Brands
Latest top stories
Technology

Europe's next strategic dependency may be AI itself

10 July 2026

 

The European Commission has unveiled a new Action Plan on Cybersecurity and Artificial Intelligence, setting out a strategy to help Europe defend its digital infrastructure as artificial intelligence rapidly transforms the cyber threat landscape. The plan includes a new European capability to evaluate advanced AI models, secure testing environments for operators of critical infrastructure and fresh investment in European AI cybersecurity technologies.

 

 

The timing is significant. On the same day, the European Systemic Risk Board (ESRB) warned that frontier AI models are fundamentally changing cyber risk, enabling attacks to become faster, more sophisticated and potentially systemic. The board also highlighted a growing strategic concern: many of today's leading frontier AI providers are headquartered outside the European Union, creating new dependencies for sectors that may increasingly rely on AI to defend themselves.

Taken together, the announcements suggest Europe's AI debate is entering a new phase.

For much of the past three years, Brussels has been associated primarily with regulating artificial intelligence. The latest initiatives tell a broader story. As AI becomes essential for protecting banks, hospitals, electricity grids and transport networks, Europe is no longer asking only how AI should be governed. It is also asking who develops it, how it should be evaluated and whether the continent can safely depend on technologies developed elsewhere.

 

AI is changing the economics of cybersecurity

 

Cybersecurity has always been a contest between attackers and defenders. What is changing is the pace—and increasingly the economics—of that contest.

Frontier AI models can analyse enormous quantities of software, identify patterns that would previously have taken analysts days to uncover and automate repetitive technical work. Security teams are already using AI to detect software vulnerabilities, prioritise patches, analyse suspicious behaviour and accelerate incident response.

The same capabilities can also benefit attackers.

According to the European Union Agency for Cybersecurity (ENISA), frontier AI is lowering the barriers to sophisticated cyber operations. Advanced models can assist with reconnaissance, vulnerability research, phishing campaigns and malware development while significantly accelerating multiple stages of an attack. Human expertise remains indispensable, but AI is compressing the time between identifying a weakness and exploiting it.

That changes more than operational speed. It changes the cost of cybercrime.

Tasks that once demanded highly specialised expertise can increasingly be automated or augmented by AI, allowing attackers to operate at greater scale while enabling defenders to automate more of their own security operations.

For organisations responsible for critical infrastructure—including energy networks, financial institutions, healthcare providers, telecommunications operators and transport systems—keeping pace increasingly requires AI-assisted defence.

The Commission explicitly recognises this shift.

Rather than treating artificial intelligence solely as a source of cyber risk, the Action Plan encourages organisations to deploy AI-enabled security tools—including appropriate open-source models—to strengthen vulnerability detection, improve cyber resilience and accelerate software remediation.

Open-source AI receives particular attention because it can make advanced cybersecurity capabilities more widely accessible, allowing organisations to adapt and inspect models while reducing barriers to adoption. At the same time, the Commission stresses that these systems must be deployed responsibly and within appropriate security frameworks.

The message is clear: AI is rapidly becoming part of the cybersecurity toolkit rather than an optional enhancement.

 

Building trust before deploying AI

 

If AI is becoming essential for cyber defence, another question immediately follows.

How can organisations trust increasingly capable AI systems before deploying them to protect critical infrastructure?

That challenge sits at the heart of one of the Action Plan's most important proposals.

The Commission intends to establish a European evaluation capability dedicated to assessing the cybersecurity characteristics and risks of advanced AI models in support of the AI Office under the AI Act. Expected to become operational in 2027, the capability is designed to strengthen independent technical evaluation as frontier AI systems become increasingly powerful.

The significance extends beyond regulatory compliance.

As foundation models grow more capable, policymakers increasingly recognise that effective oversight requires independent technical expertise rather than relying solely on information provided by developers themselves.

The evaluation capability therefore represents more than another compliance mechanism. It is part of the institutional infrastructure Europe believes it will need to understand, assess and oversee advanced AI systems as they become embedded across critical sectors.

 

Turning legislation into operational capability

 

The Action Plan also demonstrates how Europe's growing body of digital legislation is beginning to fit together.

The AI Act establishes obligations for providers of advanced AI systems. The Cyber Resilience Act introduces cybersecurity requirements for products with digital elements. The NIS2 Directive strengthens cybersecurity obligations for operators of essential services, while the Digital Operational Resilience Act (DORA) raises resilience requirements across the financial sector.

Collectively, these laws define what organisations are expected to achieve.

The Action Plan focuses on helping them do it.

One practical example is the creation of secure testing environments by ENISA and the Commission's Joint Research Centre. These cyber ranges will allow organisations to evaluate AI-enabled cybersecurity tools in realistic simulated environments before introducing them into operational networks.

Banks preparing for DORA, energy companies implementing NIS2 requirements and healthcare organisations strengthening digital resilience will be able to test defensive AI technologies without exposing live infrastructure to unnecessary risk.

The Commission also plans to develop a European framework for structured access to advanced AI models, enabling trusted public and private organisations to use leading AI systems for cybersecurity applications under appropriate safeguards.

Rather than introducing another layer of regulation, the Action Plan provides an operational framework that supports legislation already entering into force.

 

From cyber resilience to technological resilience

 

The Action Plan also reveals a broader shift in European industrial policy.

Alongside new oversight mechanisms, the Commission is investing in Europe's ability to develop its own cybersecurity AI capabilities. It plans to launch an EU Grand Challenge on AI for cybersecurity, bringing together researchers, start-ups, established companies and public institutions to accelerate innovation in defensive AI.

The initiative complements wider investments in European AI infrastructure, including AI Factories and the Commission's broader Tech Sovereignty agenda.

Individually, these initiatives may appear to address different policy objectives.

Viewed together, however, they point towards a coherent strategy.

Europe is seeking to strengthen its ability to develop, evaluate and deploy advanced AI rather than relying exclusively on capabilities created elsewhere. That does not mean attempting complete technological self-sufficiency. International collaboration will remain essential. But it does reflect growing recognition that certain AI capabilities are becoming strategically important.

This mirrors a pattern already visible across other technologies.

Over the past several years, Europe has sought to reduce vulnerabilities in areas such as semiconductors, cloud infrastructure, batteries and energy systems. Artificial intelligence is increasingly being viewed through the same strategic lens.

 

More than another Brussels policy

 

Taken on its own, the Action Plan could easily be interpreted as another technical policy document supporting existing legislation.

Seen alongside ENISA's assessment of frontier AI and the ESRB's warning about systemic cyber risk, it signals something more fundamental.

Artificial intelligence is becoming part of the infrastructure that protects modern society. The systems identifying vulnerabilities, analysing threats and defending essential services will themselves depend on increasingly capable AI.

That raises questions extending far beyond cybersecurity.

Who develops those systems? How are they evaluated? Who determines whether they are trustworthy enough to defend critical infrastructure? And if many of the most advanced frontier AI capabilities continue to originate outside Europe, how should the continent balance openness with resilience?

The Commission's Action Plan does not attempt to answer all of those questions.

It does, however, suggest that Europe's AI strategy is evolving. The conversation is no longer centred solely on regulating artificial intelligence after it reaches the market. Increasingly, it is about building the technical expertise, institutional capacity and industrial capabilities needed to ensure that the AI defending Europe's critical infrastructure is understood, tested and trusted.

Whether that approach can keep pace with the rapid evolution of frontier AI remains an open question. What already seems clear is that Europe no longer sees cybersecurity and artificial intelligence as separate policy challenges. They are rapidly becoming two sides of the same strategic equation.

 

 

Liked this article? You can support our independent journalism via our page on Buy Me a Coffee. It helps keep MoveTheNeedle.news focused on depth, not clicks.

👉 https://buymeacoffee.com/movetheneedle.news