European Commission Presents Cybersecurity and AI Action Plan
On 7 July 2026, the European Commission adopted an action plan called the Action Plan on Cybersecurity and Artificial Intelligence (COM (2026) 577 final). The document does not create new obligations but defines how the Commission will apply the existing AI Act, Cyber Resilience Act, NIS2, DORA, and Cyber Solidarity Act to the risks that advanced AI models pose to cybersecurity.
What Happened
The Commission identified two counteracting trends. On one hand, advanced AI models are accelerating vulnerability discovery and automating cyberattacks, lowering the barrier to entry for malicious actors, including cybercriminal groups. On the other hand, the same models can strengthen the protection of critical infrastructure if European companies gain timely and predictable access to them. At the same time, frontier models themselves are developed predominantly outside the EU, and decisions on access to them are often made non-transparently and unilaterally by providers or third countries. The action plan aims to close this gap without adopting new legislative acts, relying on the existing regulatory framework.
The Legal Framework Underpinning the Plan
- AI Act (Regulation (EU) 2024/1689). From 2 August 2026, the Commission will begin applying supervisory and enforcement powers over providers of general-purpose AI models (GPAI) with systemic risk, including risks of cyber misuse. Penalties can reach 3% of global annual turnover, up to a requirement to withdraw the model from the market.
- Cyber Resilience Act (Regulation (EU) 2024/2847). Security-by-design requirements and vulnerability management throughout the entire lifecycle of products with digital elements. Full applicability by 11 December 2027.
- NIS2 Directive (Directive (EU) 2022/2555) and Digital Operational Resilience Act (Regulation (EU) 2022/2554). Baseline requirements for cyber risk management for critical sectors and the financial sector, respectively.
- Cyber Solidarity Act (Regulation (EU) 2025/38). Operational mechanisms to support EU member states in preparing for, detecting, and responding to large-scale incidents.
- Draft Cloud and AI Development Act (CADA, COM(2026) 502 final). Currently in the process of adoption as a legislative act (2026/0138/COD); it introduces a four-tier system for admitting cloud and AI service providers to public sector procurement.
Three pillars of the plan
(1) The first pillar – secure access to frontier AI. The Commission will expand European capacity for pre-release evaluation of AI models, define criteria for independent evaluators under the GPAI Code of Practice, and, together with ENISA (the EU Agency for Cybersecurity), prepare a European Blueprint for structured access to models with advanced cyber capabilities. In addition, ENISA and the Joint Research Centre will deploy a secure testing platform to test AI models in realistic cybersecurity scenarios before deployment in sensitive infrastructure.
(2) The second pillar – preparing the European ecosystem. ENISA will be tasked with issuing to issue guidelines on protection against AI-based threats and on the safe integration of AI tools into cybersecurity operations. Vulnerability management, including the European Union Vulnerability Database and the CRA Single Reporting Platform, will be adapted to the pace of AI-assisted vulnerability discovery. A separate pilot Critical Open Source Resilience Campaign is being launched, since on average 80% of the code in critical infrastructure contains open-source components in one form or another.
(3) The third pillar – building sovereign capacity. The Commission intends to scale up the European ecosystem of AI-based cybersecurity solutions through the EU Grand Challenge, ensure access to AI Factories' computing capacity, and link this work to the CADA initiative and the Cybersecurity Skills Academy for workforce training.
Key Actions and Timelines
| No. | Content | Deadline |
| 1 | Establishment of European capacity for evaluating AI models, including cybersecurity, under the GPAI Code of Practice | 2027 |
| 2 | European Blueprint for structured access to advanced AI models for cybersecurity purposes (jointly with ENISA) | Q4 2026 |
| 3 | ENISA and JRC secure testing platform for AI in cybersecurity scenarios (cyber ranges) | Q4 2026 |
| 4 | ENISA guidelines and recommendations on protection against AI-based threats and safe integration of AI into cybersecurity operations | From Q3 2026 |
| 5 | Adaptation of vulnerability management practices (EUVD, CRA Single Reporting Platform) to the pace of AI-based detection | From Q3 2026 |
| 6 | Pilot Critical Open Source Resilience Campaign for critical infrastructure | Q4 2026 |
| 7 | EU Grand Challenge for AI-based cybersecurity solutions (ECCC jointly with ENISA) | Q4 2026 |
| 8 | Access to AI Factories' computing capacity for testing and deploying AI models for cyber resilience | No fixed deadline |
| 9 | Training modules for cybersecurity professionals on the use of AI (Cybersecurity Skills Academy) | Q4 2026 |
International Perspective
The Commission intends to deepen cooperation across various tracks: within the G7 framework, in particular through the Digital&Tech and Cybersecurity working groups, as well as through the UN and bilateral partnerships, and through the International Network for Advanced AI Measurement, Evaluation and Science, coordinated by the UK AI Security Institute. It has also separately affirmed its intention to strengthen cooperation with NATO, including the future NATO Centre of Excellence on Artificial Intelligence, given the impact of frontier AI on national and collective security issues.
Initial Reaction
MLex notes that the plan deliberately avoids new legislative initiatives and relies instead on implementing already existing rules. Media outlets, in turn, point to the flip side of this strategy: the plan relies heavily on negotiated access to models developed outside the EU, while the EU's own sovereign capacity still lags behind. The draft CADA, to which the plan is directly linked, remains the most contentious element of the technological sovereignty package. Industry associations, including CCIA Europe, point to the risk of market fragmentation and the displacement of non-European providers through the upper access tiers (level 3 and level 4), while analysts recall that a previous attempt to build a cloud sovereignty certification scheme (EUCS), dating back to 2019, has still not resulted in the adoption of a single standard due to disagreements among member states.
What this Means for Business
For providers of general-purpose models and their European integrators, 2 August 2026 becomes the reference date for checking the readiness of systemic risk documentation and possible engagement with the AI Office. For operators of critical infrastructure and the financial sector, the plan effectively requires synchronizing NIS2 and DORA compliance with ENISA's new expectations for the use of AI in system protection, starting from Q3 2026. For platform services and companies embedding GPAI models into their products, the plan confirms that the regulatory scope of the AI Act also extends to contractual relationships with model providers, including access conditions, procedures for notifying restriction or withdrawal of access, and the allocation of responsibility for systemic cyber risks. For companies with open-source code in their products, participation in the critical component support campaign and related sponsorship schemes becomes relevant.
REVERA Recommendations
- By 2 August 2026, conduct an audit of systemic risk documentation for the models and systems that the client uses or embeds in its product.
- Review agreements with AI model and cloud service providers regarding access conditions, procedures for notifying restrictions on access (staged access), and the allocation of responsibility for cyber risks.
- Synchronize internal NIS2 and DORA compliance procedures with the forthcoming ENISA guidelines on the safe integration of AI into cybersecurity operations.
- Include in the client's compliance plan the monitoring of the European Blueprint and the progress of the CADA legislative procedure (the estimated timeline for the CADA legislative procedure is Q4 2026), since the final access tiers will affect the structure of contracts with cloud providers.
- For clients with open-source code in their products, assess participation in the Critical Open Source Resilience Campaign and the related contractual sponsorship schemes.
Arbitration & IT Disputes Practice
| REVERA is ready to assess the readiness of the client's contractual framework and procedures for AI Act requirements and related acts, and to prepare a position for engagement with the AI Office and national regulators. |
Contact our lawyer to learn more
Contact a Lawyer