The European Commission on Tuesday presented an Action Plan on Cybersecurity and Artificial Intelligence, marking a coordinated EU-wide approach to harness AI's potential while defending against the new generation of AI-powered cyber threats.
The plan rests on three complementary objectives: promoting the safe and responsible use of advanced AI, reinforcing the EU's cybersecurity and resilience, and scaling up Europe's AI capabilities specifically for cyber defense.
At the heart of the initiative is a recognition that AI is a double-edged sword in the digital domain. While AI can help detect vulnerabilities, prevent cyberattacks, and strengthen protection of critical infrastructure, it can also be exploited by malicious actors to automate attacks, identify weaknesses, and carry out operations at unprecedented speed and scale.
To promote safe AI use, the Commission will strengthen Europe's capacity to evaluate AI models before they reach the market, in line with the AI Act. It will work with ENISA, the EU's cybersecurity agency, to develop a European Blueprint for secure access to advanced AI systems and establish a secure testing platform for critical sectors including energy, transport, health, finance, and public administration.
The plan also reinforces implementation of existing legislation including the NIS2 Directive, the Cyber Resilience Act, and DORA. It encourages organizations to use AI — including open-source models — to detect vulnerabilities more quickly.
A centerpiece is the EU Grand Challenge on AI for Cybersecurity, which will bring together companies, researchers, and stakeholders to develop innovative AI-powered security solutions. The EU will continue investing in sovereign AI capabilities through its AI Factories and future Gigafactories initiative.
The Action Plan builds on the EU's existing legal framework including the AI Act, which begins enforcement of high-risk AI system rules on August 2, 2026.




