The European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence. The plan tasks ENISA with drafting a European blueprint for access to advanced AI capabilities in cybersecurity, and builds capacity to evaluate models before they reach the market.
- The EC presented a plan for AI in cybersecurity: an ENISA blueprint, pre-market model evaluation, a secure testing platform, a Grand Challenge.
- It builds on the AI Act, the Cyber Resilience Act, NIS2, DORA, and the Cyber Solidarity Act.
- Pre-market evaluation is being built together with the Joint Research Centre - for now an institution, not a ready tool.
Not a new law. An implementation plan. The EU is describing what it will do, not what it's banning - that's a different animal.
Executive Vice-President Henna Virkkunen put it briefly: AI is changing what cybersecurity means, and we have to keep pace.
Under the surface sits a real machine: evaluating a model before market needs a test environment, people, a methodology, and - the hardest part - actually understanding what you're looking at. The EU admits as much indirectly, by building the platform together with the Joint Research Centre. So there's no ready tool yet; there's an institution that's about to build one.
If you're building something on top of someone else's model, you start carrying documentation - where it came from, how it was evaluated, what it does. Today that looks unnecessary. In two years it'll be the first question from every serious client. It's cheaper to keep it from the start.
In practice: if you're building on top of someone else's model, you start carrying documentation - where it came from, how it was evaluated, what it does. Not because someone will audit you tomorrow, but because in two years this will be the first question from every serious client. It's cheaper to keep it from the start.