AI Governance Institute
VoluntaryFrameworkEU

EU Action Plan on Cybersecurity and Artificial Intelligence

Issued by

European Commission

liveEffective 2026-07-07EU-CS-AI-APUpdated October 2026 · Last verified October 1, 2026
Official document →

The European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence on 7 July 2026. It aims to promote safe use of advanced AI, strengthen EU cybersecurity, and build European AI capabilities for cybersecurity. It creates no new obligations and relies on existing laws such as NIS2, DORA, and the Cyber Resilience Act.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

The European Commission presented this Action Plan on 7 July 2026. It has three objectives: promoting the safe and responsible use of advanced AI, reinforcing EU cybersecurity and resilience, and expanding European AI capabilities for cybersecurity. The Commission plans a call to build an EU capacity for evaluating the cybersecurity capabilities of AI models, expected to be running in 2027. With ENISA, the EU cybersecurity agency, it will define a blueprint for structured access to advanced AI for cybersecurity purposes. An EU Grand Challenge will fund AI-powered cybersecurity tools. The plan adds no new legal duties. It pushes for full implementation of existing laws, namely the NIS2 Directive, DORA, and the Cyber Resilience Act, whose main obligations apply from December 2027.

Key Requirements

  • •The Action Plan creates no new legal obligations and proposes no new legislation.
  • •It supports implementation of existing laws: the AI Act, NIS2, DORA, the Cyber Resilience Act, and the Cyber Solidarity Act.
  • •The Commission plans an EU capacity to evaluate the cybersecurity capabilities of advanced AI models, expected in 2027.
  • •With ENISA, it will develop a blueprint for secure access to advanced AI systems for cybersecurity purposes.
  • •A secure testing platform will help organisations in energy, transport, health, finance, and public administration test AI security tools.
  • •An EU Grand Challenge will fund AI-powered cybersecurity tools.

What Your Organization Must Do

  • →Brief leadership that this Action Plan adds no new legal duties for your organisation.
  • →Keep driving existing compliance work under the AI Act, NIS2, DORA, and the Cyber Resilience Act.
  • →Note that main Cyber Resilience Act obligations apply from December 2027 in your planning calendar.
  • →Watch for the EU capacity to evaluate cybersecurity capabilities of advanced AI models, expected in 2027.
  • →Decide, as a commercial choice, whether supplier contracts should ask for AI security testing results.
  • →Track the planned EU Grand Challenge funding and secure testing platform if you operate in energy, transport, health, finance, or public administration.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does the EU Action Plan on Cybersecurity and AI create binding obligations separate from the EU AI Act?
The Action Plan itself is a coordinating framework rather than standalone legislation, so it does not impose independent legal obligations. Its practical effect is to reinforce and operationalize cybersecurity requirements already embedded in the EU AI Act, particularly for advanced and high-risk systems.
Which AI systems fall within scope of the EU's new centralized evaluation capability?
No company has to submit a system. The planned capacity will evaluate the cybersecurity capabilities of advanced AI models before they reach the EU market, in line with the AI Act. It is not tied to the AI Act's high-risk categories.
When will the EU secure AI testing platform be operational and mandatory for pre-deployment review?
It will not be mandatory, and the plan sets no engagement window for companies. The model evaluation capacity is expected from 2027. The date of 7 July 2026 is when the Commission presented the plan.
How does this Action Plan interact with NIS2 cybersecurity obligations for AI deployers?
It adds no separate compliance track. The plan promotes full implementation of NIS2 alongside the AI Act, DORA, the Cyber Resilience Act, and the Cyber Solidarity Act, so NIS2 entities keep their existing duties.
What cybersecurity documentation should AI deployers prepare ahead of the EU evaluation capability going live?
The plan itself requires no documentation. Keep the records your existing duties already call for, such as AI Act technical documentation and NIS2 risk management measures.
Can procurement contracts require suppliers to share results from the EU AI testing platform?
Companies can write such terms into contracts, but the plan creates no duty to share testing results. Any disclosure terms would be a commercial choice, not an EU requirement.