

On July 7, 2026, the European Commission published its new Communication on the Cybersecurity and Artificial Intelligence Action Plan, a strategic document that acknowledges that AI is no longer just another tool in cybersecurity, but has become the factor that is completely redefining the playing field, both for those defending systems and those attacking them.
Although it does not directly introduce new legal obligations, it does set the direction for European policy for the coming years and anticipates regulatory and operational developments that organizations should start preparing for now.
The European Commission starts from the premise that frontier AI models, the most advanced systems currently available or under development, already enable cybersecurity teams to detect and respond to threats faster and at greater scale. However, those same capabilities are also being used to automate cyberattacks, identify vulnerabilities more quickly, and carry out increasingly sophisticated offensive operations, including organized cybercrime.
According to the Commission itself, the underlying challenge is that these frontier AI capabilities are developed predominantly outside the European Union, and access to them depends on the often non-transparent decisions of foreign providers. As a result, access to these technologies has become not only a matter of digital resilience but also of European technological sovereignty.
For this reason, the Action Plan is built around three main objectives, which we will examine below.
The European Commission announces that, from 2 August 2026, it will fully exercise its supervisory and enforcement powers under the AI Act in relation to general-purpose AI models, including those that present systemic cybersecurity risks.
The Communication also notes that most of the leading organizations carrying out independent evaluations of AI models before deployment are located outside the European Union. This is regarded as a strategic weakness because the AI Act itself recognizes the importance of independent third-party assessments of the systemic risks posed by general-purpose AI models before they are placed on the market.
To address this challenge, the Action Plan sets out several key initiatives:
Artificial intelligence can significantly improve cybersecurity, but it can also be used to identify vulnerabilities and carry out faster, more sophisticated attacks. For this reason, the EU aims to strengthen its preparedness for these risks by promoting the use of AI-powered tools to detect and remediate vulnerabilities in the most critical systems. As part of this effort, ENISA will play a key role in adapting European cybersecurity to the AI era.
The Commission also calls for the urgent transposition of the NIS2 and DORA Directives, ensuring that AI-related risks are incorporated into supervisory frameworks. In addition, organizations are encouraged to implement basic cyber hygiene measures, adopt zero trust security architectures, and begin using available AI capabilities—including open-source AI tools—to identify vulnerabilities and prevent cyberattacks.
For its part, ENISA will publish guidance on protecting against AI-enabled threats and on the secure integration of AI tools into cybersecurity operations, with particular attention given to the needs of small and medium-sized enterprises (SMEs).
Because AI enables attackers to discover and exploit vulnerabilities much more quickly, the EU also intends to accelerate its response capabilities through several initiatives:
The EU is placing particular emphasis on applying AI to the security of critical open-source software, which is estimated to be present in 98% of the codebases underpinning critical infrastructure. To support this objective, ENISA will develop a catalogue of AI-powered services designed to assist with vulnerability detection and patching in open-source software.
In addition, the Action Plan proposes several further initiatives to strengthen the resilience of the European cybersecurity ecosystem:
The third pillar focuses on the need for the European Union to develop its own AI-driven cybersecurity solutions in order to strengthen its technological sovereignty.
To support this objective, the EU has allocated €200 million through the Horizon Europe and Digital Europe programmes to fund research into AI technologies for cyber threat detection and incident response. In addition, the Commission will launch the Grand Challenge, an initiative bringing together European cybersecurity and AI companies, research organizations, critical infrastructure operators, and open-source communities. Its goal is to develop an AI system capable of assisting cybersecurity teams throughout the entire vulnerability remediation lifecycle.
To reduce strategic dependencies on non-European technologies, the EU also emphasizes the need to build its own frontier AI capabilities. This will involve leveraging the AI Factories initiative and the future AI Gigafactories to establish a sovereign European infrastructure for artificial intelligence and cybersecurity. The Commission also acknowledges that achieving frontier AI capabilities will require significant investment from the private sector.
However, financial investment alone will not be enough. The EU stresses that technological leadership also depends on having professionals with the skills to use these technologies safely and effectively. To that end, the EU Cybersecurity Skills Academy will develop dedicated training programmes and learning modules on AI in cybersecurity, while ENISA will update the European Cybersecurity Skills Framework (ECSF) to incorporate AI-related competencies.
To achieve this third pillar, the Action Plan identifies three key initiatives:
Although this Action Plan does not, in itself, create any new legal obligations, it does signal several developments that businesses should incorporate into their compliance roadmaps, particularly those involved in critical infrastructure, sensitive data processing, or AI development.
Stronger enforcement of the AI Act: From August 2026, the European Commission will begin fully exercising its supervisory and enforcement powers over providers of general-purpose AI models that present systemic risks. This includes the power to request information and impose fines of up to 3% of global annual turnover.
Having established the regulatory framework through the AI Act, the Cyber Resilience Act (CRA), and the NIS2 Directive, the European Union is now shifting its focus toward implementation. Its strategy rests on three key priorities: ensuring structured access to advanced AI technologies, modernizing vulnerability management, and, above all, expanding Europe's sovereign AI capabilities.
At Vericta, we understand the complexity of this evolving regulatory and technological landscape. That's why we provide AI compliance solutions designed to help organizations meet their legal obligations with confidence.
Don't wait any longer, choose Lawwwing and stay ahead of AI compliance.
Sources: