EU Action Plan on Cybersecurity and AI: an EU frontier-model evaluation capacity by 2027 and a blueprint for 'structured access' to models like Mythos
On July 7, 2026 the European Commission adopted an Action Plan on Cybersecurity and Artificial Intelligence. It plans a dedicated EU evaluation capacity for advanced models' cyber capabilities (operational in 2027), a secure AI testing platform for critical sectors by end-2026, and, with ENISA, a "European blueprint for structured access" to frontier models. Its trigger was that access to models such as Anthropic's Mythos and Fable is decided by non-European providers.
Key facts
- Adopted July 7, 2026; presented by Executive Vice-President Henna Virkkunen
- EU evaluation capacity for cybersecurity assessment of advanced AI models, supporting the AI Office's pre-market evaluation duties; operational in 2027
- Secure testing platform for critical sectors (energy, transport, health, finance, public administration) by end-2026; an 'EU Grand Challenge' competition for cyber-AI solutions
- Commission + ENISA to draft a European blueprint for structured access to frontier models by end-2026; joint procurement of access and contingency measures if access is restricted or withdrawn (The Record)
- Funding cited by The Record: €200M via Horizon Europe/Digital Europe and €100M via the EIC Fund
- The Record: the plan names Anthropic's Mythos and Fable and OpenAI's GPT-5.6, and says access is governed by 'provider-specific and often non-European decisions'
- Leans on existing law (AI Act, Cyber Resilience Act applicable end-2027, NIS2, DORA, Cyber Solidarity Act) rather than new rules; EU joins the UK-coordinated evaluation network
What happened
After Anthropic limited Mythos to selected partners, European governments worried about being locked out of frontier cyber-defence models. The Commission's July 2026 action plan responds with EU testing capacity, joint procurement of model access and contingency plans, and a blueprint for structured access to be drafted with ENISA by the end of 2026.
Why it matters
It is the EU's main policy answer to restricted-release frontier cyber models. It also prepared the ground for von der Leyen's Sept 16 invitation to frontier labs to talks on "pacing".
Changelog
- 2026-10-05: created (backfill found while searching EU news; funding figures and model names from The Record, not checked against the plan PDF)
People
Henna Virkkunen Ursula von der Leyen
Related events
- Anthropic reveals Claude Mythos Preview, withholds it over cyber risk and launches Project Glasswing ★★★★★
- UK FCA review: frontier AI finds vulnerabilities faster than financial firms can fix them ★★
Sources (5)
- officialEuropean Commission: Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence
- officialEuropean Commission: EU Action Plan on Cybersecurity and Artificial Intelligence (document)
- pressThe Record: EU unveils cyber plan to reduce reliance on foreign AI systems
- presstechUK: EU Commission publishes Action Plan on Cybersecurity and Artificial Intelligence
- pressAIwire: European Commission presents EU Action Plan on Cybersecurity and AI (Jul 9, 2026)
id: 2026-07-07-eu-action-plan-cybersecurity-ai · updated 2026-10-05 · open in the interactive timeline