For a long time, the European strategy on artificial intelligence (AI) boiled down to a single ambition: regulation. With the AI Act, the EU has established itself as the first major economic bloc to set binding rules for the most powerful AI models. The action plan, presented on 7 July by the European Commission, marks a shift in approach. The focus is no longer solely on regulating a technology deemed potentially dangerous. It is now also about harnessing it to strengthen Europe’s security.
This shift is taking place against a backdrop where the most advanced AI models are already revolutionising cybersecurity practices. They make it possible to automate the search for vulnerabilities and to launch attacks more quickly and on a larger scale, but they also offer unprecedented capabilities for detecting breaches and protecting networks. For Brussels, it is no longer simply a matter of containing these developments, but of ensuring that Europe is not left at their mercy.
AI-powered cybersecurity
The plan, spearheaded by Henna Virkkunen, executive vice-president of the European Commission responsible for technological sovereignty, security and democracy, is thus based on a simple idea: to build an autonomous European capacity in the field of AI-powered cybersecurity. The Commission plans to set up a European body to assess AI models, due to become operational in 2027, tasked with analysing their performance and risks. It will work in support of the AI Office to strengthen European expertise in the face of technologies that are currently largely developed outside the continent.
This focus on autonomy is also reflected in the aim to organise European access to the most advanced AI models. In cooperation with the European Union Agency for Cybersecurity (Enisa), Brussels will develop a framework enabling public authorities, research centres and strategic businesses to use these tools under secure conditions. The aim is to prevent access to the most advanced technologies from becoming a further factor contributing to dependence on major foreign suppliers.
The Commission also wants to speed up the practical adoption of these technologies. A European platform will enable the use of AI to be tested in simulated environments for critical sectors, whilst organisations are encouraged to start using AI tools – including open-source ones – today to detect vulnerabilities more quickly and strengthen their resilience. Enisa will be responsible for issuing recommendations, promoting best practice and supporting the communities developing the most critical open-source software.
Turning regulation into a strategic advantage
The industrial component of the plan also confirms this strategic shift. A European competition dedicated to AI for cybersecurity is set to stimulate innovation, whilst AI Factories, the future Gigafactories and the future European technology funding instrument are intended to help foster the emergence of European players capable of competing with their American and Chinese rivals. Cybersecurity is thus becoming a key driver of European industrial policy.
Ultimately, this plan reflects a broader shift in European doctrine. After several years spent establishing legal safeguards, Brussels is now seeking to turn regulation into a strategic advantage. The EU no longer wishes merely to be the power that sets the rules for AI. It intends to become a player capable of developing, mastering and deploying these technologies in the most sensitive areas of its security. In a geopolitical environment characterised by global technological competition, cybersecurity now appears to be one of the main areas in which this new European ambition is being expressed.



