Europe’s AI cyber strategy faces its biggest contradiction
EU Policy
For the past few years, the European Union has focused on writing the global rulebook for artificial intelligence and cybersecurity. Now comes the harder part: turning those rules into operational capability.
With its new Action Plan on Cybersecurity and Artificial Intelligence, the European Commission is shifting from regulation to implementation. The objective is increasingly urgent. Use AI to strengthen Europe’s cyber defences while preventing the same technology from becoming a force multiplier for cybercriminals.
The timing is no accident. AI is transforming cybersecurity at remarkable speed. It allows defenders to identify vulnerabilities, detect attacks and respond to incidents faster than ever before. But it is also equipping attackers with new tools. Advanced AI models can automate phishing campaigns, uncover software vulnerabilities in minutes instead of weeks and generate increasingly sophisticated malware.
The question is no longer whether AI will reshape cybersecurity. It is who learns to use it better, and faster.
Testing AI before it tests Europe
Rather than proposing another wave of legislation, the Commission focuses on implementation.
The first priority is ensuring advanced AI systems can be deployed safely. Working alongside the EU Agency for Cybersecurity (ENISA), Brussels plans to strengthen the testing and evaluation of AI models before they are widely adopted, building on the obligations already established under the AI Act.
A central element of the strategy is the creation of a dedicated testing platform where operators of critical infrastructure—including the energy, transport, healthcare, financial and public sectors—can experiment with AI-powered cybersecurity tools in controlled environments before deploying them in real-world systems.
The logic is familiar. Stress-test the technology before hackers do.
Europe wants AI on the defenders’ side
The second pillar focuses on resilience.
The Commission wants organisations to make greater use of AI for vulnerability detection, threat intelligence and incident response, while continuing to implement recently adopted legislation such as the NIS2 Directive and the Cyber Resilience Act.
The message is that AI should not replace Europe’s existing cybersecurity framework. It should reinforce it.
No new laws. Just a growing rulebook.
The Action Plan introduces no new regulatory obligations.
Instead, it builds on a legislative architecture that has expanded rapidly over the past several years. The AI Act already requires developers of advanced AI models to identify and mitigate systemic risks, while the General-Purpose AI Code of Practice provides guidance on how those obligations should be implemented. Most of these provisions begin applying from 2 August 2026.
By the end of 2027, the Cyber Resilience Act will also come fully into force, introducing mandatory cybersecurity requirements for hardware and software sold across the European Union.
In other words, Brussels appears convinced that Europe has written enough legislation. The next challenge is making sure it delivers.
Europe wants its own cyber champions
The Commission is also betting that cybersecurity can become another pillar of Europe’s AI industrial strategy.
The Action Plan announces the launch of an EU Grand Challenge on AI for Cybersecurity, bringing together companies, research institutes and developers to build AI-driven cyber defence technologies.
The initiative complements wider investments in Europe’s AI Factories and planned AI Gigafactories, which Brussels sees as essential to reducing dependence on foreign computing infrastructure while strengthening Europe’s technological sovereignty.
The underlying message is clear: cybersecurity is no longer just a security issue. It is becoming industrial policy.
As Brussels plans, NATO prepares
The publication of the Action Plan coincides with a broader shift in the international security debate.
As the Commission unveiled its strategy, NATO allies gathered in Ankara to discuss the growing role of AI, autonomous systems and emerging technologies in defence planning. The parallel is difficult to miss.
Both Brussels and NATO are moving beyond debating how AI should be regulated. The conversation is increasingly focused on how it should be deployed.
The next phase of Europe’s AI strategy
For several years, Europe has defined itself as the global regulator of artificial intelligence.
The next phase will test something different: whether regulation can translate into capability.
Protecting critical infrastructure, securing essential services and defending increasingly connected networks will require more than legal frameworks. It will require AI systems that can keep pace with attackers who are already using the technology themselves.
The age of AI regulation is giving way to the age of AI implementation. Europe’s success will depend on whether it can move just as quickly.


