| Cloud and AI Development Act | Discussed in relation to AI and cloud capacity [1] |
| EU Open Source Strategy | Policy context for the Critical Open Source Resilience Campaign [1] |
The Action Plan did not amend the AI Act. It predates Regulation (EU) 2026/1744, the AI Omnibus, which entered into force on 27 July 2026 [18][19]. Among other changes, that regulation extended the application dates for high-risk AI systems and amended governance and implementation rules. It did not amend the Action Plan, which remains a separate non-binding Communication [18][19].
Three problems the plan treats as one
The Communication addresses three related but distinct issues. Separating them clarifies which actions respond to which risks [1].
AI as a cyber threat. Offensive capability in frontier models, and the misuse of that capability by criminal or state actors, is the plan's opening argument. It is handled through AI Act systemic-risk supervision, pre-release evaluation, the Blueprint's access criteria, and preparedness measures under NIS2 and DORA [1].
AI as a cyber tool. Using models for vulnerability discovery, triage, threat intelligence, detection and automated remediation is the subject of the testing platform, the Grand Challenge, the open source campaign and the skills work. The Commission repeatedly nudges organisations toward models that are already available, "including through open source", rather than waiting for frontier access. This is the ground covered on the wiki by AI in cybersecurity [1].
Security of AI systems themselves. Data and model poisoning, adversarial attacks and prompt injection are named explicitly in the plan, which says they "must also be carefully assessed and mitigated in line with relevant provisions of the AI Act" [1]. This receives the least dedicated machinery of the three. There is no key action assigned specifically to this category; the plan addresses it through the AI Act-linked assessment-and-mitigation language above [1].
International dimension
The final substantive section commits the Commission to pursuing the plan's objectives in bilateral and multilateral fora. Named channels include the G7 Digital and Tech and Cybersecurity Working Groups, where the Commission will promote cooperation on standards and model evaluation; the United Nations; bilateral digital and cyber dialogues; and the Network of Advanced AI Measurement, Evaluation and Science, coordinated by the UK AI Security Institute in collaboration with partner countries' AI safety institutes and the Commission's AI Office [1]. The plan also says the EU will strengthen exchanges with NATO, including through NATO's forthcoming Centre of Excellence on Artificial Intelligence. Separately, in the third pillar rather than this section, it commits the Commission to setting up a working group with ENISA, the European Defence Agency and Member States on the security risks of deploying frontier AI models in defence and dual-use critical systems [1].
Reception
MEP Bart Groothuis (Renew, Netherlands) framed the stakes operationally, telling the plenary: "It's not business as usual anymore. Your software and IT systems will be tested by hackers, aided by the latest AI models. Hackers will operate at the speed of light and will try to put you out of business" [4]. MEP Aura Salla (EPP, Finland) redirected the sovereignty argument, saying: "Our dependency is not primarily about AI models. It is about the infrastructure they rely on" [4]. Euronews itself characterised the Commission as having "little to offer beyond recommendations and an attempt to negotiate early access with US AI companies" [4].
Laurent Hausermann, writing at Cyber Builders on 13 July 2026, credited the Commission for acknowledging that frontier capability sits outside the EU and can be withdrawn, then attacked the arithmetic: the plan admits to investment needs in the hundreds of billions while allocating figures in the hundreds of millions. He argued that Europe should build capabilities that create balanced partnerships rather than merely request access to foreign systems, and that an evaluation capacity arriving in 2027 would be late [8].
Luke O'Grady of the Center for Cybersecurity Policy and Law, writing on 16 July 2026, raised a structural problem the plan does not solve: the Cyber Resilience Act's vulnerability reporting framework was designed before AI-accelerated discovery, and a sharp rise in reports could overwhelm ENISA's processing capacity. He also warned that if EU evaluation processes diverge significantly from US ones, labs face inconsistent requirements and the result is fragmentation rather than assurance [9].
techUK said on 10 July that it would monitor implications and planned a cyber-focused delegation to Brussels on 8 and 9 September [10]. ENISA's July 2026 report, "ENISA's view on Cybersecurity in the Frontier AI Era", described an initial set of recommendations for building operational capability against machine-speed threats and said it would align them with the Commission's plan [11].
The plan also arrived against a live grievance in the European Parliament. At an IMCO committee hearing on 14 July 2026, MEP Brando Benifei noted that when Anthropic gave 50 organisations early access to Project Glasswing in April 2026, not one was European; committee chair Anna Cavazzini and MEP Reinier Van Lanschot criticised the company for sending a technical staff member unable to answer policy questions on digital sovereignty [12].
Comparison with the United States
The contrast with America's AI Action Plan, released by the White House on 23 July 2025, is instructive because the two documents share a policy-plan format [16]. Both assign work to public bodies and present policy actions rather than legislative text [1][16].
They differed in what they sat on top of when issued. The US plan, subtitled "Winning the Race", called for removing regulatory barriers to AI development; its cybersecurity content centred on an AI Information Sharing and Analysis Center, Department of Homeland Security guidance on AI-specific vulnerabilities and threats, and promotion of secure-by-design AI [16]. A June 2025 Congressional Research Service report found that targeted federal AI provisions existed but that Congress had not enacted legislation establishing broad regulatory authority over AI development or use [20]. The July 2025 plan therefore directed executive-branch policy without an EU-style comprehensive statutory framework. By contrast, the July 2026 EU plan drew on binding regulations already on the books, and much of its text urged Member States and operators to implement law they were already subject to. Both plans' cybersecurity elements converged on similar instruments: threat information sharing, secure-by-design, agency guidance and public funding.
The other structural difference is dependency. The US plan is written from the position of hosting the frontier labs, while the EU plan explicitly discusses negotiating access to capabilities developed elsewhere [1][16].
Follow-up
The Communication closes by stating that the Commission "will regularly assess the implementation of the Action Plan and adapt actions where necessary" [1]. No review date, no reporting mechanism and no indicator set are specified.
See also
- EU AI Act
- EU AI Act Digital Omnibus
- AI in Cybersecurity
- America's AI Action Plan
- AI regulation
- Council of Europe Framework Convention on AI
- Red teaming
References
- ^"Communication from the Commission: Action Plan on Cybersecurity and Artificial Intelligence, COM(2026) 577 final." European Commission, 2026-07-07. ec.europa.eu/...130848
- ^"Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence (IP/26/1544)." European Commission press release, 2026-07-07. ec.europa.eu/...ip_26_1544
- ^"Commission presents Action Plan on Cybersecurity and Artificial Intelligence." Van Bael & Bellis client alert, 2026-07-13. vbb.com/...ecurity-and-Artificial-Intelligence.pdf
- ^"Brussels pitches AI cybersecurity plan amid dependence on US models." Euronews, 2026-07-07. euronews.com/...-plan-amid-dependence-on-us-models
- ^"Expanding Project Glasswing." Anthropic, 2026-06-02. anthropic.com/...expanding-project-glasswing
- ^"US export controls on Anthropic 'should not be discriminatory,' EU Commission warns." Euronews, 2026-06-14. euronews.com/...discriminatory-eu-commission-warns
- ^"Redeploying Fable 5." Anthropic, 2026-06-30; updated 2026-07-01. anthropic.com/...redeploying-fable-5
- ^Hausermann, Laurent. "Europe Must Sell Intelligence, Not Electrons." Cyber Builders, 2026-07-13. cyberbuilders.substack.com/...ell-intelligence-not
- ^O'Grady, Luke. "European Commission Announces New Action Plan To Confront Cybersecurity Challenges in the Age of AI." Center for Cybersecurity Policy and Law, 2026-07-16. centerforcybersecuritypolicy.org/...-the-age-of-ai
- ^Maiziere, Theo. "EU Commission publishes Action Plan on Cybersecurity and Artificial Intelligence." techUK, 2026-07-10. techuk.org/...security-and-artificial-intelligence
- ^"ENISA's view on Cybersecurity in the Frontier AI Era." ENISA, 2026-07. enisa.europa.eu/...security-in-the-frontier-ai-era
- ^Baker, Jennifer. "Brussels asked policy questions. Anthropic sent newcomer tech guy to answer." EU Perspectives, 2026-07-15, reporting the IMCO committee hearing of 2026-07-14. euperspectives.eu/...t-newcomer-tech-guy-to-answer
- ^"Factsheet: Action Plan on Cybersecurity and Artificial Intelligence." European Commission, 2026-07-07. digital-strategy.ec.europa.eu/...cial-intelligence
- ^"New EU plan to address the risks and opportunities of advanced AI for cybersecurity." European Commission, 2026-07-07. commission.europa.eu/...ybersecurity-2026-07-07_en
- ^"Commission selects EUROPA consortium as the winner of the Frontier AI Grand Challenge." European Commission, Shaping Europe's digital future, 2026-06-19. digital-strategy.ec.europa.eu/...ild-european-open
- ^"Winning the Race: America's AI Action Plan." The White House, 2025-07-23. whitehouse.gov/...Americas-AI-Action-Plan.pdf
- ^"EU Action Plan on Cybersecurity and Artificial Intelligence." European Commission, Shaping Europe's digital future library entry, 2026-07-07. digital-strategy.ec.europa.eu/...cial-intelligence
- ^"AI Omnibus enters into force." European Commission, 2026-07-27. digital-strategy.ec.europa.eu/...ibus-enters-force
- ^"Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Text with EEA relevance)." Official Journal of the European Union, 2026-07-24. data.europa.eu/...pdf
- ^Harris, Laurie. "Regulating Artificial Intelligence: U.S. and International Approaches and Considerations for Congress." Congressional Research Service, 2025-06-04. congress.gov/...R48555
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
2 revisions · v3 · 3,551 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Reviewer note: Independent 2026-07-28 fact-check: all 59 material claim groups in this exact EU Action Plan on Cybersecurity and Artificial Intelligence version were checked against 30 sources, including 20 cited sources and 36 archived source artifacts. The official COM(2026) 577 final communication, Commission materials, legal analysis, contemporaneous reporting, and cited institutional and academic sources were reviewed claim by claim; legal status, dates, owners, action timelines, funding, quotations, and comparison scope were corrected or conservatively bounded. Evidence cutoff: 2026-07-28T23:59:59+07:00.
Cite this page: AI Wiki. "EU Action Plan on Cybersecurity and AI." aiwiki.ai, updated 3 Aug 2026, fact-checked 3 Aug 2026. CC BY 4.0. https://aiwiki.ai/wiki/eu_cybersecurity_and_ai_action_plan