Brussels: Artificial intelligence has become both the sharpest weapon and the strongest shield in cybersecurity, and the European Union wants the shield to win. On 7 July 2026, the Commission unveiled an action plan built around one uncomfortable fact. The same models that defend networks can also break them.
The plan treats AI cybersecurity as a double-edged problem. Advanced systems can scan code for weaknesses, patch flaws and spot intruders faster than any human team. Those same capabilities let attackers find vulnerabilities, automate intrusions and scale assaults at a speed defenders struggle to match.
Brussels has set three goals. It wants to promote the safe use of advanced AI, strengthen the bloc’s cyber resilience, and expand Europe’s own capacity to build AI tools for defence. Each goal leans on rules the EU already holds rather than inventing a fresh legal regime.
Turning existing law into capability
The AI Act supplies the backbone. It requires advanced models to be evaluated and their risks assessed before they reach the EU market. The Commission now wants to build a genuine evaluation capacity behind that requirement, strengthening independent testing of what powerful models can actually do.
Testing needs a safe place to happen. The EU Agency for Cybersecurity and the Commission’s Joint Research Centre will build a secure platform to probe AI systems for security purposes, including inside simulated environments where a model can be pushed hard without real-world damage.
The plan also reaches outward for talent. An EU Grand Challenge on AI for cybersecurity will pull companies, researchers and public bodies into a shared effort to develop defensive tools. The design borrows from contests that have long driven breakthroughs in the field.
Money and the sovereignty question
Ambition needs funding, and the figures look modest against the threat. The Commission points to 200 million euros from EU programmes and a further 100 million from the European Innovation Council Fund to support what it calls sovereign AI cybersecurity capabilities.
That word, sovereign, carries weight. Europe worries about depending on American and Chinese systems for something as sensitive as network defence. Building homegrown capacity is as much about strategic autonomy as it is about stopping the next breach.
The action plan does not stand alone. It sits on top of the AI Act, the Cyber Resilience Act, the Network and Information Systems Directive and the Cyber Solidarity Act, a dense stack of rules the EU has assembled over recent years. The Commission set out the full plan in an official announcement.
The strategy’s weakness is familiar. Europe writes strong frameworks, then struggles to turn them into operational muscle. A secure test platform and a grand challenge sound impressive, yet attackers armed with commercial AI move now, not after a procurement cycle.
The promise is real all the same. If the bloc can match its regulatory reach with genuine technical capacity, AI cybersecurity could become a field where Europe leads rather than follows. The plan is a bet that rules and research together can outrun the threat they describe.




