Insights | Integrity360

The EU Cybersecurity and AI Action Plan: What businesses need to know

Written by Matthew Olney | 20 July 2026 05:00:00 Z

The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, published earlier this month, sets out how the EU intends to respond to the threats and opportunities presented by AI.

The strategic framework links existing legislation, EU institutions, investment programmes and operational initiatives with the aim is to help European organisations adopt advanced AI securely while preparing for faster and more sophisticated cyber threats.

For businesses in the EU, and for organisations that trade with or supply EU customers, the direction is clear: AI-related cyber risk is becoming part of mainstream governance, resilience and compliance.

 

 

What is the EU Action Plan on Cybersecurity and Artificial Intelligence?

The Action Plan is the Commission’s coordinated response to the opportunities and risks created by advanced and frontier AI like Fable and Mythos.

Frontier AI refers to the most capable models currently available or under development. These systems can support vulnerability discovery, code analysis, threat detection, incident response and remediation. The same capabilities can also be misused by attackers.

The plan focuses on four objectives:

    • Making frontier AI safer and more accessible for legitimate cyber security use.
    • Preparing critical sectors, SMEs and public bodies for AI-powered threats.
    • Expanding Europe’s own AI and cyber security capabilities.
    • Promoting international cooperation on secure AI development and deployment.

It builds on the EU AI Act, NIS2 Directive, Digital Operational Resilience Act, Cyber Resilience Act and Cyber Solidarity Act. It also gives ENISA, the Joint Research Centre and other EU bodies a central role in turning policy into practical guidance and operational support.

Is it a new law?

No. The Action Plan does not create a separate set of legal duties.

However, many of its recommendations are closely tied to existing obligations under NIS2, DORA, the AI Act and the Cyber Resilience Act. It also signals how regulators may assess cyber preparedness in an AI-enabled threat environment.

The Commission expects critical-sector operators and financial entities to review their risk management frameworks, prepare for attacks occurring at greater speed and scale, improve patching, strengthen system hardening and integrate AI securely into cyber operations.

Businesses should therefore treat the Action Plan as an indication of future supervisory, contractual and procurement expectations rather than as a purely aspirational policy document.

 

 

The Three Main Pillars

Pillar 1: Making advanced AI safe and accessible

The first pillar focuses on evaluating frontier AI, controlling access to its advanced cyber capabilities and testing it safely.

The Commission plans to establish an EU evaluation capacity for advanced AI models, including their potential cyber risks. This will support oversight under the AI Act and help assess whether model providers are managing systemic risks effectively.

It will also create a European Blueprint for structured access to advanced AI capabilities. This is intended to give eligible European organisations, including public authorities, critical infrastructure operators, cyber security providers and researchers, a clearer route to powerful AI systems.

ENISA and the Joint Research Centre will also develop a secure testing platform. Organisations will be able to assess AI against realistic cyber security use cases without exposing production systems or critical infrastructure.

Cyber ranges will support this work by simulating networks, systems and operational environments in controlled conditions. These environments can be used to test AI-assisted detection, vulnerability scanning, triage, remediation and incident response.

Pillar 2: Preparing Europe for AI-powered attacks

The second pillar is focused on operational readiness.

The Commission’s concern is that AI is reducing the time and expertise needed to discover and exploit vulnerabilities. Existing security processes may not be fast enough to keep pace.

The Action Plan calls for stronger cyber security fundamentals, including:

    • Asset and exposure visibility
    • Secure configuration and system hardening
    • Zero Trust where appropriate
    • Vulnerability management
    • Secure coding
    • Faster risk-based patching
    • Coordinated vulnerability disclosure
    • Effective detection and incident response

It also highlights AI-specific risks such as prompt injection, model poisoning, data poisoning and adversarial attacks.

ENISA will publish guidance on both protecting against AI-powered threats and integrating AI securely into cyber security operations.

A major priority is vulnerability management. The Commission wants the European Union Vulnerability Database, national disclosure processes and the Cyber Resilience Act’s Single Reporting Platform to remain effective as AI increases the speed and volume of vulnerability discovery.

The challenge is no longer simply finding weaknesses. It is prioritising and fixing them before attackers exploit them.

Pillar 3: Scaling European cyber-AI capabilities

The third pillar focuses on investment, sovereignty and skills.

Many of the most advanced AI models are developed outside the EU. Access to their cyber capabilities may be controlled by commercial providers or foreign governments.

The Commission sees this as both a security and economic risk.

The Action Plan proposes more investment in European AI models, compute infrastructure, AI factories, cyber security technologies and emerging providers.

It also includes an EU Grand Challenge on AI-assisted vulnerability remediation. This will bring together cyber security companies, AI developers, researchers, critical infrastructure operators and open-source communities to develop tools that support the full remediation process.

The EU also plans to introduce AI-focused training for cyber security professionals and update the European Cybersecurity Skills Framework to include new capabilities and roles.

 

 

What challenges does the action plan address?

AI Is accelerating vulnerability discovery

AI can identify weaknesses and analyse code faster than many organisations can assess and patch them.

This creates an imbalance. Discovery is becoming more automated, but remediation often remains slow and manual.

Organisations must shorten the time between identifying an exposure and deploying an effective fix.

Attacks are becoming easier to scale

AI can support reconnaissance, phishing, social engineering, malicious code development and vulnerability exploitation.

This allows attackers to target more organisations with less effort. Security teams may face higher attack volumes, shorter response windows and more convincing lures.

Frontier AI is controlled by a small number of providers

European organisations may rely on non-European providers for advanced AI capabilities.

Access could be restricted, delayed or withdrawn. The proposed Blueprint aims to make access more structured, while the EU’s wider investment strategy is designed to reduce dependency on external providers.

AI creates new security risks

AI is also a new attack surface.

Risks include:

    • Prompt injection
    • Sensitive data leakage
    • Poisoned training or retrieval data
    • Insecure integrations
    • Excessive permissions
    • Compromised model supply chains
    • Unauthorised autonomous actions

These risks must be assessed before AI tools are connected to sensitive data, production systems or security workflows.

Open-source dependencies remain a weak point

Modern software depends heavily on open-source components. A single widely used flaw can affect thousands of organisations.

The Action Plan proposes a Critical Open Source Resilience Campaign to identify and strengthen important components used in critical sectors. ENISA will also build a catalogue of AI-powered services to support patching and remediation.

Europe faces a skills gap

AI will not remove the need for skilled cyber professionals.

Security teams will still need people who can validate outputs, investigate incidents, challenge automated decisions and understand business risk.

The skills gap may widen unless organisations invest in AI governance, model security and secure deployment capabilities.

What does it mean for businesses in the EU?

For EU organisations, AI risk and cyber security risk can no longer be managed separately.

Risk assessments must reflect AI-enabled threats

Organisations covered by NIS2, DORA or sector-specific regulation should review whether their risk assessments account for attackers using AI to move faster and operate at greater scale.

Annual assessments alone may no longer be enough. Risk management must reflect shorter attack timelines and more automated activity.

 

 

Patching will face greater scrutiny

Businesses will need to show that they can:

    • Identify affected assets quickly
    • Prioritise vulnerabilities based on business risk
    • Deploy emergency fixes safely
    • Patch complex systems
    • Track exceptions and compensating controls
    • Measure remediation performance

A scan report is not enough. Organisations must demonstrate that findings lead to action.

AI governance must include security

AI governance should cover more than privacy, accuracy and ethics.

It should also address:

    • Identity and access controls
    • Data exposure
    • Third-party dependencies
    • Model permissions
    • Monitoring
    • Incident response
    • Business continuity
    • Agentic AI risks

Security teams must know which AI systems are in use, what data they can access and what actions they are permitted to perform.

Security teams will be expected to use AI responsibly

The Commission is not asking organisations to avoid AI.

It wants businesses to use it to improve resilience through areas such as:

    • Threat detection
    • Alert triage
    • Threat intelligence
    • Vulnerability prioritisation
    • Code analysis
    • Incident investigation
    • Compliance monitoring
    • Remediation planning

These systems must still be tested, governed and subject to human oversight.

What does it mean for businesses outside the EU?

The Action Plan will also affect organisations in the UK, United States and elsewhere.

Its relevance depends on whether a company supplies, supports or processes data for EU customers.

EU Market access will influence product security

Technology providers selling software or hardware in the EU must already consider the Cyber Resilience Act.

The Action Plan reinforces expectations around secure development, lifecycle support, vulnerability disclosure and timely patching.

EU customers may demand more from suppliers

Organisations covered by NIS2 and DORA must manage third-party risk.

Suppliers may increasingly be asked to provide information about:

    • AI systems used in service delivery
    • Model and data providers
    • Security controls
    • Incident notification
    • Vulnerability management
    • Software dependencies
    • Business continuity
    • Data location and protection

These requirements are likely to appear in tenders, contracts and supplier assessments.

 

 

AI providers may face new evaluation expectations

Providers of general-purpose and frontier AI may need to engage with EU evaluation structures, AI Act supervision and structured-access programmes.

Non-EU providers placing models or services on the European market may still fall within EU rules.

EU standards may influence global practice

The Action Plan calls for cooperation through the G7, United Nations, NATO and bilateral partnerships.

Its approach to frontier AI evaluation, vulnerability management, open-source security and critical infrastructure protection may therefore shape standards beyond Europe.

What should businesses do now?

Organisations should not wait for every Action Plan initiative to be completed.

They should begin by reviewing their exposure to both AI-enabled threats and insecure AI adoption.

Key priorities include:

    • Mapping current AI use
    • Reviewing AI-related risks
    • Testing incident response plans
    • Improving vulnerability prioritisation
    • Reducing patching delays
    • Assessing supplier dependencies
    • Strengthening identity controls
    • Training cyber security teams
    • Testing AI tools before production deployment

Businesses should also examine whether their security operations can cope with faster attacks. Processes that rely heavily on manual triage and investigation may struggle as attackers increase automation.

Preparing for Cybersecurity at AI Speed

The Action Plan is designed to help Europe adapt to a threat landscape in which both attackers and defenders operate faster.

Its central message is simple: annual assessments, slow patching and heavily manual security operations may no longer be enough.

Organisations need continuous visibility, faster prioritisation, stronger response capabilities and secure AI governance.

For EU businesses, these expectations will increasingly influence regulation and supervision. For organisations outside the EU, they will shape market access, contracts and supply-chain requirements.

How Integrity360 can help

Integrity360 helps organisations strengthen cyber resilience, reduce exposure and prepare for AI-enabled threats.

Our experts support businesses across Europe with cyber risk assessments, regulatory readiness, threat exposure management, vulnerability management, penetration testing, managed detection and response, incident response and AI security.

We can help you:

    • Assess the security impact of AI adoption
    • Identify and prioritise critical exposures
    • Improve vulnerability remediation
    • Strengthen detection and response
    • Review third-party and supply-chain risk
    • Prepare for NIS2, DORA and related requirements
    • Test whether existing controls can withstand faster, AI-powered attacks

Speak to Integrity360 to build a more resilient, responsive and AI-ready cybersecurity programme.