EU unveils AI cybersecurity action plan to build on Cyber Resilience Act

The European Commission unveiled an Action Plan on Cybersecurity and Artificial Intelligence aimed at helping Member States, public authorities, and industry address cyber risks associated with advanced AI systems.

The plan includes measures to expand AI-assisted vulnerability detection, establish an EU capability to evaluate advanced AI models, and develop secure testing environments for AI systems. It builds on existing legislation, including the Cyber Resilience Act, the AI Act, and NIS2.

The Commission said the initiative will support the secure development and deployment of AI by strengthening collaboration between governments, industry, and the cybersecurity community. Planned actions include coordinated vulnerability disclosure, AI-powered cyber defense capabilities, and guidance for organizations deploying AI in critical sectors.

The plan’s press release can be found here: New EU plan to address the risks and opportunities of advanced AI for cybersecurity – European Commission

Steven Swift, Managing Director, Suzu Labs provided this comment:

   “The problem with locking new frontier models behind a governmental pre-release screening, is that it gives governments a mechanism to require frontier labs to modify their models in ways that aligns with political preferences, such as selecting which version of the truth they want models to present. While at the same time being able to claim “for better security” as the official reason to gate the release at all.

   “The other problem with it, is that there isn’t really a difference between the offensive and defensive capabilities of a model. Even if screening focus is narrowly focused on cybersecurity capabilities, actively lowering a model’s offensive capabilities directly impacts its ability to perform defensive work. Especially defensive verification, which is critical. Models will hallucinate unpredictably. It is absolutely essential that agentic systems be capable of building tests to verify the validity of results to ensure that hallucinations aren’t present.

   “This makes frontier models more insecure, and makes their use less safe. Despite the entire point of cybersecurity review process to be the opposite.

   “If we are going to gate frontier models behind an approval process, it is absolutely critical that the structured access programs actually function effectively to get legitimate security professionals, and developers access to sensitive unrestricted models, so that appropriate verification and testing can be performed on their own systems.”

Seemant Sehgal, Founder & CEO, BreachLock has this comment:

   “The EU is right to treat this as an infrastructure problem, not a software problem. AI embedded in critical sectors carries the same risk profile as power grids and financial rails in that a failure isn’t an inconvenience, but a systemic event.

   “The window to set baseline security expectations before widespread deployment is already closing. What makes this harder than traditional infrastructure is that AI systems don’t stay static after deployment. The testing frameworks have to keep pace with that. The real question is whether coordinated disclosure and continuously updated validation environments can be stood up before adversaries finish mapping what Europe has already put in place.”

Doc McConnell, Head of Policy and Compliance, Finite State adds this:

   “This action plan presents what the EU sees as an ideal ecosystem to support safe, responsible, and innovative development and utilization of AI across the Union. That vision is ambitious, including a stronger system of third-party AI evaluators, sovereign AI capacity, multi-state workforce training, and secure testing platforms. These will require significant investment, international coordination, and development of new technology. And as the EU works to achieve these goals, existing frontier labs will continue to innovate, and new open-weight models may emerge.

   “The specificity of this action plan stands in contrast to the U.S. policy on AI security, as laid out in the June 2026 Executive Order Promoting Advanced Artificial Intelligence Innovation and Security. Although the goals are similar, including protection of critical infrastructure, early government access to cybersecurity tools, and the promotion of innovation, the U.S. approach is much more open-ended.

   “I expect that neither approach will fully meet this moment, and we will see national policies have to adapt along with the technology they are seeking to oversee. The action plan describes a promising future: one of “unprecedented opportunities to enhance cyber resilience.” That is the goal to keep in mind. Even as plans, priorities, and AI models change, we must all, individual technologists and commercial companies, as well as policymakers, make choices that prioritize AI as an enabler of better defense, greater resilience, and stronger international security.”

The US and other countries that are not in the EU should copy what the EU is doing as the EU has the right idea here. And other countries when all is said and done are on the wrong side of history.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading