Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →EU Action Plan on Cybersecurity and Artificial Intelligence
Issued by
European Commission
The European Commission's Action Plan on Cybersecurity and Artificial Intelligence establishes a coordinated approach to securing AI systems deployed across the EU. It applies to developers and deployers of AI models subject to the EU AI Act, particularly those operating advanced or high-risk systems. The plan creates dedicated evaluation infrastructure, including a secure testing platform and an EU-level evaluation capability for advanced AI models.
Applies To
Overview
The Action Plan was presented by the European Commission to address two intersecting priorities: strengthening cybersecurity protections for AI systems and building the regulatory evaluation capacity needed to enforce the EU AI Act. It introduces an EU evaluation capability specifically designed to assess advanced AI models against technical safety and security standards. A secure AI testing platform is established to support pre-deployment review, enabling both public authorities and regulated entities to conduct structured security assurance assessments. The plan connects directly to the conformity assessment and pre-market review obligations already embedded in the EU AI Act, reinforcing the enforcement infrastructure available to national competent authorities. Implementation timelines and detailed operational procedures are expected to be elaborated through subsequent Commission guidance and coordinated action among member states. Enterprises deploying advanced or high-risk AI systems should treat this Action Plan as a signal that regulatory scrutiny of model security will intensify in the near term.
Key Requirements
- •AI systems deployed in the EU, particularly advanced and high-risk models, must be capable of undergoing security evaluation using the EU's centralized testing infrastructure.
- •Developers and deployers of advanced AI models should prepare for mandatory engagement with the EU evaluation capability as it becomes operational, with specific timelines to be confirmed in subsequent guidance.
- •Organizations subject to EU AI Act conformity assessments must ensure their systems meet cybersecurity requirements as assessed through the new secure testing platform.
- •Pre-deployment review processes must incorporate security assurance documentation aligned with criteria defined under this Action Plan and the EU AI Act.
- •Entities operating critical or high-risk AI systems may be required to submit models for evaluation by designated authorities before or during market deployment.
What Your Organization Must Do
- →Audit all AI systems currently deployed or under development to identify which qualify as advanced or high-risk under the EU AI Act and would fall within the scope of this Action Plan.
- →Engage early with the EU's secure AI testing platform once access procedures are published, rather than waiting for mandatory deadlines to be imposed.
- →Update internal pre-deployment checklists to include cybersecurity assurance steps that align with the evaluation criteria referenced in this Action Plan.
- →Revise vendor and supplier contracts to require disclosure of cybersecurity testing results for any advanced AI model procured for EU deployment.
- →Assign accountability within the compliance function for monitoring Commission guidance that will operationalize the evaluation capability and testing platform timelines.
- →Maintain documented evidence of security assessments for all in-scope AI systems, structured to support potential review by national competent authorities.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does the EU Action Plan on Cybersecurity and AI create binding obligations separate from the EU AI Act?
- The Action Plan itself is a coordinating framework rather than standalone legislation, so it does not impose independent legal obligations. Its practical effect is to reinforce and operationalize cybersecurity requirements already embedded in the EU AI Act, particularly for advanced and high-risk systems.
- Which AI systems fall within scope of the EU's new centralized evaluation capability?
- The evaluation capability is targeted primarily at advanced and high-risk AI models as classified under the EU AI Act. Specific thresholds and model categories will be confirmed through subsequent Commission guidance, but compliance teams should prioritize systems already flagged as high-risk under existing AI Act annexes.
- When will the EU secure AI testing platform be operational and mandatory for pre-deployment review?
- Detailed operational timelines have not yet been published, with the Action Plan listing an indicative effective date of July 2026. Subsequent Commission guidance will define mandatory engagement windows, so organizations should monitor official publications rather than treating 2026 as a confirmed hard deadline.
- How does this Action Plan interact with NIS2 cybersecurity obligations for AI deployers?
- The Action Plan complements NIS2 by addressing AI-specific security assurance requirements that general network and information security rules do not fully cover. Entities already subject to NIS2 should treat AI model security evaluation under this Action Plan as an additional, distinct compliance track requiring dedicated documentation.
- What cybersecurity documentation should AI deployers prepare ahead of the EU evaluation capability going live?
- Deployers should compile structured security assurance records covering threat modeling, pre-deployment testing results, and any third-party audits conducted for in-scope systems. Aligning this documentation to EU AI Act conformity assessment templates now reduces remediation risk once evaluation criteria are formally published.
- Can procurement contracts require suppliers to share results from the EU AI testing platform?
- Yes, and the Commission's guidance strongly implies that supply chain transparency will be a compliance expectation for organizations deploying procured AI models in the EU. Updating vendor contracts to require disclosure of cybersecurity testing outcomes is advisable before the platform's access procedures are finalized.
