{"id":12547,"date":"2026-08-27T21:30:00","date_gmt":"2026-08-27T20:30:00","guid":{"rendered":"https:\/\/lawwwing.com\/?p=12547"},"modified":"2026-07-23T14:16:39","modified_gmt":"2026-07-23T13:16:39","slug":"eu-action-plan-on-cybersecurity-and-artificial-intelligence","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/eu-action-plan-on-cybersecurity-and-artificial-intelligence\/","title":{"rendered":"The EU presents its Action Plan on Cybersecurity and Artificial Intelligence"},"content":{"rendered":"\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>On July 7, 2026, the European Commission published its new <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex:52026DC0577\"><strong>Communication on the Cybersecurity and Artificial Intelligence Action Plan<\/strong><\/a>, a strategic document that acknowledges that AI is no longer just another tool in cybersecurity, but has become the factor that is completely redefining the playing field, both for those defending systems and those attacking them.<\/p>\n\n\n\n<p>Although it does not directly introduce new legal obligations, it does set the direction for European policy for the coming years and anticipates regulatory and operational developments that organizations should start preparing for now.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Context: AI as a Double-Edged Sword<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The European Commission starts from the premise that frontier AI models, the most advanced systems currently available or under development, already enable cybersecurity teams to detect and respond to threats faster and at greater scale. However, those same capabilities are also being used to automate cyberattacks, identify vulnerabilities more quickly, and carry out increasingly sophisticated offensive operations, including organized cybercrime.<\/p>\n\n\n\n<p>According to the Commission itself, the underlying challenge is that these frontier AI capabilities are developed predominantly outside the European Union, and access to them depends on the often non-transparent decisions of foreign providers. As a result, access to these technologies has become not only a matter of digital resilience but also of <strong>European technological sovereignty.<\/strong><\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Three Strategic Pillars<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>For this reason, the Action Plan is built around three main objectives, which we will examine below.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-dfe5004558179df8250594cbfd8290db\">1. The Safe and Responsible Use of Advanced AI<\/h3>\n\n\n\n<p>The European Commission announces that, from 2 August 2026, it will fully exercise its supervisory and enforcement powers under the AI Act in relation to general-purpose AI models, including those that present systemic cybersecurity risks.<\/p>\n\n\n\n<p>The Communication also notes that most of the leading organizations carrying out independent evaluations of AI models before deployment are located outside the European Union. This is regarded as a strategic weakness because the AI Act itself recognizes the importance of independent third-party assessments of the systemic risks posed by general-purpose AI models before they are placed on the market.<\/p>\n\n\n\n<p>To address this challenge, the Action Plan sets out several key initiatives:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Establish a European AI evaluation capability by 2027, providing an independent \"European option\" for assessing AI models before they are released.<\/li>\n\n\n\n<li><strong>Develop a structured access \"Blueprint\"<\/strong>, in cooperation with ENISA (the European Union Agency for Cybersecurity), enabling European organizations\u2014including public authorities, critical infrastructure operators, and cybersecurity providers\u2014to securely access AI models with advanced cyber capabilities.<\/li>\n\n\n\n<li><strong>Create a secure testing platform<\/strong>, led by ENISA and the Joint Research Centre (JRC). This platform will use cyber ranges (simulated cyber environments) so that operators of critical infrastructure can test and experiment with AI systems without putting their real-world systems at risk.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-aa7b5152460e96fc7871c7bffa5bb690\">2. Strengthening the Resilience of the European Cybersecurity Ecosystem<\/h3>\n\n\n\n<p>Artificial intelligence can significantly improve cybersecurity, but it can also be used to identify vulnerabilities and carry out faster, more sophisticated attacks. For this reason, the EU aims to strengthen its preparedness for these risks by promoting the use of AI-powered tools to detect and remediate vulnerabilities in the most critical systems. As part of this effort, ENISA will play a key role in adapting European cybersecurity to the AI era.<\/p>\n\n\n\n<p>The Commission also calls for the urgent transposition of the NIS2 and DORA Directives, ensuring that AI-related risks are incorporated into supervisory frameworks. In addition, organizations are encouraged to implement basic cyber hygiene measures, adopt zero trust security architectures, and begin using available AI capabilities\u2014including open-source AI tools\u2014to identify vulnerabilities and prevent cyberattacks.<\/p>\n\n\n\n<p>For its part, ENISA will publish guidance on protecting against AI-enabled threats and on the secure integration of AI tools into cybersecurity operations, with particular attention given to the needs of small and medium-sized enterprises (SMEs).<\/p>\n\n\n\n<p>Because AI enables attackers to discover and exploit vulnerabilities much more quickly, the EU also intends to accelerate its response capabilities through several initiatives:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Modernising cybersecurity infrastructure. ENISA will work to ensure that both the EU Vulnerability Database (EUVD) and the Single Reporting Platform established under the Cyber Resilience Act (CRA) effectively support the discovery and management of vulnerabilities.<\/li>\n\n\n\n<li>Providing guidance to help manufacturers and users identify which vulnerabilities should be patched as a priority.<\/li>\n\n\n\n<li>Encouraging Member States to update their national Coordinated Vulnerability Disclosure (CVD) policies.<\/li>\n<\/ul>\n\n\n\n<p>The EU is placing particular emphasis on applying AI to the security of critical open-source software, which is estimated to be present in 98% of the codebases underpinning critical infrastructure. To support this objective, ENISA will develop a catalogue of AI-powered services designed to assist with vulnerability detection and patching in open-source software.<\/p>\n\n\n\n<p>In addition, the Action Plan proposes several further initiatives to strengthen the resilience of the European cybersecurity ecosystem:<\/p>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li>ENISA guidelines and recommendations on protection against AI-enabled cyber threats.<\/li>\n\n\n\n<li>Cooperation between the European Commission, Member States, ENISA, and industry to modernize vulnerability management practices and tools.<\/li>\n\n\n\n<li>The launch of a pilot programme for a Critical Open Source Resilience Campaign, aimed at improving the security of essential open-source software.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-b346be66dc602d08941fb8c88c20c6e1\">3. Scaling Europe's AI Capabilities for Cybersecurity<\/h3>\n\n\n\n<p>The third pillar focuses on the need for the European Union to develop its own AI-driven cybersecurity solutions in order to strengthen its technological sovereignty.<\/p>\n\n\n\n<p>To support this objective, the EU has allocated \u20ac200 million through the Horizon Europe and Digital Europe programmes to fund research into AI technologies for cyber threat detection and incident response. In addition, the Commission will launch the<strong> Grand Challenge<\/strong>, an initiative bringing together European cybersecurity and AI companies, research organizations, critical infrastructure operators, and open-source communities. Its goal is to develop an AI system capable of assisting cybersecurity teams throughout the entire vulnerability remediation lifecycle.<\/p>\n\n\n\n<p>To reduce strategic dependencies on non-European technologies, the EU also emphasizes the need to build its own frontier AI capabilities. This will involve leveraging the <strong>AI Factories <\/strong>initiative and the future AI Gigafactories to establish a sovereign European infrastructure for artificial intelligence and cybersecurity. The Commission also acknowledges that achieving frontier AI capabilities will require significant investment from the private sector.<\/p>\n\n\n\n<p>However, financial investment alone will not be enough. The EU stresses that technological leadership also depends on having professionals with the skills to use these technologies safely and effectively. To that end, the <strong>EU Cybersecurity Skills Academy <\/strong>will develop dedicated training programmes and learning modules on AI in cybersecurity, while ENISA will update the <strong>European Cybersecurity Skills Framework<\/strong> (ECSF) to incorporate AI-related competencies.<\/p>\n\n\n\n<p>To achieve this third pillar, the Action Plan identifies three key initiatives:<\/p>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li>Launching the Grand Challenge to accelerate the development and adoption of European AI-based cybersecurity solutions.<\/li>\n\n\n\n<li>Facilitating access to the computing capacity of AI Factories, enabling organizations to test, train, and deploy advanced and frontier AI models.<\/li>\n\n\n\n<li>Developing specialised training modules for cybersecurity professionals on the secure and effective use of AI in cybersecurity operations.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What Does This Mean for Businesses?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Although this Action Plan does not, in itself, create any new legal obligations, it does signal several developments that businesses should incorporate into their compliance roadmaps, particularly those involved in critical infrastructure, sensitive data processing, or AI development.<\/p>\n\n\n\n<p>Stronger enforcement of the AI Act: From August 2026, the European Commission will begin fully exercising its supervisory and enforcement powers over providers of general-purpose AI models that present systemic risks. This includes the power to request information and impose fines of up to 3% of global annual turnover.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Review of Coordinated Vulnerability Disclosure (CVD) policies<\/strong>: Organizations should reassess their vulnerability disclosure procedures in light of AI-assisted exploitation techniques. This is particularly relevant to entities already subject to obligations under the NIS2 Directive.<\/li>\n\n\n\n<li><strong>Greater scrutiny of the open-source software supply chain:<\/strong> Critical open-source software is becoming an increasingly important area of regulatory focus, meaning organizations should pay closer attention to the security and governance of the open-source components they rely on.<\/li>\n\n\n\n<li><strong>Preparing for controlled access to frontier AI models:<\/strong> The future European Blueprint for structured access to advanced AI models could become an important mechanism through which certain organizations demonstrate legitimate, secure, and traceable access to frontier AI technologies.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Having established the regulatory framework through the AI Act, the Cyber Resilience Act (CRA), and the NIS2 Directive, the European Union is now shifting its focus toward implementation. Its strategy rests on three key priorities: ensuring structured access to advanced AI technologies, modernizing vulnerability management, and, above all, expanding Europe's sovereign AI capabilities.<\/p>\n\n\n\n<p>At <a href=\"https:\/\/vericta.com\/#use-cases-section\"><strong>Vericta<\/strong><\/a>, we understand the complexity of this evolving regulatory and technological landscape. That's why we provide AI compliance solutions designed to help organizations meet their legal obligations with confidence.<\/p>\n\n\n\n<p>Don't wait any longer, choose <strong>Lawwwing <\/strong>and stay ahead of AI compliance.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Sources: <\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>European Commission.<\/strong> (2026, July 7). <em>Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: Action Plan on Cybersecurity and Artificial Intelligence<\/em> (COM(2026) 577 final). EUR-Lex. <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex:52026DC0577\">https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:52026DC0577<\/a><\/li>\n\n\n\n<li><strong>European Commission.<\/strong> (2026, July 7). <em>EU Action Plan on Cybersecurity and Artificial Intelligence<\/em>. Shaping Europe\u2019s Digital Future. <a href=\"https:\/\/digital-strategy.ec.europa.eu\/es\/library\/eu-action-plan-cybersecurity-and-artificial-intelligence\">https:\/\/digital-strategy.ec.europa.eu\/en\/library\/eu-action-plan-cybersecurity-and-artificial-intelligence<\/a><\/li>\n<\/ul>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/lawwwing.com\/en\/blog\/\" style=\"background:linear-gradient(135deg,rgb(132,206,249) 0%,rgb(219,180,255) 100%)\">DIGITAL LAW AND DATA PROTECTION BLOG<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>On July 7, 2026, the European Commission published its new Communication on the Cybersecurity and Artificial Intelligence Action Plan, a strategic document that acknowledges that AI is no longer just another tool in cybersecurity, but has become the factor that is completely redefining the playing field, both for those defending systems and those attacking them. [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":12548,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[69,627,65,73,631],"tags":[448,451,465,654,655,853],"class_list":["post-12547","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguridad","category-privacidad-y-proteccion-de-datos-ue","category-ia","category-inteligencia-artificial","category-seguridad-y-confianza-online","tag-european-comission","tag-ai","tag-cybersecurity","tag-artificial-intelligence","tag-cibersecurity","tag-action-plan"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=12547"}],"version-history":[{"count":1,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12547\/revisions"}],"predecessor-version":[{"id":12551,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12547\/revisions\/12551"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/12548"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=12547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=12547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=12547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}