KAPTOR SECURITY
What we do Services Process About Blog Contact Get Audit
Kaptor Research

The EU’s New Action Plan on Cybersecurity and Artificial Intelligence: What Organizations Need to Know

A strategic roadmap for how Europe intends to strengthen its cybersecurity capabilities in an era where AI is a defining factor in both cyber defense and cyber attacks.

Author José Rabal Sastre
Co-founder & AI Security Lead at Kaptor
Date 16 Jul 2026

Contents


The European Commission has unveiled its Action Plan on Cybersecurity and Artificial Intelligence, setting out a strategic roadmap for how Europe intends to strengthen its cybersecurity capabilities in an era where Artificial Intelligence (AI) is becoming a defining factor in both cyber defense and cyber attacks.

Rather than introducing new legislation, the Action Plan outlines a series of initiatives designed to accelerate the secure adoption of AI across the cybersecurity ecosystem, strengthen Europe’s technological capabilities, and reduce its dependence on non-EU providers.

The full document is available on the European Commission’s website under the title EU Action Plan on Cybersecurity and Artificial Intelligence [1].


AI Is Reshaping the Cybersecurity Landscape

The Commission’s starting point is simple. Artificial Intelligence is fundamentally changing cybersecurity.

Advanced AI models are enabling security teams to detect threats more quickly, automate complex analysis, and respond to incidents faster than ever before. At the same time, cybercriminals are using many of these same capabilities to launch attacks that are more sophisticated, more scalable, and harder to detect.

Europe’s challenge is to capitalize on AI’s potential while ensuring that the risks associated with these technologies remain under control.


Three Strategic Priorities

The Action Plan is built around three strategic priorities that will shape the EU’s cybersecurity agenda in the coming years.

1. Accelerating the Secure Adoption of Advanced AI

The first pillar focuses on frontier AI models, which are the most advanced AI systems currently available or under development.

Key initiatives include:

The objective is to ensure that Europe develops its own capability to assess both the opportunities and the risks associated with advanced AI, helping organizations adopt these technologies with greater confidence.

2. Strengthening Europe’s Readiness for AI-Driven Cyber Threats

The second pillar focuses on improving the preparedness of both public and private organizations.

According to the Commission, AI will significantly reduce the time required to identify and exploit software vulnerabilities. As attackers become faster, defenders will need to accelerate their own capabilities.

To strengthen cyber resilience, the Action Plan promotes initiatives such as:

The roadmap also foresees ENISA publishing dedicated guidance and best practices to help organizations defend against AI-enabled cyber threats while integrating AI technologies into their cybersecurity operations safely and responsibly.

3. Building Europe’s AI Capabilities for Cybersecurity

The third pillar reflects a broader strategic objective of strengthening Europe’s technological sovereignty.

The Commission acknowledges that many of today’s most advanced AI capabilities are developed outside the European Union. As a result, European organizations remain heavily dependent on technology providers based elsewhere.

To reduce that dependency, the Action Plan proposes a range of initiatives aimed at strengthening Europe’s own AI ecosystem. These include:

According to the Commission, strengthening these capabilities will be essential to improving Europe’s digital resilience and reinforcing its long-term technological sovereignty.


Nine Priority Actions

The Action Plan also identifies nine priority initiatives that will support these strategic objectives. Among them are:


What This Means for Organizations

Although the Action Plan is primarily aimed at EU institutions and Member States, it offers valuable insight into the future direction of cybersecurity across Europe.

One message stands out clearly. Artificial Intelligence is no longer simply another emerging technology. It is becoming a core element of both cyber defense and cyber threats.

Organizations that are already adopting AI, or planning to do so, should expect increased attention on AI-specific risk management, secure development practices, vulnerability management, and governance frameworks that enable AI to be deployed safely and responsibly.

Preparing for these changes today will help organizations strengthen their cyber resilience while positioning themselves to meet future regulatory expectations.


How Kaptor Security Can Help

At Kaptor Security, we closely monitor the latest regulatory, technical, and strategic developments in Cybersecurity and Artificial Intelligence. Our goal is to help organizations understand how these changes may affect their business and prepare for what comes next.

Whether your organization is already integrating AI into its operations or evaluating future adoption, our specialists can help you assess risks, strengthen security, and implement best practices for securing AI systems with confidence.


References

  1. European Commission. Action Plan on Cybersecurity and Artificial Intelligence. COM(2026) 577 final. 7 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence