Artificial Intelligence, Cybersecurity, and Digital Sovereignty: The European Strategy and the Role of National Capabilities

Science and Technology - July 22, 2026

The emergence of advanced artificial intelligence models is profoundly transforming the cybersecurity landscape, introducing unprecedented opportunities but also new forms of risk. On the one hand, these technologies improve the ability to identify vulnerabilities, accelerate threat identification, and strengthen the resilience of digital infrastructures. On the other, the same tools can be used maliciously to automate cyber attacks, identify system weaknesses, and amplify the speed and scope of cyber incidents. To respond to this scenario, the European Commission has developed an Action Plan aimed at building a coordinated response to the risks and opportunities arising from advanced artificial intelligence applied to cybersecurity. The initiative involves Member States, European institutions, and the industrial sector with the aim of strengthening the security of the European digital ecosystem through an integrated approach based on cooperation, technological innovation, and a common regulatory framework.

EVALUATION AND THE EUROPEAN REGULATORY FRAMEWORK

One of the core elements of the strategy concerns the preventive evaluation of advanced artificial intelligence models. The rules introduced by the AI ​​Act require such systems to undergo a risk analysis and adopt appropriate mitigation measures before being released to the European market. To consolidate independent expertise in this area, the Commission will promote the creation of a European organization dedicated to the evaluation of AI models, with a particular focus on cybersecurity aspects. The infrastructure, expected to be operational by 2027, will strengthen independent assessments of the capabilities and risks of artificial intelligence at the international level, supporting the regulatory activities of the AI ​​Office. This initiative is part of an already comprehensive regulatory framework. In addition to the AI ​​Act, which will enter the full implementation phase of its provisions for advanced models on August 2, 2026, along with the Code of Conduct for Artificial Intelligence, the European strategy is based on the Cyber ​​Resilience Act, which will introduce the principle of security by design for hardware and software by the end of 2027; the NIS2 Directive for the protection of critical sectors; the Digital Operational Resilience Act for the financial sector; and the Cyber ​​Solidarity Act, designed to strengthen Europe’s capabilities for preventing, preparing for, and responding to large-scale cyberattacks.

ACCESS TO ADVANCED TECHNOLOGIES AND SECURE EXPERIMENTATION

Another objective of the Plan is to establish transparent and structured conditions for access to the most advanced artificial intelligence systems. To this end, the Commission will collaborate with the European Union Agency for Cybersecurity (ENISA) to develop a European model governing access to AI capabilities for cybersecurity, enabling public and private organizations to use these tools according to shared criteria. In parallel, ENISA and the Commission’s Joint Research Centre will develop a secure platform dedicated to testing artificial intelligence applied to cybersecurity. Simulated environments will allow for system behavior testing and dissemination of expertise on the safe use of AI among operators in strategic sectors, such as energy, transport, healthcare, finance, and public administration.

STRENGTHENING EUROPEAN RESILIENCE AND ENHANCEMENT OF NATIONAL CAPABILITIES

The Plan places particular emphasis on protecting Europe’s critical infrastructure, which is considered particularly vulnerable to vulnerabilities resulting from the misuse of artificial intelligence. Organizations are therefore called upon to strengthen cyber hygiene practices, risk management activities, and the adoption of the principle of security by design. At the same time, the use of existing artificial intelligence capabilities, including open source models, is encouraged to accelerate the identification and remediation of vulnerabilities, as well as to improve prevention and response to cyber attacks. In this context, the importance of preserving a strong national capacity to influence digital policies is particularly evident. While European coordination is essential for addressing transnational threats, each Member State must maintain autonomous technological expertise, decision-making capabilities, and industrial tools to protect its national security. The availability of internal expertise allows for the protection of essential infrastructure, reduction of external technological dependencies, and prompt intervention in the event of a cyber crisis. At the same time, investing in the national development of emerging technologies also serves as a lever for industrial policy, fostering the growth of innovative businesses, attracting investment, developing highly qualified human capital, and strengthening economic competitiveness. The ability to actively contribute to shaping European digital policies is therefore not only a matter of security, but also an essential condition for ensuring long-term economic development, innovation, and strategic autonomy.