I have been saying for years that AI and cybersecurity are racing ahead of the rules, and most organisations are still catching their breath. The European Commission just made that gap a legal problem.
On 7 July 2026, the Commission published its Action Plan on Cybersecurity and Artificial Intelligence. This is not a warm policy paper. It is a structured playbook that builds on the AI Act, the Cyber Resilience Act, NIS2, and DORA. The plan sets out nine actions across three objectives: promote safe and responsible advanced AI, reinforce EU cybersecurity and resilience, and scale up Europe’s sovereign AI capabilities for cyber defence.
What Changes on 2 August
The implementation phase begins in less than four weeks. From 2 August 2026, the Commission can enforce new obligations against providers of general-purpose AI models with systemic risk, including the risk of cyber misuse. Fines climb to 3% of worldwide annual turnover or 15 million euros, whichever is higher. That is a serious penalty for any company that has not documented its AI security posture.
The plan also introduces a European Blueprint for structured access to advanced AI capabilities for cybersecurity. ENISA and the Joint Research Centre will build a secure testing platform. Member States are expected to align their vulnerability management and critical infrastructure protections with the new standard.
Why This Matters Right Now
This is not just about European borders. If you sell software, process data, or run cloud infrastructure accessed from Europe, the compliance perimeter follows the customer. The plan explicitly references open-source AI models and the need to secure critical open-source software. That means the LibreOffice plugin you wrote, the FastAPI microservice you deployed, and the LLM you fine-tuned on customer data are all in scope.
The timing is deliberate. Frontier models can now discover and chain vulnerabilities at machine speed. The industry has documented AI-powered ransomware, autonomous zero-day hunting, and large-scale phishing campaigns generated in hours. Regulation is finally moving to match the capability curve.
The Practical Checklist
Do not wait for the fine. Start now:
- Inventory every AI model and agent with access to production systems or sensitive data
- Document your AI risk assessments, incident response plans, and model deployment approvals
- Review third-party AI vendors for security attestations and incident reporting commitments
- Test your security stack against prompt injection, agentic abuse, and data exfiltration paths
- Assign a clear owner for AI governance who sits outside the engineering team
These steps sound basic, but most organisations still treat AI as a research curiosity rather than a production attack surface. The EU plan makes that distinction expensive.
The Bottom Line
The European Commission is not trying to ban AI. It is trying to make sure that when a model escapes its sandbox, there is a legal and operational framework for responding. That is a reasonable demand. The hard part is execution, and execution starts on 2 August.
The EU plan shifts AI security from voluntary guidance to enforceable liability. Companies that have treated AI governance as a slide deck will face a hard wake-up call when fines reach 3% of global turnover.
Philip Hall
