From the journal

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.

2 min read

The European Commission adopted the Action Plan on Cybersecurity and Artificial Intelligence on 7 July 2026. The Action Plan is a non-legislative initiative setting Commission and ENISA policy priorities; it does not create new directly binding obligations but directs the Commission to act under existing mandates in the AI Act and EU cybersecurity legislation.

The Action Plan operates under Regulation (EU) 2024/1689 (AI Act), Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), the Cyber Resilience Act, and the Cyber Solidarity Act. The Commission will strengthen capacity to evaluate AI models prior to EU market placement under Article 43 of the AI Act and will work with the European Union Agency for Cybersecurity (ENISA) to develop a European Blueprint for secure access to advanced AI systems for cybersecurity purposes.

AI model providers, critical infrastructure operators in energy, finance, and health, and AI deployers in high-risk sectors face increased scrutiny of pre-market conformity assessments under the AI Act. ENISA will operate a secure testing platform to help organisations in those sectors safely test and deploy AI solutions. The Commission will also launch an EU Grand Challenge on AI for cybersecurity to fund joint research and development across industry and research institutions.

The Action Plan does not introduce delegated acts or implementing measures; those will follow through ENISA rulemaking and subsequent Commission decisions under the AI Act. Funding timelines and eligibility criteria for the EU Grand Challenge have not been published. ENISA coordination will determine how the Action Plan intersects with national cybersecurity strategies under Article 7 of NIS2.

Licentium advises AI developers, critical infrastructure operators, and regulated financial institutions on EU AI Act compliance, NIS2 cybersecurity obligations, and DORA operational resilience requirements. If you are assessing how the Action Plan affects your AI systems or cybersecurity programme, our team and partner network can assist. Work we undertake includes AI Act conformity assessments, cybersecurity regulatory gap analysis, NIS2 incident-response frameworks, and DORA third-party risk advisory.

Source: European Commission, Press Release IP/26/1544, Action Plan on Cybersecurity and Artificial Intelligence, 7 July 2026

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.