7/19/2026, 1:03:49 PM · evaluation-safety

EU Launches Cybersecurity-AI Action Plan With Mandatory Pre-Market Evaluation Capacity for Advanced Models

The European Commission published a formal Action Plan on July 7, 2026 requiring pre-market evaluation of advanced artificial intelligence models under the EU AI Act, with a dedicated evaluation capacity targeting operational status by 2027.

Overview

<cite index="9-10">The European Commission launched the EU Action Plan on Cybersecurity and Artificial Intelligence (AI) on July 7, 2026, outlining measures for advanced AI model evaluation, controlled cybersecurity testing, faster vulnerability remediation, and European investment in AI security.</cite> The official document is registered as COM(2026) 577 final.

Pre-Market Evaluation Mandate

<cite index="5-4,5-5">Under the AI Act, advanced AI models must be evaluated and mitigation measures carefully assessed before the models are placed on the EU market. To foster homegrown expertise, the Commission will launch a dedicated call to establish an EU evaluation capacity, covering cybersecurity, expected to be operational in 2027.</cite> <cite index="5-6">This new capacity will contribute to the regulatory function of the AI Office by strengthening third-party assessment of AI capabilities and risks globally.</cite>

<cite index="9-16">The capacity must cover cybersecurity and will conduct independent third-party testing of model capabilities and provider safeguards before or around deployment, including evaluations that can support AI Act compliance work.</cite> <cite index="17-12,17-13">The EU therefore needs to reinforce available expertise to create a credible and competitive ecosystem of third-party evaluators to assess advanced AI capabilities and risk mitigations. To this end, the Commission will propose criteria for third-party evaluators for the purpose of the Code of Practice on General-Purpose AI (GPAI) and foster the development of a broader evaluation ecosystem.</cite>

Three Core Objectives

<cite index="9-12">The action plan focuses on three objectives: promoting the safe use of advanced AI, strengthening EU cyber resilience, and expanding European AI capabilities for cybersecurity.</cite>

On the threat side, <cite index="2-4">AI can be misused to identify vulnerabilities, automate attacks, and increase the scale and speed of cyber incidents at an unprecedented speed.</cite> <cite index="17-8,17-9">Recent research from the UK AI Security Institute suggests that, in controlled cybersecurity tests, the most advanced AI models are able to complete increasingly long tasks without human help, and the estimated length of tasks they can handle has been doubling over months rather than years.</cite>

ENISA Blueprint and Secure Testing Platform

<cite index="9-25,9-26">The Commission and the European Union Agency for Cybersecurity (ENISA) will complete a European Blueprint for structured access to advanced AI cybersecurity capabilities in the fourth quarter of 2026, and ENISA and the Commission's Joint Research Centre (JRC) will develop a separate secure testing platform during the same quarter for controlled cybersecurity trials.</cite> <cite index="9-27,9-28">The Blueprint will give model providers guidance on granting European organizations safe and timely access to advanced cyber capabilities, addressing eligibility, security criteria, information sharing and access procedures for organizations such as EU bodies, national authorities, critical infrastructure operators, security providers and researchers.</cite>

Legal Framework Integration

<cite index="9-14">The plan coordinates existing obligations under the AI Act, the Network and Information Systems Directive (NIS2), the Digital Operational Resilience Act (DORA), the Cyber Resilience Act, and the Cyber Solidarity Act rather than creating a separate compliance regime.</cite> <cite index="7-23">These provisions will start to be enforced on 2 August 2026.</cite>

Grand Challenge and Sovereign AI Investment

<cite index="11-7">To strengthen Europe's technological leadership, the Commission will launch an EU Grand Challenge on AI for cybersecurity, bringing together companies, researchers and other stakeholders to develop innovative AI-powered cybersecurity solutions.</cite> <cite index="5-18,5-19">The EU must continue investing in developing its own sovereign advanced AI capabilities, leveraging the infrastructure provided by AI Factories and future Gigafactories, with the upcoming European Tech equity capacity, announced in the Tech Sovereignty Package, potentially crowding in private investment to scale up homegrown AI capabilities.</cite>

Compliance Implications

<cite index="6-3">The plan treats frontier AI not as a consumer product requiring labelling and transparency disclosures — the EU AI Act's primary approach — but as an active security risk requiring inspection before deployment.</cite> <cite index="6-10">The categories of software most directly affected are those classified as high-risk under the EU AI Act — AI systems used in employment, education, critical infrastructure management, law enforcement or access to essential services — and AI systems that interact with or are implemented within critical infrastructure as defined under NIS2.</cite>

Sources

  1. [1]
    EU Action Plan on Cybersecurity and Artificial Intelligence | Shaping Europe’s digital future
  2. [2]
    Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence | Shaping Europe’s digital future
  3. [3]
    Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence
  4. [4]
    Factsheet - Action Plan on Cybersecurity and Artificial Intelligence | Shaping Europe’s digital future
  5. [5]
    European Commission Presents EU Action Plan on Cybersecurity and Artificial Intelligence - AIwire
  6. [6]
    What Does The New European Cyber Evaluation Plan Mean For Software Vendors? - TechRound
  7. [7]
    EU Commission launches plan to counter AI-driven cybersecurity threats – INSIGHT EU MONITORING
  8. [8]
    Exploited before the patch exists: inside the EU's Cybersecurity and AI Action Plan EU Cybersecurity and AI Action Plan: what it means for firms
  9. [9]
    EU Unveils Cybersecurity and AI Action Plan
  10. [10]
    AI Act | Shaping Europe's digital future - European Union
  11. [11]
    EU Launches Cybersecurity Action Plan With Mandate to Test Frontier AI Models Before Market Entry
  12. [12]
    EU Action Plan 2026 Bolsters AI Act for Frontier AI Models
  13. [13]
    Action Plan on Cybersecurity and Artificial Intelligence
  14. [14]
    Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence