The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, published earlier this month, sets out how the EU intends to respond to the threats and opportunities presented by AI.
The strategic framework links existing legislation, EU institutions, investment programmes and operational initiatives with the aim is to help European organisations adopt advanced AI securely while preparing for faster and more sophisticated cyber threats.
For businesses in the EU, and for organisations that trade with or supply EU customers, the direction is clear: AI-related cyber risk is becoming part of mainstream governance, resilience and compliance.
The Action Plan is the Commission’s coordinated response to the opportunities and risks created by advanced and frontier AI like Fable and Mythos.
Frontier AI refers to the most capable models currently available or under development. These systems can support vulnerability discovery, code analysis, threat detection, incident response and remediation. The same capabilities can also be misused by attackers.
The plan focuses on four objectives:
It builds on the EU AI Act, NIS2 Directive, Digital Operational Resilience Act, Cyber Resilience Act and Cyber Solidarity Act. It also gives ENISA, the Joint Research Centre and other EU bodies a central role in turning policy into practical guidance and operational support.
No. The Action Plan does not create a separate set of legal duties.
However, many of its recommendations are closely tied to existing obligations under NIS2, DORA, the AI Act and the Cyber Resilience Act. It also signals how regulators may assess cyber preparedness in an AI-enabled threat environment.
The Commission expects critical-sector operators and financial entities to review their risk management frameworks, prepare for attacks occurring at greater speed and scale, improve patching, strengthen system hardening and integrate AI securely into cyber operations.
Businesses should therefore treat the Action Plan as an indication of future supervisory, contractual and procurement expectations rather than as a purely aspirational policy document.
The first pillar focuses on evaluating frontier AI, controlling access to its advanced cyber capabilities and testing it safely.
The Commission plans to establish an EU evaluation capacity for advanced AI models, including their potential cyber risks. This will support oversight under the AI Act and help assess whether model providers are managing systemic risks effectively.
It will also create a European Blueprint for structured access to advanced AI capabilities. This is intended to give eligible European organisations, including public authorities, critical infrastructure operators, cyber security providers and researchers, a clearer route to powerful AI systems.
ENISA and the Joint Research Centre will also develop a secure testing platform. Organisations will be able to assess AI against realistic cyber security use cases without exposing production systems or critical infrastructure.
Cyber ranges will support this work by simulating networks, systems and operational environments in controlled conditions. These environments can be used to test AI-assisted detection, vulnerability scanning, triage, remediation and incident response.
The second pillar is focused on operational readiness.
The Commission’s concern is that AI is reducing the time and expertise needed to discover and exploit vulnerabilities. Existing security processes may not be fast enough to keep pace.
The Action Plan calls for stronger cyber security fundamentals, including:
It also highlights AI-specific risks such as prompt injection, model poisoning, data poisoning and adversarial attacks.
ENISA will publish guidance on both protecting against AI-powered threats and integrating AI securely into cyber security operations.
A major priority is vulnerability management. The Commission wants the European Union Vulnerability Database, national disclosure processes and the Cyber Resilience Act’s Single Reporting Platform to remain effective as AI increases the speed and volume of vulnerability discovery.
The challenge is no longer simply finding weaknesses. It is prioritising and fixing them before attackers exploit them.
The third pillar focuses on investment, sovereignty and skills.
Many of the most advanced AI models are developed outside the EU. Access to their cyber capabilities may be controlled by commercial providers or foreign governments.
The Commission sees this as both a security and economic risk.
The Action Plan proposes more investment in European AI models, compute infrastructure, AI factories, cyber security technologies and emerging providers.
It also includes an EU Grand Challenge on AI-assisted vulnerability remediation. This will bring together cyber security companies, AI developers, researchers, critical infrastructure operators and open-source communities to develop tools that support the full remediation process.
The EU also plans to introduce AI-focused training for cyber security professionals and update the European Cybersecurity Skills Framework to include new capabilities and roles.
AI can identify weaknesses and analyse code faster than many organisations can assess and patch them.
This creates an imbalance. Discovery is becoming more automated, but remediation often remains slow and manual.
Organisations must shorten the time between identifying an exposure and deploying an effective fix.
AI can support reconnaissance, phishing, social engineering, malicious code development and vulnerability exploitation.
This allows attackers to target more organisations with less effort. Security teams may face higher attack volumes, shorter response windows and more convincing lures.
European organisations may rely on non-European providers for advanced AI capabilities.
Access could be restricted, delayed or withdrawn. The proposed Blueprint aims to make access more structured, while the EU’s wider investment strategy is designed to reduce dependency on external providers.
AI is also a new attack surface.
Risks include:
These risks must be assessed before AI tools are connected to sensitive data, production systems or security workflows.
Modern software depends heavily on open-source components. A single widely used flaw can affect thousands of organisations.
The Action Plan proposes a Critical Open Source Resilience Campaign to identify and strengthen important components used in critical sectors. ENISA will also build a catalogue of AI-powered services to support patching and remediation.
AI will not remove the need for skilled cyber professionals.
Security teams will still need people who can validate outputs, investigate incidents, challenge automated decisions and understand business risk.
The skills gap may widen unless organisations invest in AI governance, model security and secure deployment capabilities.
For EU organisations, AI risk and cyber security risk can no longer be managed separately.
Organisations covered by NIS2, DORA or sector-specific regulation should review whether their risk assessments account for attackers using AI to move faster and operate at greater scale.
Annual assessments alone may no longer be enough. Risk management must reflect shorter attack timelines and more automated activity.
Businesses will need to show that they can:
A scan report is not enough. Organisations must demonstrate that findings lead to action.
AI governance should cover more than privacy, accuracy and ethics.
It should also address:
Security teams must know which AI systems are in use, what data they can access and what actions they are permitted to perform.
The Commission is not asking organisations to avoid AI.
It wants businesses to use it to improve resilience through areas such as:
These systems must still be tested, governed and subject to human oversight.
The Action Plan will also affect organisations in the UK, United States and elsewhere.
Its relevance depends on whether a company supplies, supports or processes data for EU customers.
Technology providers selling software or hardware in the EU must already consider the Cyber Resilience Act.
The Action Plan reinforces expectations around secure development, lifecycle support, vulnerability disclosure and timely patching.
Organisations covered by NIS2 and DORA must manage third-party risk.
Suppliers may increasingly be asked to provide information about:
These requirements are likely to appear in tenders, contracts and supplier assessments.
Providers of general-purpose and frontier AI may need to engage with EU evaluation structures, AI Act supervision and structured-access programmes.
Non-EU providers placing models or services on the European market may still fall within EU rules.
The Action Plan calls for cooperation through the G7, United Nations, NATO and bilateral partnerships.
Its approach to frontier AI evaluation, vulnerability management, open-source security and critical infrastructure protection may therefore shape standards beyond Europe.
Organisations should not wait for every Action Plan initiative to be completed.
They should begin by reviewing their exposure to both AI-enabled threats and insecure AI adoption.
Key priorities include:
Businesses should also examine whether their security operations can cope with faster attacks. Processes that rely heavily on manual triage and investigation may struggle as attackers increase automation.
The Action Plan is designed to help Europe adapt to a threat landscape in which both attackers and defenders operate faster.
Its central message is simple: annual assessments, slow patching and heavily manual security operations may no longer be enough.
Organisations need continuous visibility, faster prioritisation, stronger response capabilities and secure AI governance.
For EU businesses, these expectations will increasingly influence regulation and supervision. For organisations outside the EU, they will shape market access, contracts and supply-chain requirements.
Integrity360 helps organisations strengthen cyber resilience, reduce exposure and prepare for AI-enabled threats.
Our experts support businesses across Europe with cyber risk assessments, regulatory readiness, threat exposure management, vulnerability management, penetration testing, managed detection and response, incident response and AI security.
We can help you:
Speak to Integrity360 to build a more resilient, responsive and AI-ready cybersecurity programme.