
The European Commission has presented a new Action Plan focused on the relationship between cybersecurity and artificial intelligence, aimed at strengthening the European Union’s ability to address increasingly sophisticated and rapidly evolving cyber threats.
Artificial intelligence can help identify vulnerabilities, detect anomalous behavior, and prevent cyberattacks. However, these same capabilities can be exploited by malicious actors to automate operations, identify system weaknesses more quickly, and increase the scale and impact of cyber incidents.
The Plan therefore aims to address both sides of the equation: using AI as a defensive tool while reducing the risks associated with the use of increasingly advanced models. The strategy is built around three main areas: secure use of AI, faster vulnerability management, and the development of European technologies and expertise.
Safely assessing and using advanced AI models
The first area of focus concerns the most advanced artificial intelligence models, which are increasingly capable of having a significant impact on cybersecurity activities as well.
The European Commission intends to strengthen Europe’s ability to assess the characteristics, performance, and potential risks of these models before they are introduced to the market. By 2027, a dedicated assessment capability is expected to become operational, supporting the AI Office and the obligations established under the AI Act.
The Plan also calls for the development of a European Blueprint, a coordinated framework designed to give European organizations secure access to the most advanced AI models and computing capabilities for cybersecurity purposes.
This will be complemented by the development of secure platforms and cyber ranges: controlled simulation environments where AI-based applications can be tested, system responses to potential attacks can be assessed, and vulnerabilities identified without directly exposing operational networks, data, or infrastructure.
Managing vulnerabilities at AI speed
The second area addresses one of the most tangible impacts of artificial intelligence on cybersecurity: the shorter time required to discover and exploit a vulnerability.
When vulnerability discovery is automated, traditional approaches to system management and updates may prove too slow. The time between identifying a vulnerability, developing a fix, and actually deploying the patch therefore needs to be significantly reduced.
The European Commission aims to modernize vulnerability tracking and remediation tools, fostering closer collaboration among institutions, developers, technology providers, and businesses.
Particular attention will be given to open-source components, which are widely used in the software and applications adopted by businesses. A vulnerability in a shared component can propagate across multiple products and systems, creating risks throughout the digital supply chain.
To address this challenge, the Plan includes a Critical Open Source Resilience Campaign, coordinated with ENISA, along with operational guidance for the secure integration of AI into activities for preventing, detecting, and responding to cyberattacks.
Strengthening European technologies, infrastructure, and expertise
Strengthening European technologies, infrastructure, and expertise
The third area focuses on expanding Europe’s cybersecurity capabilities, reducing reliance on infrastructure and solutions developed outside the European Union.
The initiatives include an EU Grand Challenge focused on developing AI-powered tools capable of automatically identifying and remediating vulnerabilities. The goal is to foster collaboration among businesses, startups, research centers, and technology providers.
An important role will also be played by AI Factories, European infrastructures that provide advanced computing capabilities to develop, train, and test new models. Applied to cybersecurity, these resources can help create more sophisticated defense tools while strengthening control over the data and technologies being used.
The technology component will be complemented by new training programs under the Cybersecurity Skills Academy. The availability of advanced tools, in fact, must be supported by the right expertise to interpret, manage, and properly integrate them into business processes.
A framework connected to the AI Act, NIS2, and the Cyber Resilience Act
The Action Plan does not introduce a new standalone regulatory framework, but instead strengthens and coordinates the existing European framework.
The AI Act regulates the development and use of artificial intelligence systems through a risk-based approach. The NIS2 Directive addresses cybersecurity risk management, governance, and the ability to prevent and manage incidents in critical sectors. The Cyber Resilience Act, meanwhile, introduces security requirements for hardware and software products throughout their entire lifecycle.
The Plan connects these frameworks through a broader operational strategy: the goal is to ensure that security, innovation, and technological capabilities evolve together, preventing the rapid adoption of artificial intelligence from creating new points of exposure.
Implications for industrial companies
For businesses, the Plan confirms that AI adoption cannot be considered separately from the management of the systems, data, and processes into which it is integrated.
The issue is particularly relevant in manufacturing, where business applications, cloud platforms, machinery, planning systems, and analytics tools are increasingly interconnected. A vulnerability can therefore have consequences that go beyond data availability, potentially affecting production continuity, supply chain coordination, and the ability to meet delivery times and service levels.
The introduction of new solutions therefore requires a clear understanding of dependencies between systems and processes, proper management of access and data, and careful assessment of the technologies and vendors involved.
The European Action Plan sets a clear direction: artificial intelligence can strengthen the ability to prevent and respond to threats, but it must be integrated into reliable architectures and organizational models capable of ensuring proper oversight and control.