The EU's Plan for AI-Powered Cyberattacks: Test the Models, Rally the Builders, Pass No New Laws

The takeaway: The European Commission has set out how it intends to deal with AI on both sides of the cybersecurity fight — as a technology that can automate attacks at a speed and scale defenders haven't faced before, and as the best available defence. The Action Plan on Cybersecurity and Artificial Intelligence, presented on 7 July and doing the rounds in trade press this week, is notable as much for what it doesn't do as what it does: no new legislation, no headline funding figure — instead, testing infrastructure, an ENISA-built access blueprint, and a public challenge prize, all bolted onto laws the EU has already passed.
What's actually in it
The plan is organised around three objectives: promoting the safe and responsible use of advanced AI, reinforcing the EU's cybersecurity and resilience, and scaling up Europe's AI capabilities for cybersecurity. Concretely, per the Commission's own summary, that means:
- Model evaluation before market placement. The Commission wants stronger capacity to evaluate advanced AI models before they reach the EU market, aligned with the AI Act's existing machinery — the same law whose transparency obligations begin applying in August.
- A "European Blueprint for secure access to advanced AI systems for cybersecurity purposes", to be developed with ENISA, the EU's cybersecurity agency — governing who gets to use frontier models for security work, and how.
- A secure testing platform for organisations in critical sectors — such as energy, transport, health, finance and public administration — to trial AI tools without exposing live systems.
- An "EU Grand Challenge on AI for cybersecurity", a competition intended to pull companies and researchers toward defensive applications, alongside continued sovereign-compute investment through the AI Factories programme.
- Implementation of what already exists — the NIS2 directive and the Cyber Resilience Act — rather than new rules, with explicit encouragement to adopt AI, including open-source models, for vulnerability detection and incident response.
Executive Vice-President Henna Virkkunen's framing: "AI is transforming the meaning of cybersecurity. And we must keep pace."
The reading between the lines
The threat model here is the one Western security agencies have been shouting about all summer — the Five Eyes' joint warning in June put AI-enabled cyberattacks on a timescale of "not years, months" — and the interesting choice is the EU's posture in response. Where the AI Act built new law, this plan deliberately doesn't: it channels everything through existing frameworks and voluntary coordination. That reads two ways. Charitably: the EU has learned that legislation moves at treaty speed while attacks move at model-release speed, so it's reaching for the tools it can deploy this year. Sceptically: a blueprint, a platform and a prize are what you announce when the budget conversation hasn't happened yet — no new funding figure is named in the announcement or its published summary (the full plan document recaps roughly €200m of existing Horizon and Digital Europe commitments — money already pledged, not new).
For UK and non-EU readers, the practical bit is the testing platform: if it materialises, it becomes the reference environment for what "safely deploying AI in critical infrastructure" looks like on this side of the Atlantic — and the de facto bar suppliers will be asked to clear.
Ask Relay — he reads every question himself and replies personally by email.
