Brussels: The European Commission on 7 July presented an Action Plan on Cybersecurity and Artificial Intelligence, framing the same technology as at once the defender and the aggressor in Europe’s digital future. The document rests on a candid premise. Advanced AI can scan systems for vulnerabilities, flag intrusions and shield critical infrastructure faster than any human team, yet the identical capabilities let hostile actors automate attacks, probe for weaknesses and mount operations at a speed and scale that older defences were never built to withstand. The plan is an attempt to tilt that balance toward the defenders before the gap widens.
What is notable is what the plan is not. It carries no new legislation. Instead of adding another statute to an already dense rulebook, the Commission has chosen to knit together instruments that already exist, among them the AI Act, the Cyber Resilience Act, the NIS2 Directive, the Digital Operational Resilience Act and the Cyber Solidarity Act. The wager is that Europe’s problem is not a shortage of rules but a shortage of coordinated capacity to apply them, and that implementation, not fresh drafting, is where the next few years will be won or lost.
Four strands hold the plan together. The first turns the AI Act’s requirement that advanced models be evaluated for risk before reaching the EU market into a working capability. The Commission wants to build an EU evaluation capacity that can strengthen third-party assessment of what these systems can and cannot safely do, reinforcing the regulatory role of the AI Office. The second addresses access. European defenders need clear, transparent terms on which they can reach the most powerful models, so the Commission will work with the EU Agency for Cybersecurity to define a blueprint for structured access to advanced AI for security purposes. The third is practical machinery. The cybersecurity agency and the Commission’s Joint Research Centre will build a secure platform, complete with simulated environments, where AI tools can be tested before they touch live infrastructure. The fourth is an EU Grand Challenge on AI for cybersecurity, a contest meant to draw companies, researchers and public bodies into building defensive tools that Europe can call its own.
That last ambition points to the plan’s unspoken anxiety. Europe’s most capable models are largely developed elsewhere, and a cybersecurity strategy that leans on systems built and controlled abroad inherits a dependency it cannot easily unwind. Structured access arrangements and homegrown evaluation capacity are, in part, an effort to convert that dependency into something the bloc can supervise rather than simply consume. Whether a testing platform and a grand challenge are enough to close a capability gap measured against the largest American and Chinese laboratories is the question the plan does not fully answer.
Skeptics will note a familiar pattern. Brussels excels at frameworks and coordination documents, and the sprawl of overlapping acts the plan invokes is itself evidence of how crowded the field has become. A strategy that promises to implement existing law is only as good as the resources and political attention that follow it, and evaluation capacity of the kind envisaged is expensive, technically demanding and slow to staff. There is also a tension between opening structured access to frontier models and the secrecy that both vendors and security agencies prize.
Set against those doubts is a reasonable case that sequencing matters. By declining to write new rules, the Commission avoids years of negotiation at a moment when threat actors are already using automation, and it forces attention onto the unglamorous work of testing, evaluation and shared infrastructure. For operators of energy grids, hospitals and financial systems, the value will be judged not by the elegance of the plan but by whether the promised platform, blueprint and evaluation capacity actually arrive, and arrive before the next wave of AI-assisted attacks does.




