
EU Launches Cybersecurity-AI Action Plan as August Deadlines Close In
Brussels has unveiled a coordinated plan to address the cyber risks of advanced AI models, including expanded EU evaluation capacity, weeks before the AI Act's transparency rules and sandbox deadlines bite.
The European Commission has published a July action plan on cybersecurity and AI, setting out a coordinated approach to help member states, businesses and public authorities manage the security risks posed by the most advanced AI models — and signaling that Brussels wants its own capacity to scrutinize them.
What's in the plan
The headline commitment: the Commission will launch a call to increase EU evaluation capacity for AI models before they are placed on the European market — a move toward the kind of pre-deployment testing infrastructure that bodies like METR and the national AI safety institutes provide today, but under EU auspices. The plan also addresses resilience challenges for critical infrastructure as agentic AI systems spread.
A crowded compliance calendar
The action plan lands amid a dense run of AI Act milestones:
- 2 August 2026 — transparency rules for AI systems take effect, and every member state must have at least one AI regulatory sandbox operating.
- July 2026 — formal adoption of the Digital Omnibus simplification package is expected in the Official Journal, following the Council's final green light on June 29. The package defers high-risk compliance obligations to December 2027.
The takeaway
The omnibus deferral bought companies time on the AI Act's hardest requirements, but the cybersecurity plan shows the Commission is not standing still: model evaluation, not just documentation, is becoming the EU's chosen lever. For Asian and American exporters, an EU-run evaluation gate — however embryonic — is the detail worth watching.
Newsletter
Get Lanceum in your inbox
Weekly insights on AI and technology in Asia.


