Blog post

EU Action Plan on Cybersecurity and AI: What Website Owners and Developers Need to Know

The European Commission's July 2026 Action Plan on Cybersecurity and AI bridges the AI Act with existing frameworks including NIS2 and the Cyber Resilience Act.

On July 6–7, 2026, the European Commission presented its Action Plan on Cybersecurity and AI — a coordinated framework that bridges the AI Act with existing cybersecurity regulations including NIS2, the Cyber Resilience Act, DORA, and the Cyber Solidarity Act.

This is not a new standalone regulation. It is an operational roadmap that connects existing legal instruments, clarifies obligations for AI systems at the intersection of cybersecurity rules, and allocates funding for implementation.

The Three Objectives

The Action Plan has three complementary goals:

1. Promote safe and responsible use of advanced AI. The Commission will strengthen its capacity to evaluate AI models before they enter the market, building on the AI Act’s risk-based classification. For developers, this means clearer expectations about what constitutes a “high-risk” AI system and what conformity assessments will look like in practice.

2. Reinforce EU cybersecurity and resilience. ENISA will develop a European Blueprint for secure structured access to advanced AI systems. This creates a standardised framework for auditing and testing AI models — something that currently varies wildly across member states.

3. Scale up Europe’s AI capabilities for cybersecurity. A secure testing platform for critical sectors (energy, transport, health, finance, public administration) will be established. The EU Grand Challenge on AI for cybersecurity functions as an innovation competition, directing funding toward practical AI security tools.

What This Means for EU-Based Businesses

If you operate a website, SaaS platform, or AI service in the EU, three things are directly relevant:

  • AI model evaluation pathways — if your application uses AI, expect clearer certification requirements modelled on the AI Act’s categories
  • Secure testing for critical sectors — if you serve energy, transport, health, finance, or public administration, your AI systems may need to pass the Commission’s planned testing platform before deployment
  • Innovation funding — the Grand Challenge and continued investment in AI Factories represent funding opportunities for teams building AI security tooling

The plan also explicitly encourages use of open-source AI models for cybersecurity. For more context on the current threat landscape, the analysis of pure data-theft extortion covers the security challenges driving this regulatory response.

Related What I Do

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.