Artificial intelligence is rapidly transforming the cybersecurity landscape. The same systems that can detect vulnerabilities in seconds, predict cyberattacks, and strengthen the defenses of critical infrastructure, can simultaneously be used by malicious actors to automate attacks, create sophisticated malware, and exploit vulnerabilities at an unprecedented speed. In this new environment, the European Commission recently presented its new Action Plan on Cybersecurity and Artificial Intelligence, aiming to prepare Europe for a reality where security and innovation must coexist.
This initiative is more than just another policy strategy. It reflects a deeper shift in how we perceive security in the digital age. Until recently, cybersecurity relied primarily on reacting to known threats. Today, however, advanced artificial intelligence models can discover new vulnerabilities, adapt their attacks in real time, and operate with levels of autonomy that, just a few years ago, were considered the stuff of science fiction. Defense can no longer be static; it must constantly evolve.
The new European plan is based on three interlinked pillars. First, it promotes the safe and responsible use of advanced artificial intelligence systems. Second, it strengthens the European Union’s overall cyber resilience through closer cooperation among member states, businesses, and competent authorities. Third, it invests in the development of European artificial intelligence capabilities specifically for cybersecurity purposes, aiming to reduce Europe’s dependence on technologies developed outside European borders.
Of particular importance is the plan to establish a European capability for evaluating advanced artificial intelligence models, as well as the development of secure testing environments for organizations in critical sectors, such as energy, transportation, health, financial services, and public administration. At the same time, the European Commission, in collaboration with ENISA, is promoting the creation of a common European framework that will facilitate secure access to advanced artificial intelligence capabilities for cybersecurity purposes.
However, the most important message of the Action Plan is not exclusively about technology. It is about governance. The European Union recognizes that the real challenge is not simply to create more powerful algorithms, but to create stronger institutions. Trust will not be built by artificial intelligence itself, but by the rules, accountability, transparency, and effective oversight that will govern its use.
This approach is directly linked to the philosophy of the AI Act, which introduces a risk-based regulatory model and shifts the focus from the technology itself to the management of its consequences. The new cybersecurity strategy complements this framework, aiming to ensure that Europe does not merely keep pace with technological developments but actively shapes the rules of the digital future.
In the age of artificial intelligence, power will not be measured solely by computing power or the speed of algorithms. It will be measured by a society’s ability to combine innovation with security, technology with democracy, and progress with trust. This is, perhaps, the most important message of the new European strategy. It seeks not merely to protect our digital systems, but to safeguard the very foundation upon which the digital Europe of the coming decades will be built.
