Action Plan on Cybersecurity and Artificial Intelligence
Summary
The action plan sets out measures to make advanced AI capabilities available for cybersecurity while addressing AI-enabled threats. It covers an EU evaluation capacity for AI models, structured access to advanced capabilities, secure testing, guidance, vulnerability management and training. It also proposes a pilot campaign on critical open-source resilience, an EU Grand Challenge for AI-powered cybersecurity solutions, and use of AI Factories' computing capacity for cyber resilience.
Action items
1–6 of 9 items
Source order · D = digital dimension- Item 1
Key Action 1 – The Commission will support the establishment of an EU evaluation capacity for AI models that must include cybersecurity (2027).
- Item 2
Key Action 2 – The Commission in coordination with ENISA will define a European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes to ensure that European organisations can access such capabilities safely and timely (Q4 2026).
- Item 3
Key Action 3 - ENISA and the Joint Research Centre of the European Commission (JRC) will develop a secure testing platform for AI with advanced cyber capabilities for cybersecurity use cases to boost timely and secure deployment of AI in cybersecurity (Q4 2026).
- Item 4
Key Action 4 – ENISA in cooperation with relevant Union entities will issue guidance, recommendations, advisories and best practices on the protection against AI-powered threats and for the secure integration of AI in cybersecurity operations (as of Q3 2026)
- Item 5
Key Action 5 – The Commission, Member States, ENISA and industry will cooperate in view of making existing vulnerability management practices and tools fit for the AI Age (as of Q3 2026)
- Item 6
Key Action 6 – ENISA, in cooperation with the Commission, Member States, open source communities, Union entities and industry, will launch a first pilot of a Critical Open Source Resilience Campaign to accelerate patching including by leveraging AI (Q4 2026)