From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence
Description
This paper assesses whether the European Union’s 2026 Action Plan on Cybersecurity and Artificial Intelligence converts an extensive regulatory framework into operational capabilities against AI-enabled cyber threats, with a focus on critical infrastructure. Using a source-audited baseline–additionality–maturity framework, it distinguishes inherited mechanisms, redirected capabilities and genuinely Plan-specific measures. The analysis finds that the Union entered July 2026 with substantive horizontal cyber capacity, including cooperation networks, crisis mechanisms and sectoral resilience regimes. The Plan’s distinctive AI-specific components - European third-party model-evaluation capacity, structured access to advanced systems and secure testing for critical sectors - remained largely prospective at the research cut-off. Its immediate value therefore lay in orchestration and implementation design rather than demonstrable new outcomes. The paper further argues that sectoral absorption will be uneven and that strategic dependencies should be assessed through access, auditability, continuity, operational control and substitutability rather than ownership alone.
Research cut-off: 17 July 2026.