[Commentary] European Commission Issues Action Plan for AI Cybersecurity

IT

On July 7, 2026, the European Commission announced the “Action Plan on Cybersecurity and AI” to address the cyber risks posed by advanced artificial intelligence (AI). As rapid technological innovation advances attack methods, the aim is to integrate existing regulations and enhance defense capabilities and digital sovereignty within Europe.

Europe’s comprehensive approach to integrating existing regulations

On July 7, 2026, the European Commission presented a comprehensive “Action Plan on Cybersecurity and AI (COM (2026) 577 final)” aimed at addressing cybersecurity risks posed by advanced artificial intelligence (AI) while maximizing its benefits. This plan does not immediately establish new legal obligations, but rather addresses how existing regulatory frameworks—such as the AI Act, Cyber Resilience Act (CRA), NIS2 Directive, Digital Operational Resilience Act (DORA), and Cyber Solidarity Act—are applied to specific risks posed by advanced AI models. It defines how effectively it can be adjusted. The European Commission strongly recognizes that while advanced AI improves software vulnerability identification and immediate incident response capabilities, if abused, it is a “double-edged sword” that leads to automated attack processes and dramatic expansion of damage. This action plan aims to unite the strengths of EU member states, industry, European institutions, researchers, and the open source community to systematically strengthen defense capabilities in the digital landscape across Europe.

The threat posed by cutting-edge AI in the ‘democratization of attacks’

Behind the formulation of the action plan is a serious sense of urgency, as AI technology is evolving at a pace far surpassing traditional regulatory and governance update cycles. For example, high-performance AI like Claude Mythos, developed by Anthropic in the United States, possesses the ability to detect software vulnerabilities in a short time at a level that would take humans decades, leading to the “democratization” of cyberattacks. Cyberattacks, which previously required advanced skills and training, are becoming easily executed by individuals without specialized knowledge thanks to the spread of AI. Please refer to the diagram below.

Figure 1

。 Christine Lagarde, President of the European Central Bank (ECB), has also warned that the risks posed by AI are far more serious than traditional cyber threats, pointing out that defenders’ capabilities and funding for countermeasures are not keeping pace with technological advances. To respond to such a rapid technological shift, the European Commission decided that rather than waiting for years of legislative processes, it is necessary to proactively and flexibly operate the existing legal framework to counter the automation of AI-driven attacks and the acceleration of cyber incidents.

[Core Measures: Building Evaluation Systems and Securing Access Rights]

Evaluation Function for AI Models Aiming for Operation in 2027

One of the most important concrete measures in the action plan is to establish a capability to rigorously assess cybersecurity risks before advanced AI models enter the European market. The European Commission has launched a public call aiming to activate this evaluation function by 2027, aiming to strengthen the objective evaluation system for AI capabilities by independent third-party organizations. This legally requires careful consideration of specific risk mitigation measures for models with potential risks of being exploited in large-scale cyberattacks before being deployed to the market. Additionally, in close cooperation with the European Union Agency for Cybersecurity (ENISA), the company plans to develop a “European Blueprint for Structured Access” by the fourth quarter of 2026 to leverage advanced AI capabilities for cybersecurity purposes. This is a crucial step for European public and private organizations to enable them to use advanced AI technologies for their national defenses safely and predictably, without unilaterally blocking technology access due to opaque decisions by foreign countries or companies.

Unique capacity development to support European digital sovereignty

Europe aims to reduce excessive dependence on external forces such as the United States and China in the field of advanced AI, solidifying its own “digital sovereignty.” This action plan clearly states that the large-scale competition “EU Grand Challenge on AI,” bringing together companies, researchers, and organizations, will be launched in the fourth quarter of 2026 to strongly foster Europe’s unique AI-based cybersecurity solutions. Furthermore, the plan is to directly leverage access to cutting-edge infrastructure such as “AI factories” and future “gigafactories” to secure advanced AI computing capabilities to strengthen cyber resilience within the region. Meanwhile, there is ongoing discussion about drafting the “Cloud AI Development Act (CADA),” which could hierarchically restrict access for non-European providers, raising concerns within the industry that this could lead to market fragmentation and the exclusion of non-European providers. The European Commission is skillfully linking these sovereignty efforts with existing technological sovereignty packages to enhance Europe’s technological competitiveness while building stable supply chains.

[Future Developments: Strengthening Resilience and the Future of International Cooperation]

Providing a secure testing environment and protecting open source

To help raise concrete defense capabilities, the European Commission, ENISA, and the Joint Research Center (JRC) will build a “secure test platform (Cyberrange)” to practically validate AI for cybersecurity purposes by the fourth quarter of 2026. In the virtual environment provided by this platform, operators of critical infrastructure can proactively verify the effectiveness of the latest AI tools based on realistic attack scenarios and establish secure operational methods. Additionally, taking the reality that about 80% of software code used in critical European infrastructure contains some form of open source components, a pilot project called the “Critical Open Source Resilience Campaign” is scheduled to launch in Q4 2026. Furthermore, to cultivate advanced cybersecurity professionals proficient in AI, the “Cybersecurity Skills Academy” will provide state-of-the-art training modules specialized in AI utilization, accelerating the qualitative improvement of the European workforce and automation of vulnerability management processes as a key pillar of the plan.

Corporate preparations for full-scale regulation in August 2026

As an important milestone going forward, August 2, 2026, marks a critical benchmark for providers of General AI (GPAI) models with system risk to begin rigorous documentation and compliance under the European AI Act. Additionally, this action plan incorporates a broad international perspective, aiming to properly manage the impact of advanced AI on national security and collective defense by deepening collaboration with the G7 working group, the United Nations, and even NATO, and promoting common technical standards and scientific evaluation methods on a global scale. On the other hand, there are harsh findings showing that many of the current major AI models do not fully meet European legal standards, making how to ensure the effectiveness of the established regulations remains a major challenge going forward. The European Commission’s current plan is an ambitious attempt to establish a security framework for the rapidly changing AI era by simultaneously establishing a “shield” of providing evaluation infrastructure and supporting technological development, not only through the “constraints” of legal regulation but also by providing an evaluation infrastructure and supporting technological development. Companies and organizations will be required to closely monitor the guidelines to be released by ENISA and make advanced strategic decisions on how to safely integrate AI technology into the protection of their infrastructure. Please refer to the diagram below.

Figure 2

[#欧州委員会 #AI法 #サイバーセキュリティ #デジタル主権 #人工知能 #EU #テクノロジー #サイバーレジリエンス]

コメント

Copied title and URL