Policy
European Commission unveils AI cybersecurity action plan
The European Commission announced a plan for testing advanced AI and using it more safely in cybersecurity.
European Commission
What happened
The Commission published the plan on July 7, 2026. It says the EU will create a new program for evaluating AI used in cybersecurity. That program is expected to start operating in 2027 and support the EU AI Office.
The plan also asks two EU agencies to build a secure testing platform. Organizations could use simulated environments to test AI without exposing real systems. The intended users include finance, energy, health, transport, and government services.
The plan builds on laws the EU already has. It does not create a new binding AI law. Much of it consists of recommendations, planned programs, and tools that still need to be designed.
Why it matters
The plan focuses on practical questions that broad AI rules often skip. Who will test powerful models? How can security teams use them safely? How can important services test AI without putting real systems at risk? The answers will show whether the EU plan becomes a useful safeguard or stays mostly on paper.
What remains unclear
- The Commission has not published the program's budget, eligibility rules, or testing method.
- The testing platform is not finished. The EU has not said which organizations or AI models will qualify to use it.
- Most of the plan describes future work. Its effect on real cybersecurity will depend on how that work is funded, built, and enforced.
Related claims
Sources
-
EU Action Plan on Cybersecurity and Artificial Intelligence
Used for: The Commission’s publication date, the plan’s three objectives, and its commitments on evaluation capacity, ENISA cooperation, secure access and a testing platform.
-
Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence
Used for: The expected 2027 operational date for the evaluation capacity and the planned roles for ENISA and the Joint Research Centre.
-
Brussels pitches AI cybersecurity plan amid dependence on US models
Used for: Independent reporting that the plan is principally a package of recommendations and planned initiatives.