Brussels opts against new legislation, focusing instead on frontier-model access, testing infrastructure and resilience as Europe seeks to reduce its dependence on foreign AI capabilities
The European Union has unveiled a new action plan on artificial intelligence and cybersecurity, but for European businesses its most important feature may be what it does not contain: another layer of legislation. Presented by the European Commission under Executive Vice-President Henna Virkkunen, responsible for technological sovereignty, security and democracy, the plan focuses on implementing the extensive regulatory framework Europe has already built. As Virkkunen put it, AI is changing the very meaning of cybersecurity, and Europe must keep pace.
The existing architecture already includes the AI Act, the Cyber Resilience Act, the NIS2 Directive, the Digital Operational Resilience Act for financial services and the Cyber Solidarity Act. Rather than imposing additional obligations, Brussels now wants to turn those rules into operational capabilities. Under the AI Act, the most advanced models must already undergo evaluation and risk mitigation before entering the European market. The Commission’s AI Office will now cooperate with specialised evaluators to examine frontier models, including their cybersecurity implications.
Europe’s dependence on foreign AI
Behind the strategy lies a more uncomfortable issue: many of the world’s most powerful AI capabilities are developed outside Europe. The problem became particularly visible when Mythos, a frontier model developed by Anthropic, demonstrated an ability to identify previously hidden software vulnerabilities, while access was subsequently restricted by a foreign government for non-US citizens.
For European cybersecurity operators, this illustrates a potential strategic vulnerability. If critical defensive capabilities depend on a single foreign supplier or government, access could theoretically disappear because of decisions made thousands of kilometres away. The Commission therefore plans to work with ENISA, the EU Agency for Cybersecurity, on a European framework providing structured access to advanced models useful for cyber defence. Brussels is also discussing early access to frontier technologies with the United States. The wider objective is technological sovereignty — not necessarily eliminating foreign technology, but ensuring Europe is not dangerously dependent on capabilities it cannot control.
A European testing platform
One of the plan’s most concrete measures is the creation of a secure European platform for testing AI cybersecurity applications ENISA and the Commission’s Joint Research Centre are expected to establish the infrastructure by the end of 2026. It will allow AI security tools to be evaluated in controlled and simulated environments while providing expertise to operators in critical sectors including finance, healthcare, energy, transport and public administration. Brussels does not, however, want organisations to wait for the platform before adopting AI.
Existing systems, including open models, should already be used to identify and patch vulnerabilities faster and improve responses to cyberattacks. ENISA is expected to publish guidelines and best practices and launch a pilot project aimed at strengthening the resilience of critical open-source software. Open-source technology has particular strategic significance in this context. Unlike a closed service controlled remotely by an external provider, software that organisations can inspect and operate on their own infrastructure reduces dependence on third parties.
From compliance to operational resilience
The plan also reinforces more traditional cybersecurity principles: good security hygiene, continuously updated risk management and security-by-design. For companies, this signals an important evolution in the European approach. Compliance remains necessary, but regulatory compliance alone cannot provide protection against increasingly sophisticated AI-assisted threats. That shift comes as the EU simultaneously simplifies parts of its AI regulatory timetable. Obligations affecting certain high-risk AI systems have been pushed further into the future, giving companies additional time to adapt. The direction increasingly appears to be from regulation alone towards practical capability: Europe wants organisations not merely to demonstrate compliance, but to possess the tools and expertise required to defend themselves.
A new market for European technology
That transition could also create significant opportunities for European companies.
By the end of 2026, Brussels plans to launch a European challenge dedicated to AI-powered cybersecurity solutions. The Commission is also exploring, together with the European Investment Bank, public financing mechanisms for strategically important technologies, including frontier AI There are already signs that European capabilities can compete. The Commission selected Europa, a consortium led by Italian company Domyn, as the winner of its frontier AI challenge — evidence that advanced European technology is not merely a theoretical ambition.
Nevertheless, Europe still faces a substantial technological gap. The Commission’s strategy acknowledges that sovereignty cannot simply be legislated into existence. It requires infrastructure, investment, expertise and companies capable of developing technologies that Europe can inspect, operate and ultimately control. For businesses, the message is equally clear. AI is becoming both a cybersecurity weapon and a potential vulnerability. Companies must therefore examine not only how powerful their security tools are, but who controls them and whether access can be guaranteed. Europe’s new plan does not attempt to answer those questions with another law. Instead, it marks the beginning of a more practical challenge: building enough technological capacity to ensure that European cybersecurity is never entirely dependent on someone else’s permission.