Why the new action plan affects more businesses than many think
On 7 July 2026, the European Commission presented the EU Action Plan on Cybersecurity and Artificial Intelligence, its first coordinated strategy for how advanced AI models are changing both cyberattacks and cyberdefence. Many decision makers have already dismissed it as Brussels strategy language for tech giants and government agencies. That is a misreading. The plan is addressed to the whole economy, and it tells every company already covered by the EU’s cybersecurity rules what supervisory authorities will expect next: treat AI as an attack risk, and start using it in your own defence.
What is the Action Plan on Cybersecurity and Artificial Intelligence?
The action plan is a policy instrument, not a new law. It builds on the legal framework the EU has put in place over recent years: Regulation (EU) 2024/1689 (the AI Act), Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2024/2847 (the Cyber Resilience Act), Regulation (EU) 2022/2554 (DORA) and the Cyber Solidarity Act. Instead of adding new obligations, it coordinates how member states, industry and EU bodies such as ENISA, the EU’s cybersecurity agency, will use existing capabilities against AI-driven threats. Executive Vice-President Henna Virkkunen summed up the ambition when she said that “AI is transforming the meaning of cybersecurity. And we must keep pace.”
What does the plan actually contain?
The plan is organised around three complementary objectives: promoting the safe and responsible use of advanced AI, reinforcing the EU’s cybersecurity and resilience, and scaling up Europe’s AI capabilities for cybersecurity.
Safe and responsible use of advanced AI
The AI Act requires the most advanced AI models to be evaluated and their risks assessed before they are placed on the EU market. The Commission will therefore help establish an EU evaluation capacity that strengthens independent third-party assessment of what these models can do, supporting the regulatory work of the AI Office. Together with ENISA, the Commission will also develop a European blueprint for structured access to advanced AI capabilities for cybersecurity purposes. In addition, ENISA and the Commission’s Joint Research Centre will build a secure platform where organisations in critical sectors such as energy, transport, health, finance and public administration can test AI solutions in simulated environments before deploying them.
Reinforced cybersecurity and resilience
The second objective is about implementation rather than innovation. Organisations covered by NIS2, the Cyber Resilience Act and DORA are expected to intensify cyber hygiene, risk management and security by design, and to start using available AI capabilities to find and fix vulnerabilities faster. ENISA will support the transition with guidance, recommendations and best practices, and the Commission will run a campaign to secure critical open source software, which underpins much of Europe’s digital infrastructure.
Scaling up Europe’s AI capabilities
Finally, the Commission will launch an EU Grand Challenge on AI for cybersecurity that brings together companies, researchers and other stakeholders to develop European AI-powered security solutions. The plan also points to the AI Factories and future Gigafactories infrastructure and the European tech equity capacity announced in the Tech Sovereignty Package as vehicles for investment in sovereign AI capabilities.
What still applies for your business?
Every obligation that applied on 6 July still applies today. NIS2 has been implemented in Sweden through the Cybersecurity Act (2025:1506), in force since 15 January 2026, which requires covered organisations to register with their supervisory authority, take risk-based security measures, train their management and report significant incidents. The Cyber Resilience Act takes effect in stages, with manufacturers’ duty to report actively exploited vulnerabilities applying from 11 September 2026. The AI Act follows its own timeline, and national market surveillance of AI systems begins on 2 August 2026. The action plan changes none of these dates. What it changes is the context: authorities now say openly that they expect AI-driven threats to be part of every serious risk analysis.
A practical example: a regional energy company
Consider a mid-sized Swedish energy company that operates distribution networks and uses an AI-based system to monitor load and detect anomalies. As an essential entity under NIS2 and the Cybersecurity Act, it already does risk analyses and incident reporting. The action plan affects it in three practical ways. Its risk analysis should now address AI-enabled attacks, such as automated vulnerability scanning and highly targeted phishing against operations staff. Its procurement should ask AI vendors how their models have been evaluated and how the products meet the Cyber Resilience Act’s security requirements. And its security team can expect concrete support, including ENISA guidance and, in time, a secure European platform for testing AI tools before connecting them to critical systems.
Common mistakes companies make
The most common mistake is treating the plan as non-binding and therefore irrelevant. Action plans do not impose fines, but they shape how supervisory authorities interpret the binding rules that do. Another mistake is assuming AI security is the vendor’s problem, when NIS2 and DORA place responsibility for supply chain risks squarely on the organisation that uses the technology. Many companies also run AI governance and cybersecurity as separate projects with separate owners, although the threats the plan describes sit exactly at the intersection. Finally, some companies wait for new legislation before acting, and overlook the open source components that the Commission itself has singled out as a systemic concern.
Recommended actions
Start by mapping which AI systems your business uses and which systems could become targets of AI-enabled attacks, then update the risk analysis you already do under NIS2 or DORA so that both perspectives are covered. Brief your management, since the Swedish Cybersecurity Act makes management training a legal duty. Review your vendor contracts and ask AI suppliers for documentation on model evaluation and product security. Follow ENISA’s coming guidance and consider whether the testing platform or the EU Grand Challenge could be relevant for your organisation. Document every step, because a documented process is what a supervisory authority will ask to see.
Frequently asked questions
Does the action plan create new obligations for my company?
No. It is a policy instrument that coordinates existing rules such as the AI Act, NIS2 and the Cyber Resilience Act. Your obligations continue to flow from those acts, but the plan signals clearly what supervisory authorities will expect organisations to prioritise.
Which companies should pay closest attention?
Operators in critical sectors covered by NIS2, financial entities under DORA, manufacturers of connected products under the Cyber Resilience Act and companies deploying advanced AI systems. In practice, the plan’s expectations on cyber hygiene and AI-assisted defence reach most businesses.
When will the plan’s measures be in place?
The plan contains no legislative deadlines. The evaluation capacity, the ENISA blueprint and the testing platform will be rolled out gradually. Existing deadlines still apply, including AI Act market surveillance from 2 August 2026 and vulnerability reporting under the Cyber Resilience Act from 11 September 2026.
Conclusion
The EU Action Plan on Cybersecurity and Artificial Intelligence creates no new paperwork, and that is precisely why it is easy to underestimate. It announces how the Commission, ENISA and national authorities will use the rules that already bind your business, and it raises the bar for what a defensible risk analysis looks like in an era of AI-driven attacks. Companies that connect their AI governance with their cybersecurity work now will meet the coming guidance from a position of strength. At Lawgent, we help companies bring AI compliance and cybersecurity together, from risk analyses and vendor reviews to management training and documentation. Get in touch if you want to know what the action plan means for your organisation.