AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkEUHigh risk

EU Action Plan on Cybersecurity and Artificial Intelligence

Issued by

European Commission

liveEffective 2026-07-07EU-CS-AIVerified July 2026

The European Commission presented this Action Plan on July 7, 2026, to strengthen the cybersecurity of AI systems deployed in the EU and to build regulatory evaluation capacity in support of the EU AI Act. It establishes a formal EU evaluation capability for advanced AI models, targeted for operation by 2027, and a secure AI testing platform expected to launch by end of 2026. Enterprises placing advanced AI models on the EU market should expect enhanced pre-market evaluation requirements coordinated through the AI Office.

Applies To

Large enterpriseAI developerAI deployerPublic sector

Overview

The EU Action Plan on Cybersecurity and Artificial Intelligence is a European Commission initiative that operationalizes the cybersecurity and model evaluation dimensions of the EU AI Act. It creates two core infrastructure elements: an EU-level evaluation capacity for advanced AI models, which is intended to be operational in 2027, and a secure AI testing platform expected to be available by end of 2026. The plan formally supports the AI Office's regulatory function and reinforces the existing requirement under the EU AI Act that advanced AI models undergo evaluation before being placed on the EU market. Enforcement of pre-market evaluation obligations flows through the AI Act's existing compliance and supervisory mechanisms, coordinated by the AI Office. The Action Plan signals the Commission's intent to develop harmonized evaluation standards and technical infrastructure that providers of general-purpose AI models and frontier systems will be required to engage with. Enterprises operating or procuring advanced AI models in the EU should treat this as a timeline anchor for compliance readiness.

Key Requirements

  • AI model providers must submit advanced AI models for EU-level evaluation before EU market entry, consistent with existing AI Act obligations.
  • Enterprises must engage with the secure AI testing platform once operational, expected by end of 2026.
  • Providers of general-purpose AI models designated as high-capability must cooperate with EU evaluation capacity infrastructure from 2027 onward.
  • Organizations must align internal cybersecurity controls for AI systems with standards developed under the Action Plan as they are published.
  • Compliance timelines are linked to the AI Act enforcement schedule; providers should monitor AI Office guidance for evaluation procedure details.
  • Non-compliance with pre-market evaluation requirements may trigger enforcement under the AI Act, including market access restrictions and financial penalties.

What Your Organization Must Do

  • Audit all advanced and general-purpose AI models in your portfolio now to identify which will be subject to pre-market evaluation requirements under the AI Act and this Action Plan.
  • Establish a timeline tracker linked to the end-of-2026 testing platform launch and the 2027 evaluation capacity go-live, assigning internal owners to each milestone.
  • Engage with the AI Office's published guidance and consultation processes to monitor evaluation procedure requirements as they are finalized.
  • Update procurement and vendor contracts to require AI model providers to demonstrate conformity with EU evaluation procedures before deployment in EU markets.
  • Incorporate cybersecurity-specific controls for AI systems into your existing information security management framework in anticipation of standards issued under the Action Plan.
  • Brief legal and technical teams on the intersection of this Action Plan with existing EU AI Act obligations to avoid duplicating or missing compliance activities.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

When does the EU Action Plan on Cybersecurity and AI take effect and what are the key infrastructure milestones?
The Action Plan was presented on July 7, 2026. The secure AI testing platform is expected to launch by end of 2026, and the EU-level evaluation capacity for advanced AI models is targeted to be operational in 2027. Compliance timelines track alongside the EU AI Act enforcement schedule.
Which companies are subject to pre-market evaluation requirements under the EU-CS-AI Action Plan?
Providers placing advanced AI models and general-purpose AI models with high-capability designations on the EU market are directly affected. Large enterprises deploying or procuring such models in the EU are also subject to related obligations, including updated procurement and cybersecurity control requirements.
How does the EU-CS-AI Action Plan relate to existing EU AI Act obligations?
The Action Plan operationalizes the cybersecurity and model evaluation dimensions of the EU AI Act rather than creating entirely separate requirements. Pre-market evaluation obligations are enforced through the AI Act's existing supervisory mechanisms, coordinated by the AI Office, so compliance teams should treat this as an extension of AI Act readiness work.
What penalties apply if a company fails to comply with pre-market evaluation requirements under this framework?
Non-compliance with pre-market evaluation requirements can trigger enforcement under the EU AI Act, including market access restrictions and financial penalties. The Action Plan itself does not establish new penalty structures; enforcement authority remains with the AI Office and competent national authorities under the AI Act.
What steps should compliance teams take now given the 2026 testing platform and 2027 evaluation capacity deadlines?
Compliance teams should immediately audit all advanced and general-purpose AI models in their portfolio to identify evaluation obligations, assign internal owners to the end-of-2026 and 2027 milestones, and update vendor contracts to require conformity evidence from AI model providers before EU deployment.
Will the EU-CS-AI Action Plan introduce new harmonized cybersecurity standards for AI systems, and when should companies expect them?
The Action Plan signals the Commission's intent to develop harmonized evaluation and cybersecurity standards for AI systems, but specific standards have not yet been published. Organizations should monitor AI Office guidance and consultation processes closely, and begin incorporating AI-specific cybersecurity controls into existing information security management frameworks now in anticipation of forthcoming requirements.