Skip to content

EU Action Plan on AI and Cybersecurity: What CISOs Should Take Away from Brussels’ Blueprint

Bottom line: The EU Action Plan on Cybersecurity and AI combines a defence strategy against AI-powered attacks with an access framework for security teams, placing data sovereignty, vendor independence and cost transparency at the centre of procurement criteria.

EU Digital Commissioner Henna Virkkunen presented the EU Action Plan on Cybersecurity and Artificial Intelligence in early July 2026, warning of AI-powered cyberattacks capable of generating functional exploits within minutes or hours. Alongside a coordinated defence strategy, the plan includes a blueprint for structured access by IT security teams to advanced AI models.

At the launch event of the EU Action Plan on Cybersecurity and Artificial Intelligence in early July 2026, Henna Virkkunen, Digital Commissioner of the European Union, warned that advanced AI models are now capable of creating functional cyber exploits within minutes or hours. This development, she said, poses a direct threat to critical infrastructure and society as a whole. The action plan presented pursues two main thrusts: a coordinated response strategy to AI-driven attacks, and a framework for structured access to powerful AI models for IT security teams in government agencies and companies.

Rene van Haaster, Vice President EMEA North at Elastic, put the development into context in connection with the announcement: while AI is a powerful tool for attackers, it is equally a critical lever for defence. Organisations are already using AI to shorten detection, response and recovery times (Mean Time to Detect, Respond, Recover) in order to keep pace with the speed of advanced attacks.

From Elastic’s perspective, the current threat landscape gives rise to three key areas of action for organisations in the EU. First, control and sovereignty: companies must be able to track where their data is generated, moved and stored in order to avoid technological dependencies. In practice, this means avoiding architectures that lock organisations into a single vendor, and instead retaining the freedom to move data between providers and services. Open-source technologies are cited here as an approach to reducing dependency on individual suppliers, since the source code is publicly accessible, modifiable, and continuously reviewed and maintained by a global developer community — in contrast to closed-source products, where continuity of service is not guaranteed, for instance if a vendor changes its terms of business or exits the market.

Second, the economic dimension: according to Elastic, the structural cost and licensing models of many vendors are poorly suited to an environment of rising threats combined with stagnant or shrinking budgets. Cited examples include per-device fees, which can force organisations to leave lower-priority endpoints unprotected, as well as additional costs for automation technologies used to coordinate response workflows. There are also financial risks arising from the use of large language models that fail to adequately document the rationale behind their decisions — a particular concern for audit purposes — along with high costs and delays in retrieving historical data during incident response.

For CISOs in the DACH region, the EU Action Plan provides a regulatory reference point likely to inform future procurement decisions. Those planning IT security architectures should already factor the criteria mentioned — data sovereignty, avoidance of vendor lock-in, and cost transparency for AI-powered security tools — into tenders and contract negotiations with vendors.


Source: www.politico.eu · Published 20 August 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: