EU policy · AI + cybersecurity

Europe is connecting AI governance and cybersecurity into one operational compliance stack.

The Commission's 2026 Action Plan combines advanced-model evaluation and secure AI testing with existing frameworks including the AI Act, NIS2, the Cyber Resilience Act and DORA.

Published: 29 September 2026 · Commission plan: 7 July 2026.

Direct answer

The Action Plan is policy, not a replacement regulation.

It does not merge these laws. It sets a coordinated direction: evaluate advanced AI, strengthen resilience and help critical sectors test AI securely while implementing existing cybersecurity legislation.

Advanced-model evaluation

The Commission plans to strengthen European capacity to evaluate advanced AI models before EU-market deployment, in line with the AI Act.

Secure testing

The Commission and ENISA plan a secure testing platform for critical sectors including energy, transport, health, finance and public administration.

Existing cyber law

The plan expressly sits alongside the AI Act, Cyber Resilience Act, NIS2, DORA and Cyber Solidarity Act rather than displacing them.

Cross-border governance

U.S. organisations operating in Europe should map obligations by entity, product, sector and regulatory role instead of relying on one generic AI policy.

Operational takeaway

Reuse controls, but preserve each law's legal boundary.

A governance program can reuse evidence across model risk, vulnerability management, incident response, supplier controls and testing while documenting which legal instrument each control supports.