A coordination plan, not a new law
On 7 July 2026, the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence, COM(2026) 577, alongside remarks from Executive Vice-President Henna Virkkunen: "AI is transforming the meaning of cybersecurity. And we must keep pace." Unlike the AI Act or the Cyber Resilience Act before it, this document creates no new legal obligations. It is explicitly a coordinating instrument, stitching together the NIS2 Directive, the Cyber Resilience Act, the Digital Operational Resilience Act (DORA), and the Cyber Solidarity Act into a single response to one problem: frontier AI models that can now find and weaponize software vulnerabilities far faster than human red teams.
The plan sets three objectives, per the Commission's own framing: promoting the safe and responsible use of advanced AI, reinforcing the EU's cybersecurity resilience, and scaling up Europe's AI capabilities for cybersecurity work. The most concrete deliverable is operational rather than legislative — ENISA, working with the Commission's Joint Research Centre, is tasked with building a secure testing platform (framed as part of a "European Blueprint for secure access to advanced AI systems for cybersecurity purposes") that lets critical-sector operators in energy, transport, health, finance, and public administration trial AI tools for vulnerability scanning, triage, and incident response in a controlled environment before deploying them live. The target is the end of 2026.
The case for coordination
There's a real problem here, and the Commission is right to name it. Generative and agentic AI has compressed the time between vulnerability discovery and exploit development from weeks to hours, and the same capabilities that let a defender triage a breach in minutes let an attacker automate reconnaissance across thousands of targets at once. A hospital IT department or a mid-sized utility has no realistic way to independently evaluate a frontier model's cybersecurity capability or safety guardrails — that expertise and infrastructure sits with a handful of labs and hyperscalers, mostly headquartered outside the EU. A shared, publicly backed testing environment that lets operators evaluate AI tools before betting critical infrastructure on them is a proportionate response to that gap, not an overreach. It is also, notably, the kind of intervention this publication tends to favor over the alternative: infrastructure and access rather than a new licensing regime layered atop the AI Act's already dense compliance architecture.
Where the plan is thinner than it looks
The trouble is the plan can't manufacture what Europe doesn't have: frontier models of its own. As Euronews reported the day the plan launched, Brussels is negotiating with the same US labs — OpenAI and Anthropic chief among them — whose models it now wants ENISA to test, and those labs have shown a preference for voluntary evaluation regimes like the UK's AI Security Institute over binding EU oversight. MEP Aura Salla put the underlying problem plainly: "Europe has strong AI research, but too few companies operating at this frontier." A testing platform is only as useful as the labs willing to expose their models to it, and nothing in COM(2026) 577 compels that cooperation — it invites it. The plan's parallel investment in "AI Factories" and future "Gigafactories" compute capacity is a longer-run answer to that dependency, but it does nothing to close the gap for the sectors this plan is meant to protect in 2026 or 2027.
There's also a sequencing risk worth naming rather than glossing over. The AI Act's obligations on providers of general-purpose models with systemic risk are already live, and NIS2 has already pushed thousands of "important" and "essential" entities across the bloc into new incident-reporting duties. Layering a fifth coordinating framework on top of four existing ones, without new enforcement teeth, risks becoming what some analysts have already dismissed it as: a restatement of existing tools dressed up as a new initiative, with the real deliverables — the testing platform, an EU Grand Challenge on AI for cybersecurity — buried inside a document that reads more like a policy communiqué than an operational mandate.
The proportionate path
None of this argues for scrapping the plan. A voluntary, shared testing infrastructure that critical-sector operators can opt into, without a parallel licensing burden, is close to the right shape for this problem — better than either doing nothing or reaching for a new authorization regime that would slow deployment of the defensive AI tools operators actually need. What the plan needs now is less rhetorical positioning about "keeping pace" and more transparency about who is actually testing on the ENISA platform, what happens when a frontier lab declines to participate, and how the Commission will measure whether the end-of-2026 deadline was met. Coordination plans succeed or fail on follow-through, not on the confidence of the press release announcing them. The Commission has correctly diagnosed the problem; whether it can deliver the platform on schedule, with labs that have every incentive to test elsewhere, is the actual story to watch through the rest of 2026.