we_are_coded.by CODE · The world, decoded
БГ
European Commission

The EU will evaluate AI models for cybersecurity before they even reach the market

European CommissionControl

The European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence. The plan tasks ENISA with drafting a European blueprint for access to advanced AI capabilities in cybersecurity, and builds capacity to evaluate models before they reach the market.

In short
  • The EC presented a plan for AI in cybersecurity: an ENISA blueprint, pre-market model evaluation, a secure testing platform, a Grand Challenge.
  • It builds on the AI Act, the Cyber Resilience Act, NIS2, DORA, and the Cyber Solidarity Act.
  • Pre-market evaluation is being built together with the Joint Research Centre - for now an institution, not a ready tool.
Checked on8 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Not a new law. An implementation plan. The EU is describing what it will do, not what it's banning - that's a different animal.

The facts: On 7 July 2026, the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence with five actions: a European blueprint (the Commission and ENISA) for structured access to advanced AI capabilities for cybersecurity; building EU capacity to evaluate AI models before they reach the market, supporting the regulatory function of the AI Office (the EU body overseeing enforcement) under the AI Act; a secure testing platform (ENISA together with the Joint Research Centre, the EU's scientific institute); and an EU Grand Challenge for AI in cybersecurity. The plan builds on the AI Act, the Cyber Resilience Act (the EU's product security law), NIS2, DORA, and the Cyber Solidarity Act (the EU's law for collective cyber defense). Primary source: digital-strategy.ec.europa.eu.

Executive Vice-President Henna Virkkunen put it briefly: AI is changing what cybersecurity means, and we have to keep pace.

Under the surface sits a real machine: evaluating a model before market needs a test environment, people, a methodology, and - the hardest part - actually understanding what you're looking at. The EU admits as much indirectly, by building the platform together with the Joint Research Centre. So there's no ready tool yet; there's an institution that's about to build one.

If you're building something on top of someone else's model, you start carrying documentation - where it came from, how it was evaluated, what it does. Today that looks unnecessary. In two years it'll be the first question from every serious client. It's cheaper to keep it from the start.

In practice: if you're building on top of someone else's model, you start carrying documentation - where it came from, how it was evaluated, what it does. Not because someone will audit you tomorrow, but because in two years this will be the first question from every serious client. It's cheaper to keep it from the start.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→European Commission - EU Action Plan on Cybersecurity and AI→European Commission - New EU plan on advanced AI and cybersecurity
Original: https://wearecoded.com/en/articles/eu-action-plan-cybersecurity-ai.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news