Overview
<cite index="18-2">On 7 July 2026, the European Commission published its EU Cybersecurity and Artificial Intelligence Action Plan (COM(2026) 577 final), a coordinated programme of nine actions layered on binding law already in force.</cite> <cite index="5-3">The Action Plan reflects the Commission's view that advanced AI models can improve vulnerability detection, incident response, and infrastructure protection, but also can be misused to identify weaknesses, automate attacks, and increase the speed and scale of cyber incidents.</cite>
Regulatory Context
<cite index="18-4,18-5">The plan sets nine actions across three objectives: making frontier AI safe and available for cyber defence, hardening the EU's critical infrastructure, and scaling Europe's own AI capacity for cybersecurity. It is a communication, not a regulation, so it creates no new binding duties.</cite> <cite index="1-6">The plan coordinates existing obligations under the AI Act, the Network and Information Systems 2 (NIS2) Directive, the Digital Operational Resilience Act (DORA), the Cyber Resilience Act, and the Cyber Solidarity Act, rather than creating a separate compliance regime.</cite>
Third-Party Evaluation Capacity
The centrepiece of the Action Plan is a new EU-level model assessment infrastructure. <cite index="3-4,3-5">The Commission will launch a call to increase EU evaluation capacity of AI models before they are placed on the EU market. Expected to be operational by 2027, this will strengthen third-party assessment of AI capabilities and risks and contribute to the regulatory function of the AI Office.</cite>
<cite index="11-1,11-2">The AI Act also highlights the importance of pre-deployment evaluation through third-party entities to assess and mitigate systemic risks. To date, most leading entities performing pre-deployment third-party evaluations of AI models are based outside the EU.</cite> The new capacity is explicitly designed to address that gap.
<cite index="15-9,15-10">Without an independent evaluation body, even well-drafted rules about advanced AI models depend on vendors' own documentation and self-assessment. The 2027 evaluation capacity changes that calculus for any provider seeking EU market access: third-party assessment becomes the path to market, not an optional audit.</cite>
Enforcement Timeline
<cite index="4-10,4-11">Starting August 2, 2026, the Commission will exercise its supervisory powers under the AI Act to oversee general-purpose AI (GPAI) models, particularly those posing systemic cybersecurity risks. This includes requesting information, conducting evaluations, demanding risk mitigation measures, and imposing fines of up to 3% of global annual turnover.</cite>
<cite index="6-11,6-12">The AI Act requires providers to assess and mitigate risks from AI models, while the General-Purpose AI Code of Practice further specifies these requirements and facilitates compliance by advanced model providers. These provisions will start to be enforced on 2 August 2026.</cite>
ENISA Blueprint and Secure Testing Platform
<cite index="22-1,22-2">To promote the safe use of advanced AI, the Commission will strengthen Europe's capacity to evaluate AI models before they are placed on the EU market. It will also work with the European Union Agency for Cybersecurity (ENISA) to develop a European Blueprint for secure access to advanced AI systems for cybersecurity purposes and establish a secure testing platform to help organisations in critical sectors, such as energy, transport, health, finance, and public administration, safely test and deploy AI solutions.</cite>
<cite index="9-7">According to Euractiv's reporting, the plan includes a "European Blueprint" with ENISA to establish secure access conditions for frontier models, prompted in part by concerns around Anthropic's Mythos model.</cite>
Investment and International Cooperation
<cite index="17-13,17-14">The EU is already investing around €200 million through Horizon Europe and Digital Europe programmes until the end of the current Multiannual Financial Framework. By the end of 2026, the Commission will facilitate €100 million in European Innovation Council (EIC) Fund investments in cybersecurity and AI startups as part of strategic defence technology investments.</cite> <cite index="4-6">International cooperation with G7, bilateral partners, and NATO is also a key component.</cite>
Near-Term Milestones
<cite index="16-7">In the fourth quarter of 2026, the Commission targets completion or launch of the access Blueprint, secure testing platform, open-source campaign pilot, AI remediation Grand Challenge, and cyber-AI training modules.</cite> <cite index="16-8">The EU model-evaluation capacity is then scheduled for establishment in 2027.</cite> <cite index="6-13">The Cyber Resilience Act, to be applicable by end of 2027, will separately mandate security-by-design for hardware and software products.</cite>