The EU Action Plan on Cybersecurity and Artificial Intelligence in the spotlight
Introduction
Cybersecurity and artificial intelligence (AI) are often treated as separate policy fields: they have followed different trajectories of development, involve different forms of private-sector participation, and are governed by distinct regulatory frameworks. Yet as the interlinkages between the two fields continue to grow, questions arise about how they can be regulated within an increasingly interconnected policy landscape. This also has significant practical implications – AI is becoming an integral part of cybersecurity, and vice versa. Any discussion of the security of systems and critical infrastructure cannot ignore the impact of AI’s development and its influence on offensive and defensive cyber-capabilities.
In July 2026, the European Union published the new EU Action Plan on Cybersecurity and Artificial Intelligence, bringing the two policy fields together within a common framework. The Action Plan seeks to strengthen cyber resilience and Europe’s “technological sovereignty” while preventing new strategic dependencies in the field of advanced AI. To achieve these objectives, it identifies four central fields of action:
- Early identification and assessment of new AI developments, as well as their opportunities and risks,
- Supporting critical sectors in the secure use of AI and in addressing AI-enabled cyber threats,
- Expanding the European AI and cybersecurity ecosystem to develop and scale AI-enabled cybersecurity solutions,
- Strengthening European and international cooperation.
Background
The new EU Action Plan is not a response to a regulatory vacuum. While the EU AI Act establishes the first binding European framework for the safe use of AI systems, the Cyber Resilience Act (CRA) focuses on the security of digital products (hardware and software) and the management of their vulnerabilities. Together, these regulatory frameworks form the European basis for deploying AI systems and digital technologies safely and reducing the risks associated with them. Additional instruments include the NIS 2 Directive1, the Digital Operational Resilience Act (DORA)2, and the Cyber Solidarity Act (CSA)3. The EU faces the challenge of balancing technological innovation with resilience. At the same time, it strives to ensure that the development of new technologies is consistent with fundamental values.
A significant problem in this case is dependence on suppliers from outside the EU, which weakens the EU’s ability to act and makes it difficult to enforce compliance with specific rules already introduced. Therefore, in the development and use of AI, the goal is to avoid new dependencies and build “in-house” (European) technological capabilities to remain strategically capable despite increasing technological advances. Through EU funding programs such as Horizon Europe and the European Innovation Council Fund, the EU has begun to provide targeted support for research, innovation, and strategic technologies. Since the publication of the AI Continent Action Plan4 in April 2025, these efforts have been supplemented by further measures, including the Apply AI Strategy5 and the proposed Cloud and AI Development Act (CADA) as part of the European Technological Sovereignty Package6. Against this backdrop, the EU Action Plan presents a next step, bringing cybersecurity and AI closer together.
Analysis of the EU Action Plan
Pillar 1 calls for the development of technical expertise in the field of advanced AI to ensure that it is secure, accessible, and ready for use in European cybersecurity. To this end, technical expertise and capabilities for the security assessment and testing of high-performance AI models are to be expanded. Among other measures, the plan includes coordinated procedures for pre-release evaluations to identify risks early on, support the secure deployment of AI systems, and promote their use to strengthen cybersecurity. In addition, an infrastructure for independent pre-release evaluations of AI models is to be established within the EU, and the expertise of authorities and operators of critical infrastructure is to be strengthened to test AI under realistic conditions and deploy it safely.
Pillar 2 calls for the systematic use of AI to strengthen cyber resilience, particularly to identify, prioritize, and address vulnerabilities. Existing EU cybersecurity instruments should be consistently utilized, particularly the NIS 2 Directive, DORA, and the CRA. At the same time, fundamental cybersecurity hygiene measures should be implemented across all sectors, and existing AI applications should be leveraged to detect cyber threats early and counter them effectively. The goal is to accelerate vulnerability management and not only identify security vulnerabilities but also address them efficiently. The European Union Agency for Cybersecurity (ENISA) will play a central coordinating role in this effort. Small and medium-sized enterprises, as well as operators of critical infrastructure, should strengthen their cyber resilience.
Pillar 3 calls for strengthening Europe’s innovation and skills base in the fields of AI and cybersecurity, thereby enhancing the EU’s cyber resilience and independence. In addition to establishing a regulatory framework that fosters innovation, the goal is to strengthen Europe’s technological capabilities by providing targeted support to European companies, research institutions, and startups in the development and scaling of AI-based cybersecurity solutions. To this end, the Action Plan calls for investments of at least €300 million. Of this amount, €200 million is to be mobilized through the existing EU funding programs Horizon Europe and Digital Europe, while an additional €100 million will be provided through the European Innovation Council Fund. In addition, instruments such as the ScaleUp Europe Fund and co-investment models are intended to mobilize additional private investment. Furthermore, the pillar calls for the expansion of education and training programs, particularly through the EU Cybersecurity Skills Academy, to train specialists in the secure deployment and development of AI-powered cybersecurity solutions. At the same time, knowledge exchange between research institutions, industry, government agencies, and operators of critical infrastructure will be intensified to accelerate the translation of innovations into practice. In the long term, the EU is thus pursuing the goal of strengthening its “technological sovereignty” in the field of advanced AI, building its own frontier AI capabilities, and reducing its dependence
The development and use of AI require close international cooperation. Thus, the Action Plan calls for sharing of experience, knowledge, and best practices with like-minded partners to further develop standards for trustworthy AI, cybersecurity, and a resilient regulatory framework. To this end, the EU intends to utilize both bilateral and multilateral forums, including the G7, NATO, the United Nations, and partnerships with individual countries such as the United Kingdom.
Implications of the EU Action Plan
- AI as a central component of the EU Cybersecurity Strategy: The new regulation places greater emphasis on AI within EU cybersecurity policy and complements the regulatory framework for the secure use and evaluation of advanced AI systems.
- Targeted development of European expertise and infrastructure: The EU Action Plan emphasizes the development of in-house capabilities for assessing, testing, and safely using AI models through independent evaluation capacities and specialized institutions.
- Establishment of joint testing and evaluation structures: Through ENISA and the Joint Research Centre (JRC), joint European capacities for the evaluation and testing of AI-based cybersecurity applications are to be established by the end of 2026.
- Strengthening knowledge transfer and skills: Through more advanced training, exchange, and support programs, the Action Plan aims to prepare public authorities, businesses, and critical infrastructure to address novel AI and cybersecurity risks.
- Promoting European technological sovereignty: By investing in AI and cybersecurity capabilities, Europe aims to develop its own capacities and reduce its dependence on non-European providers.
- Enforcement powers under the AI Act: The European Commission already has broader powers to enforce the provisions of the AI Act against providers of general-purpose AI models, particularly those posing systemic risk. In the event of violations, fines of up to 3% of global annual revenue or €15 million may be imposed, and additional measures may be ordered to ensure compliance with the requirements.
The EU Action Plan on Cybersecurity and Artificial Intelligence marks an important step towards addressing the growing interlinkages between AI and cybersecurity. Rather than creating a single regulatory framework for both fields, it builds on and connects existing instruments and regulations. The accumulation of numerous legal acts could pose a problem. One key to the smooth implementation of sound solutions will be navigating the complex EU regulatory framework, which will require effective coordination between the public and private sectors. It remains to be seen in the coming months and years how the implementation will progress and whether it will ultimately succeed.
1 The NIS 2 Directive strengthens cybersecurity in the EU by establishing requirements for risk management, security incident reporting, and the resilience of essential and critical infrastructure.
2 DORA establishes uniform EU requirements to strengthen the digital resilience of the financial sector through requirements for information and communication technology risk management, cybersecurity, and operational stability
3 The CSA strengthens European cooperation in the field of cybersecurity through joint early warning systems, coordinated response measures, and mutual assistance in the event of cyber incidents.
Copyright: Creative Commons

