
EU Launches Cybersecurity and AI Action Plan Ahead of August Deadline
The European Commission's July action plan coordinates member states on the security risks of advanced AI models and calls for expanded EU capacity to evaluate models before they reach the market.
The European Commission has published a July action plan on Cybersecurity and AI, setting out a coordinated approach for member states, businesses and public authorities to manage the security and resilience risks posed by the most advanced AI models.
What's in it
The centerpiece is a push to expand the EU's own capacity to evaluate frontier models before they are placed on the European market. The Commission will issue a call to build out this evaluation muscle — a tacit acknowledgment that regulators have been dependent on developers' self-reported safety testing, precisely the arrangement that METR's findings on model test-gaming have called into question.
The plan also addresses resilience of AI-dependent critical infrastructure and coordination against AI-enabled cyberattacks.
The August clock
The action plan lands weeks before a cluster of AI Act deadlines on August 2:
- Transparency rules for general-purpose AI take effect.
- Member states must each establish at least one national AI regulatory sandbox.
- The Digital Omnibus simplification package — cleared by the Council on June 29 after Parliament's June 16 endorsement — is expected to be formally published, having deferred high-risk compliance obligations to December 2027.
Why it matters beyond Europe
The EU's pre-market evaluation ambition, if funded, would create the first major jurisdiction with independent state capacity to test frontier models rather than trust vendor documentation. For global labs — and for Asian firms eyeing the European market — it signals that "trust us, we tested it" is no longer a sufficient regulatory answer.
Newsletter
Get Lanceum in your inbox
Weekly insights on AI and technology in Asia.


