A New Era of AI Security Testing
In July 2026, the European Commission released the Action Plan on Cybersecurity and Artificial Intelligence, setting out a coordinated approach to address the dual nature of AI in cybersecurity. AI can strengthen cyber defenses, but it can also automate attacks at unprecedented scale. The Action Plan establishes concrete initiatives to help Member States, businesses, and public authorities harness AI benefits while mitigating emerging risks.
At the center of this initiative is a new secure testing platform that will enable organizations in critical sectors to safely test and deploy AI solutions. The platform, expected to be operational by 2027, represents a significant investment in Europe’s technical infrastructure for AI safety.
The Three Pillars of the Action Plan
The Action Plan rests on three complementary objectives:
-
Promoting the safe and responsible use of advanced AI — through enhanced evaluation capacity and secure access frameworks.
-
Reinforcing the EU’s cybersecurity and resilience — through implementation of existing cybersecurity legislation and AI-powered vulnerability detection.
-
Scaling up Europe’s AI capabilities for cybersecurity — through research investments, innovation challenges, and sovereign AI development.
These pillars reflect the Commission’s recognition that AI security is not solely about regulating AI systems themselves, but also about building the broader ecosystem of tools, capabilities, and standards needed for secure AI deployment.
Expanded EU Evaluation Capacity
The Commission will launch a call to increase EU evaluation capacity for AI models before they are placed on the EU market. This initiative directly supports the AI Office’s regulatory function by providing the technical infrastructure needed to assess AI capabilities and risks independently.
Under the AI Act, general-purpose AI models that may carry systemic risks are subject to evaluation obligations. The expanded evaluation capacity will:
- Enable third-party assessment of AI model capabilities, including the ability to detect and prevent malicious use
- Support the AI Office’s role in overseeing systemic-risk GPAI models
- Provide a technical foundation for enforcement actions against non-compliant providers
- Offer smaller Member States access to evaluation resources they could not develop independently
This capacity is particularly important given the concentration of advanced AI development among a small number of global companies. By developing sovereign evaluation capabilities, the EU reduces its dependence on external assessments and ensures that regulatory decisions are based on rigorous, independent technical analysis.
Secure Testing Platform for Critical Sectors
Working with the European Union Agency for Cybersecurity (ENISA), the Commission will establish a secure testing platform designed specifically for organizations in critical sectors. These sectors include energy, transport, health, finance, and public administration — all of which are increasingly adopting AI for cybersecurity and operational purposes.
The platform will enable organizations to:
- Test AI-based cybersecurity tools in controlled, isolated environments
- Validate that AI systems meet cybersecurity requirements before deployment
- Assess the resilience of AI systems against adversarial attacks
- Identify potential vulnerabilities or unintended behaviors in AI applications
For critical infrastructure operators, the platform provides a resource that few individual organizations could justify developing independently. By sharing this infrastructure across sectors, the EU accelerates the safe adoption of AI for cybersecurity while reducing duplication of effort.
European Blueprint for Secure Access to AI
The Action Plan includes a European Blueprint for secure access to advanced AI systems for cybersecurity purposes. This blueprint will establish:
- Standards and best practices for integrating AI into cybersecurity operations
- Architectural patterns for secure AI deployment
- Guidelines for data sharing between AI systems and cybersecurity infrastructure
- Requirements for monitoring and maintaining secure AI deployments
The blueprint is particularly relevant for organizations that must comply with multiple regulatory frameworks. The AI Act, Cyber Resilience Act, NIS2 Directive, Digital Operational Resilience Act (DORA), and Cyber Solidarity Act all impose requirements on the secure deployment of digital systems. The blueprint will clarify how AI-specific requirements integrate with these existing regimes.
Implementing Existing Cybersecurity Legislation
While much of the Action Plan focuses on new initiatives, it also emphasizes the importance of implementing existing EU cybersecurity legislation. The NIS2 Directive and the Cyber Resilience Act establish baseline cybersecurity requirements for digital products and services. AI systems fall within this scope, and organizations must ensure their AI deployments meet these obligations alongside AI Act requirements.
The Action Plan encourages organizations to use AI, including open-source models where appropriate, to strengthen their cybersecurity posture. Specifically, AI can help:
- Detect and classify vulnerabilities more quickly than manual analysis
- Identify patterns in security events that human analysts might miss
- Automate incident response workflows while maintaining human oversight
- Predict and prevent attacks before they materialize
This dual perspective — AI as both a security risk and a security tool — is central to the Action Plan’s approach.
EU Grand Challenge on AI for Cybersecurity
To stimulate innovation, the Commission will launch an EU Grand Challenge on AI for cybersecurity. This challenge will bring together companies, researchers, and other stakeholders to develop innovative AI-powered cybersecurity solutions.
The Grand Challenge aims to:
- Accelerate the development of next-generation AI cybersecurity tools
- Identify breakthrough approaches to emerging AI-enabled threats
- Foster collaboration between industry, research institutions, and public authorities
- Highlight European leadership in AI for cybersecurity
For organizations developing AI-based cybersecurity products, the Grand Challenge offers both funding opportunities and visibility within the European market.
Sovereign AI Capabilities and Investment
The Action Plan continues the EU’s investment in sovereign AI capabilities, building on initiatives such as AI Factories and future Gigafactories. These investments aim to ensure that Europe has the computational resources, talent, and infrastructure needed to develop and deploy advanced AI systems securely.
Sovereign AI capabilities are particularly important for cybersecurity applications, where reliance on external providers may introduce security risks. By developing domestic AI capabilities, the EU reduces its exposure to supply chain vulnerabilities and ensures that critical cybersecurity functions can be maintained independently.
Interplay with the AI Act
The Action Plan is explicitly designed to complement the EU’s existing AI legal framework, particularly the AI Act. Several connections are worth noting:
-
Evaluation capacity: The expanded evaluation capacity supports the AI Office’s role in assessing systemic-risk GPAI models under the AI Act.
-
High-risk AI systems: AI systems used for cybersecurity in critical infrastructure may be classified as high-risk under Annex III of the AI Act. The testing platform will help providers and deployers meet their compliance obligations.
-
Cybersecurity requirements: The Action Plan’s emphasis on secure AI deployment aligns with the cybersecurity and robustness requirements in Article 15 of the AI Act.
-
Conformity assessment: For high-risk AI systems, conformity assessment includes cybersecurity evaluation. The Action Plan’s initiatives provide resources to support this process.
Implications for Organizations
The Action Plan has several practical implications for organizations developing or deploying AI systems:
For AI System Providers
-
Prepare for third-party evaluation: If your models may carry systemic risks, expect increased scrutiny as EU evaluation capacity expands. Prepare documentation demonstrating your model’s capabilities and risk mitigation measures.
-
Engage with the testing platform: The secure testing platform will offer a resource for validating AI system security before market placement. Early engagement can provide competitive advantages.
-
Monitor the blueprint: The European Blueprint for secure access will establish standards that may become de facto requirements for AI systems in cybersecurity applications.
For Critical Infrastructure Operators
-
Plan for platform participation: The secure testing platform will be a resource for safely deploying AI systems. Identify high-priority AI use cases and plan for platform participation.
-
Review regulatory interplay: Ensure your AI deployments comply with both the AI Act and cybersecurity legislation (NIS2, DORA, Cyber Resilience Act). The Action Plan’s initiatives will provide guidance on this integration.
-
Consider open-source AI: The Action Plan encourages the use of open-source AI models for cybersecurity. Evaluate whether open-source solutions meet your security and compliance requirements.
For All Organizations
-
Stay informed on AI threat developments: As AI capabilities advance, so do AI-enabled threats. The Action Plan’s initiatives will generate intelligence on emerging threats and mitigation strategies.
-
Invest in AI literacy: The Action Plan emphasizes the importance of understanding AI’s role in cybersecurity. Build internal expertise on AI security principles and practices.
Timeline and Next Steps
The secure testing platform and expanded evaluation capacity are expected to become operational by 2027. In the interim, organizations should:
- Monitor AI Office and ENISA announcements for implementation updates
- Begin preparing documentation that may be required for third-party evaluation
- Identify AI use cases that would benefit from secure testing environments
- Review current cybersecurity practices against emerging AI threat scenarios
Conclusion
The July 2026 Action Plan on Cybersecurity and AI represents a significant investment in Europe’s technical infrastructure for safe AI deployment. For organizations navigating the intersection of AI and cybersecurity, the Action Plan provides both resources and clarity on regulatory expectations.
As with all AI Act implementation efforts, the key is proactive engagement. Organizations that monitor these developments, participate in testing initiatives, and align their practices with emerging standards will be well-positioned to meet compliance requirements while benefiting from AI’s transformative potential for cybersecurity.
Jurista.ai monitors all AI Act technical standards and cybersecurity requirements, ensuring your compliance program stays current with the latest EU initiatives. Assess your compliance at jurista.ai.