EU eases AI act in cybersecurity push

Drip

The gist

The EU is turbocharging its AI cybersecurity strategy—led by ENISA and a pan-European testing platform—while easing AI Act red tape and tightening cyber demands on banks.

What to know

  • ENISA will launch an EU-wide AI model testing platform by 2027 to standardize and strengthen AI defenses in critical infrastructure.
  • The EU is dialing back some AI Act compliance requirements, targeting a €3.3 billion annual burden, and expanding the AI Office’s oversight of large online platforms.
  • By October 2026, major banks must submit AI cyber defense plans to the ECB, tackling AI-powered threats, supply chain risks, and Zero Trust for non-human identities.

ENISA’s AI Security Blueprint

ENISA’s forthcoming EU-wide AI model testing platform marks a strategic pivot to standardized, cross-sector AI resilience, embedding cybersecurity at the core of critical infrastructure and enforcement under the AI Act.

The EU has entrusted ENISA with leading a comprehensive AI cybersecurity strategy that centers on launching a secure, EU-wide AI model testing platform by 2027. This platform aims to standardize and enhance the evaluation and resilience of AI systems deployed across critical infrastructure sectors, ensuring robust defenses against AI-related cyber threats while building evaluation capacity to support enforcement under the AI Act.

This initiative is a cornerstone of the broader EU Action Plan on AI Cybersecurity, which strategically emphasizes three complementary objectives: promoting the safe and responsible use of advanced AI, reinforcing cybersecurity resilience, and scaling up Europe’s AI capabilities through innovation and market development. Rather than introducing new binding regulations, the plan integrates with existing frameworks to balance mitigating AI-powered cyber threats with fostering defensive AI innovation, positioning AI as a dual-use technology critical to the EU’s cybersecurity posture.

Sources

AI Compliance Costs Recalibrated

The EU is slashing red tape and consolidating oversight for AI on major platforms, responding to industry outcry over billion-euro compliance burdens while layering in new pre-market security demands for advanced AI software.

The EU's Digital Omnibus on AI addresses significant compliance challenges by simplifying and delaying parts of the AI Act, particularly due to delays in harmonised technical standards and national authority setups across member states. This move responds directly to industry concerns about the heavy administrative burden and high costs, with associations like DIGITALEUROPE highlighting that compliance could cost companies up to EUR 3.3 billion annually, and smaller AI firms facing initial expenses between EUR 320,000 and EUR 600,000. By easing these requirements, the EU aims to balance regulatory rigor with fostering innovation and competitiveness within the AI sector.

Expanding its oversight, the newly empowered EU AI Office now assumes reorganized supervisory responsibilities over AI systems operating on very large online platforms regulated under the Digital Services Act. This consolidation reflects a strategic effort to streamline governance and enhance regulatory clarity for complex AI deployments within major digital ecosystems, ensuring that oversight keeps pace with the evolving digital landscape and the scale of AI integration in online services.

The EU's Action Plan on Cybersecurity and AI introduces a paradigm shift by mandating pre-market security evaluations and third-party risk assessments for advanced AI software, moving beyond the AI Act’s traditional consumer product labelling towards active security risk inspection. This layered regulatory approach integrates AI-specific mandates into existing frameworks like the Cyber Resilience Act and ENISA certification, compelling software vendors to navigate a complex compliance landscape that demands extensive documentation, product modifications, and engagement with accredited conformity assessment bodies—challenges that significantly increase costs and time-to-market.

Post-Brexit realities add another layer of complexity for UK software vendors, as EU certification no longer automatically recognizes UK conformity assessment bodies, forcing these companies to seek EU-based accreditation or rely on mutual recognition agreements. Meanwhile, regulatory scrutiny remains sharply focused on high-risk AI systems deployed in critical sectors such as infrastructure, employment, education, and law enforcement, as well as general-purpose AI models surpassing capability thresholds, while consumer-facing AI products face comparatively lighter direct regulatory impact unless they cross defined risk boundaries.

Sources

Banks Face AI Risk Mandate

Europe’s finance leaders are shifting from innovation to resilience, forcing banks to address AI-driven cyber threats, supply chain risks, and operational opacity through ECB-mandated action plans and joint supervisory oversight.

The Eurogroup finance ministers have elevated AI cyber risks to a central position on the financial policy agenda, signaling a strategic shift from prioritizing innovation to emphasizing resilience and supervisory risk management. This change reflects growing concerns about vulnerabilities unique to AI systems, such as manipulation, operational opacity, and systemic risks stemming from reliance on a narrow set of AI vendors. Moreover, Europe's increasing dependence on non-European AI infrastructure in the financial sector raises sovereignty and auditability issues, prompting calls for enhanced control and oversight to safeguard critical banking operations.

In response to these emerging threats, the European Central Bank has mandated significant financial institutions to submit comprehensive action plans by 31 October 2026, focusing on defending against AI-driven cyberattacks. The ECB’s directive outlines six critical areas for immediate attention, including AI-powered attack surface management, vulnerability operations, automated security operations center alerts, AI supply chain oversight, Zero Trust architectures for non-human identities, and resilience testing against advanced AI scenarios. This targeted approach underscores the necessity of integrating AI both as a tool for defense and as a risk factor requiring rigorous governance.

Effective regulation of AI cyber risks in finance demands a multidisciplinary supervisory framework, necessitating close coordination among finance ministries, central banks, financial supervisors, cybersecurity agencies, and data protection authorities. The ECB reinforces this collaborative approach through its Joint Supervisory Teams, which align oversight efforts with key regulatory instruments such as the Digital Operational Resilience Act (DORA), the Network and Information Security Directive (NIS2), and the EU AI Act. This integrated supervisory model aims to build technical expertise and harmonize responses to the complex challenges posed by AI in the financial ecosystem.

Sources

Digital Sovereignty Through AI Infrastructure

The EU’s whole-continent strategy ties regulatory, innovation, and procurement levers to build homegrown AI security and democratize compute access, aiming to make inference infrastructure as vital—and accessible—as the power grid.

The EU is advancing a comprehensive, whole-of-continent strategy to secure AI infrastructure and capabilities, recognizing that talent, financing, and equitable access to compute resources are foundational to digital sovereignty. As MEPs emphasize, this approach integrates regulatory frameworks, innovation policies, public procurement, and diplomatic efforts to build a resilient AI ecosystem that supports secure deployment across member states. Virkkunen’s call to develop Europe’s own AI-powered cybersecurity capabilities underscores the urgency of these efforts to reduce dependency on external actors and fortify the bloc’s strategic autonomy.

Central to Europe’s institutional initiatives is the planned launch of an EU-wide AI model evaluation platform by 2027, designed to enhance the continent’s capacity for rigorous testing and secure deployment of advanced AI systems. This platform aligns with the broader Action Plan on AI Cybersecurity, which prioritizes evaluation, innovation, and resilience to protect critical infrastructure sectors, thereby ensuring that Europe can confidently manage AI risks within its borders while fostering homegrown expertise.

Europe’s vision for equitable AI compute infrastructure focuses on inference capabilities rather than the more resource-intensive training phase, conceptualizing this infrastructure as essential as an electricity grid. By ensuring broad, affordable access to inference compute, the EU aims to democratize AI deployment and prevent digital divides, reflecting a pragmatic approach that balances industrial-scale safety with inclusive technological advancement.

Institutionally, Europe is leveraging lessons from established AI safety bodies like the UK’s AI Security Institute, encouraging emerging entities such as the German AI Security Institute to adopt proven frameworks rather than reinventing the wheel. This strategy promotes cohesion and efficiency in AI safety governance across Europe, reinforcing the continent’s commitment to robust, collaborative security standards that complement legislative efforts like the AI Act’s general-purpose security provisions.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.