EU Unveils New AI & Cybersecurity Action Plan: Model Audits, Controlled Access, and Testing for Critical Infrastructure

The European Commission has released a comprehensive Action Plan on AI and cybersecurity, outlining new rules for evaluating advanced AI models, controlled access for critical sectors, and a dedicated testing platform for critical infrastructure.

EU Unveils New AI & Cybersecurity Action Plan: Model Audits, Controlled Access, and Testing for Critical Infrastructure

The European Commission has just dropped a bombshell that will reshape how AI and cybersecurity intersect across the continent. On July 8, 2026, it unveiled a new Action Plan on Cybersecurity and Artificial Intelligence — a sweeping regulatory blueprint that acknowledges both the promise and the peril of advanced AI. The message is clear: AI is a double-edged sword, and the EU intends to wield it with a very firm grip.

As AI models grow more powerful, they are becoming both a defender's dream and an attacker's weapon. The Commission warns that while AI can identify vulnerabilities and protect critical infrastructure, malicious actors can also use it to automate attacks and find weaknesses at machine speed. The Action Plan aims to create a coordinated European response — one that balances innovation with security, and sets the stage for a new era of AI governance.

Three Pillars of the New AI Cybersecurity Framework

The Action Plan is built on three core objectives: promoting the safe and responsible use of advanced AI models, strengthening the EU's cybersecurity resilience, and developing European capabilities in AI-driven security. To achieve these, the Commission is launching several concrete initiatives that will directly impact businesses, governments, and security professionals across the bloc.

An EU-Run AI Model Evaluation Capability

Perhaps the most significant measure is the creation of a dedicated European capacity for evaluating advanced AI models before they hit the market. This new body, expected to become operational in 2027, will work alongside the EU AI Office to conduct independent assessments of capabilities and risks. In plain terms: if you're a company developing a cutting-edge AI model and you want to sell it in Europe, expect a thorough pre-market security review. This is not just about compliance — it's about ensuring that models don't ship with hidden vulnerabilities that could be exploited.

Controlled Access to Top-Tier AI Systems

The Commission also wants to ensure that public and private organizations — especially those in cybersecurity — have structured, transparent access to the most advanced AI models. To that end, it will work with ENISA (the EU Agency for Cybersecurity) to develop a European guide for structured access. This is a recognition that not all organizations can or should have unfettered access to powerful AI; instead, access should be governed by clear rules that balance utility with security. For penetration testers and security teams, this could mean a more predictable and secure pathway to using state-of-the-art AI for defensive purposes.

A Secure Testing Platform for Critical Infrastructure

Another headline measure is the creation of a secure testing platform for AI-based solutions, developed by ENISA and the Joint Research Centre. This platform will use simulated environments to test AI technologies before they are deployed in critical sectors such as energy, transport, healthcare, finance, and public administration. For organizations operating in these sectors, this is a direct call to action: start preparing now for mandatory pre-deployment testing of any AI tools you plan to use. The platform is designed to catch flaws before they become exploits, and it will likely become a benchmark for AI security across Europe.

Encouraging AI-Driven Vulnerability Detection — and a New Competition

The Commission is not just regulating; it's also encouraging organizations to actively use AI for cybersecurity. It recommends that institutions and companies leverage available AI capabilities — including open-source models — to speed up vulnerability discovery, remediation, and incident response. ENISA will facilitate partnerships between public authorities, private sector, and open-source communities, and will publish best practices. To spur innovation, the EU will launch an "EU Grand Challenge on AI for Cybersecurity," a competition bringing together companies, researchers, and organizations to develop AI-powered security solutions. This is a clear signal that the EU wants to foster a homegrown ecosystem of AI security tools, reducing reliance on non-European technologies.

What This Means for Your Organization — and the Regulatory Landscape

The Action Plan doesn't exist in a vacuum. It builds on existing EU legislation that is already coming into force. From August 2, 2026, obligations under the AI Act for general-purpose AI models kick in, including requirements for risk assessment and mitigation. The Cyber Resilience Act will be fully applicable by end of 2027, mandating security-by-design for hardware and software products. The NIS2 Directive tightens cybersecurity for critical sectors, while DORA does the same for finance. And the Cyber Solidarity Act aims to bolster the EU's collective ability to detect and respond to large-scale attacks.

For Pentest.md's readers — security professionals and decision-makers — the takeaway is straightforward: the era of unregulated AI in cybersecurity is ending. The EU is building a framework that will require proactive evaluation, controlled access, and rigorous testing. Organizations that start aligning their AI governance and security practices now will be ahead of the curve. Those that wait may find themselves scrambling to meet requirements that are already taking shape. The Action Plan is a roadmap — and the journey starts now.

Request a scoping call · Penetration testing services