In recent years, the debate surrounding artificial intelligence in Europe has focused primarily on regulation. The adoption of the European Artificial Intelligence Act (AI Act) positioned the European Union as one of the first jurisdictions in the world to establish a dedicated legal framework for these technologies. However, Europe’s strategy is no longer limited to regulation alone.

With the presentation of the Action Plan on Cybersecurity and Artificial Intelligence, the European Commission has taken a further step by combining protection against AI-related risks with the development of European technological capabilities, stronger cybersecurity, and the promotion of a competitive European ecosystem.

In other words, Europe wants artificial intelligence to be safe, but it also wants it to become an opportunity to strengthen technological sovereignty, foster innovation and enhance its position in an increasingly competitive global environment.

A new landscape: AI is also transforming cybersecurity

Artificial intelligence is fundamentally changing the way cyberattacks are both carried out and prevented.

The most advanced AI models make it possible to analyse vast amounts of information, identify vulnerabilities more quickly, automate monitoring tasks and improve incident response capabilities.

However, the same technology can also be exploited by malicious actors to automate attacks, identify vulnerabilities and increase both the speed and sophistication of cyber threats.

This dual reality explains why the European Commission considers artificial intelligence to be both a powerful tool for strengthening cybersecurity and a new source of risk that must be properly managed.

From regulating AI to building a European ecosystem

The new Action Plan reflects a significant shift in Europe’s technology policy.

Until now, much of the focus has been placed on the AI Act and other regulations establishing obligations for developers and users of artificial intelligence.

The objective now goes much further.

The Commission aims to promote a European ecosystem capable of developing home-grown technologies, reducing strategic dependencies and encouraging collaboration between public institutions, businesses, research centres and technology providers.

This vision is closely aligned with other recent European Union initiatives designed to strengthen technological sovereignty and digital competitiveness.

How this Action Plan fits into Europe’s digital strategy

Although the Action Plan has its own identity, it has not emerged in isolation.

Its approach complements other regulatory and strategic frameworks that are also reshaping how organisations manage technology and digital risk.

Among them is the AI Act, whose implications for businesses we analysed in detail in our article on the European Artificial Intelligence Act, legislation that introduces different risk categories for AI systems and is expected to have a significant impact across multiple sectors.

Other initiatives include the NIS2 Directive, aimed at strengthening the cybersecurity of essential and important entities; the Digital Operational Resilience Act (DORA), focused on the financial sector’s digital operational resilience; and the Cyber Resilience Act, which seeks to raise cybersecurity standards for digital products and services.

Taken together, these initiatives point in the same direction: integrating security, risk management and technology governance as essential components of corporate strategy.

Four priorities to strengthen AI and cybersecurity

The Action Plan is built around four key priorities.

1. Assessing and safely deploying advanced AI models

One of the Commission’s objectives is to strengthen Europe’s ability to assess the risks associated with the most advanced artificial intelligence models before they are deployed.

To achieve this, the Commission will establish a dedicated European evaluation capability to independently assess both the capabilities and risks of these models, particularly from a cybersecurity perspective.

It will also develop secure testing environments where public and private organisations can experiment with AI solutions designed to protect critical infrastructure without compromising real-world systems.

The aim is to encourage innovation while maintaining high security standards and increasing confidence in the adoption of artificial intelligence.

2. Preparing businesses and critical sectors for the new reality

The Commission believes that artificial intelligence should progressively become part of organisations’ risk management strategies.

Sectors such as energy, transport, healthcare, financial services and public administration will increasingly need to integrate AI tools to improve vulnerability detection, strengthen incident response and enhance prevention capabilities.

At the same time, the Commission will promote recommendations, technical guidance and best practices to support the safe implementation of these technologies.

For many organisations, this will require assessing not only which AI tools are being used, but also how they are integrated into internal processes, the risks they generate and the governance mechanisms in place to ensure their responsible use.

3. Strengthening Europe’s own technological capabilities

Another pillar of the Action Plan is the promotion of European artificial intelligence solutions specifically designed for cybersecurity.

The Commission plans to launch new funding initiatives, research programmes and projects aimed at strengthening the European technology ecosystem, supporting the growth of innovative companies and expanding Europe’s own technological capabilities.

The objective is to reduce dependence on technologies developed outside Europe while building a European AI infrastructure capable of competing globally.

Beyond its economic dimension, this initiative is also closely linked to strategic resilience, technological sovereignty and digital security.

4. Strengthening international cooperation

Cybersecurity knows no borders.

For this reason, the Action Plan also seeks to strengthen cooperation with other countries and international organisations to share knowledge, coordinate responses to cyber threats and promote common standards for artificial intelligence and digital security.

International cooperation will be particularly important in areas such as early threat detection, information sharing and the development of best practices for increasingly complex risk scenarios.

 

I would like more information

 

What does all this mean for businesses?

Although many of the measures announced are strategic and institutional in nature, the message for organisations is clear.

Artificial intelligence will no longer be viewed solely as a productivity tool. It will also become a key component of risk management, business continuity and cybersecurity strategies.

It will become increasingly important to understand which AI solutions an organisation uses, how they are integrated into internal processes, the risks they create and the control measures in place to ensure their safe and compliant use.

It will also be essential to establish governance mechanisms that enable organisations to oversee the use of these technologies, define internal responsibilities and monitor their potential impact on information security, privacy and regulatory compliance.

In many organisations, this process will run alongside other compliance, control and corporate reporting initiatives. In this regard, integrating corporate governance and risk management principles has already become an integral part of numerous projects related to sustainability, transparency and compliance, including those associated with Non-Financial Information Statement (NFIS) assurance and other corporate oversight frameworks.

How businesses can prepare

Although many of the measures included in the Action Plan will be implemented over the coming years, organisations can already take several steps to strengthen their preparedness.

First, companies should identify which artificial intelligence tools are currently being used across the organisation and for what specific purposes.

It is also advisable to assess the risks associated with these systems and determine whether sufficient controls are in place to ensure their secure use and compliance with the applicable regulatory framework.

Employee training will be another key factor. The responsible adoption of AI depends not only on the technology itself, but also on the knowledge, skills and procedures that support its use.

Finally, organisations should closely monitor the evolution of European legislation. The AI Act marks an important starting point, but the new Action Plan demonstrates that both the regulatory and strategic landscape will continue to evolve over the coming years. Understanding the obligations introduced by the European Artificial Intelligence Act (AI Act) can help organisations anticipate risks and prepare for compliance with greater confidence.

Key considerations

The rapid expansion of artificial intelligence is creating significant opportunities, but it is also giving rise to challenges that organisations do not always identify immediately.

One of these is the so-called shadow AI, namely the use of artificial intelligence tools by employees or collaborators without the organisation’s formal knowledge or oversight.

Additional risks may arise in relation to the protection of confidential information, excessive reliance on specific technology providers or the absence of adequate human oversight mechanisms.

The objective is not to slow innovation, but to ensure that AI is adopted in a controlled manner that is aligned with business objectives.

A strategy that goes beyond regulation

The Action Plan demonstrates that Europe’s artificial intelligence strategy is entering a new phase.

The discussion is no longer focused solely on how to regulate AI, but also on how to develop European capabilities, foster innovation, protect critical infrastructure and strengthen Europe’s technological competitiveness.

In this context, the AI Act, the Cyber Resilience Act, the NIS2 Directive, the Digital Operational Resilience Act (DORA) and the new initiatives announced by the European Commission form part of an increasingly integrated strategy.

For businesses, this means adopting a more holistic approach to technology, in which artificial intelligence, cybersecurity, governance and regulatory compliance are no longer managed as separate disciplines.

Is your business ready to integrate AI securely?

Artificial intelligence has already become part of the business strategy of many organisations. Ensuring its responsible use, managing the associated risks and adapting to the new European regulatory framework will be essential to unlocking its full potential.

At Adlanter, we help businesses integrate artificial intelligence from a legal, technological and compliance perspective, supporting them in implementing governance models aligned with the new European regulatory landscape and the evolving requirements established by the European institutions.

 

Nuestros expertos

  • Adlanter

    Expertos en asesoría fiscal, laboral, mercantil, contable, movilidad internacional y gestión del talento. Compartimos análisis, novedades normativas y contenido especializado para ayudar a empresas y profesionales a tomar decisiones informadas y afrontar con seguridad los retos de un entorno empresarial en constante evolución.

Conversation

Do you have any questions?

If you have any questions after reading "Europe accelerates its artificial intelligence strategy: key takeaways from the new AI and Cybersecurity Action Plan", we are here to help you.

Let's talk. We guide you clearly and step by step.