The European Commission unveiled a sweeping action plan on July 7 to address the dual threat and promise of advanced artificial intelligence in cybersecurity, acknowledging that AI can now build cyber exploits in minutes at a fraction of the cost of human-led vulnerability discovery. The plan centers on five pillars: evaluating advanced AI models before they enter the EU market, establishing structured access to powerful AI systems for cybersecurity purposes, building secure testing platforms, reinforcing cyber hygiene across critical infrastructure, and scaling Europe's own AI capabilities through its AI Factories and Gigafactories programs.
EU digital chief Henna Virkkunen presented the initiative to the European Parliament, warning that weaponised AI vulnerabilities "endanger the security of our infrastructure and society". But the plan also exposes a stark vulnerability of its own. Europe remains heavily dependent on US-made AI models for advanced cybersecurity work. The Commission was forced to negotiate restricted access to Anthropic's most powerful model, Mythos, through a programme called Project Glasswing, after Washington briefly imposed and then lifted export controls on it. EuroNews described the plan as "a patchwork of existing regulatory tools and new initiatives," noting that Brussels currently lacks homegrown alternatives to American AI systems in this domain. The initiative builds on existing EU legislation including the AI Act, the Cyber Resilience Act, and the Network and Information Systems Directive.