EU Unveils Cyber Plan to Reduce Reliance on Foreign AI Systems
The European Commission has published an action plan on cybersecurity and artificial intelligence, committing to nine measures to reduce the EU's reliance on foreign AI systems. The plan, adopted on July 7, focuses on making frontier AI safe, accessible, and deployable for European cybersecurity.
Three Pillars of the Plan
The plan is built around three pillars: making frontier AI safe, accessible, and deployable for European cybersecurity, preparing the EU's cyber ecosystem, and scaling European AI capabilities. Henna Virkkunen, the Commission's executive for technology, stated that the plan would not be accompanied by new legislation, with the focus instead being on enforcing existing rules.
The lack of legislation means the action plan carries no legal force, with the document highlighting the need for member states to adopt and implement existing European laws, particularly NIS2 and the Cyber Resilience Act, as a matter of urgency.
European Blueprint for Structured Access to Advanced AI Capabilities
The plan's most significant measure is the creation of a European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes. The blueprint will be drafted by the Commission and the EU Agency for Cybersecurity (ENISA) by the end of this year.
The blueprint aims to set criteria for granting access to frontier models for EU institutions, member state authorities, critical infrastructure operators, security vendors, and researchers. It will also include contingency measures in case of restricted or withdrawn access.
Concerns over Foreign AI Systems
The plan follows the United States introducing export restrictions on Anthropic's Mythos and Fable models and other restrictions on OpenAI's GPT-5.6, which were imposed and then withdrawn earlier this year. During the restriction, access was barred to foreign nationals, including EU customers.
The Commission notes that access to frontier models is increasingly governed by provider-specific and often non-European decisions, and that gating that access, while potentially justified on safety grounds, often lacks transparency regarding the criteria applied.
EU's Limited Domestic Capability
The Commission concedes that frontier capabilities are mainly developed outside of the EU, and their availability is often determined by non-transparent, foreign-led processes. Without a significant domestic capability, the EU is set to turn to its market size of around 450 million customers and regulation as a way of pursuing its interests.
The EU's plan cites research indicating that the length of cybersecurity tasks advanced models can complete unaided has been doubling over months rather than years. The Commission's AI Office will participate in an evaluation network coordinated by the UK's AI Security Institute (AISI).
Investment Needs
Building frontier capability within the European Union will entail hundreds of billions of euro investment needs, which can only be partly covered by public finances. The plan cites investment pledges of €200 million under the Horizon Europe and Digital Europe programs, and €100 million through the European Innovation Council Fund for strategic defence tech.
In comparison, a single American technology company, Meta, is expected to spend around $125 billion on capital expenditure this year. The plan points to a European equity vehicle floated in June's Tech Sovereignty Package, intended to draw in private capital.
Without compute, models, and data infrastructure, the EU is bound to remain a vulnerable user of frontier AI systems made elsewhere that others can suddenly switch off.
Source: The Record