On July 7, 2026, the European Commission presented the EU Action Plan on Cybersecurity and Artificial Intelligence, a coordinated approach to help Member States, businesses, and public authorities address the security challenges posed by the most advanced AI models. The plan responds to a double-edged reality: AI can detect vulnerabilities and strengthen the protection of critical infrastructure, but the same capabilities let malicious actors automate attacks and identify weaknesses at unprecedented speed and scale. Executive Vice-President Henna Virkkunen summed up the stakes: “AI is transforming the meaning of cybersecurity. And we must keep pace.”
The Action Plan is organized around three objectives: promoting the safe use of advanced AI, strengthening EU cyber resilience, and expanding European AI capabilities for cybersecurity. Planned measures include an EU model-evaluation capacity for assessing advanced AI models, an access blueprint developed with ENISA, a secure testing platform, a Critical Open Source Resilience Campaign, and new funding for AI and cybersecurity projects. The Commission will also launch an EU Grand Challenge on AI for cybersecurity to bring companies, researchers, and other stakeholders together around AI-powered defensive tooling.
Rather than creating new legislation, the plan builds on the EU’s existing legal stack, including the AI Act, the Cyber Resilience Act, the NIS2 Directive, DORA, and the Cyber Solidarity Act. For businesses operating in Europe, it signals that AI security evaluation infrastructure is becoming an EU-level public capability, and that the Commission views frontier model security as inseparable from critical infrastructure protection ahead of the AI Act’s general-purpose AI enforcement date of August 2, 2026.