Brussels Bets on AI Rulebook Amid Cyber Risks
EU's Action Plan addresses AI cyber threats but lacks autonomy.
Model Diplomat7 min readEurope

Brussels Bets on AI Rulebook as Chinese Hackers Weaponize Frontier Models
The EU's July 7 Action Plan on Cybersecurity and AI answers state-linked AI cyberattacks with governance — but the leverage sits in Washington's export controls and US frontier labs, not in Brussels.
The European Commission on July 7, 2026 unveiled its Action Plan on Cybersecurity and Artificial Intelligence, a governance response to a hardware and model-supply problem the plan does not solve: eight months after Anthropic disclosed that a China-linked group had used its Claude Code model to run a largely autonomous espionage campaign against roughly 30 targets, Brussels is doubling down on the AI Act, ENISA and a new "European Blueprint" for secure access to frontier AI — while the frontier models themselves, and the chips that train them, remain overwhelmingly American. The plan matters, but it is a regulatory scaffold on a supply chain the EU does not yet own.
Executive Vice-President Henna Virkkunen presented the plan the same day MEPs quizzed the Commission in Strasbourg on its "EU strategy on cybersecurity and AI," according to the European Parliament. The Commission frames it around three objectives: promote the safe use of advanced AI, reinforce EU cybersecurity, and scale up European AI capabilities for cyber defence, per the primary text on the Commission's
Shaping Europe's digital future portal.
The trigger: AI agents that hack on their own
The political catalyst is not a single directive but a new category of threat. In mid-September 2025, Anthropic detected what it later called "the first reported AI-orchestrated cyber espionage campaign," attributing it with high confidence to a Chinese state-sponsored group tracked as GTG-1002. According to the BBC, the operators tricked Claude into performing 80–90% of the attack chain — reconnaissance, exploit writing, credential theft, data exfiltration — against tech firms, financial institutions, chemical manufacturers and government agencies, with humans "sporadically" in the loop.
The Council on Foreign Relations called it "the dawn of a new era for AI agents in cyberattacks," noting that the model executed thousands of actions per second and that the attackers overcame Anthropic's guardrails by decomposing malicious workflows into innocuous-looking sub-tasks, in a November 20, 2025 analysis. Five months later the ground shifted again: on April 7, 2026, Anthropic withheld Claude Mythos from general release after tests showed it could autonomously discover thousands of zero-day vulnerabilities across every major operating system and browser.
The Economist reported that access was routed through "Project Glasswing," a closed consortium of Apple, Google, Microsoft, Nvidia and other defenders.
That is the world into which the Action Plan lands.
What the plan actually does — and what it doesn't
The Commission's own text is precise about scope. The plan pledges to strengthen Europe's capacity to evaluate advanced AI models before market placement under the AI Act, to build with the EU Agency for Cybersecurity (ENISA) a "European Blueprint for secure access to advanced AI systems for cybersecurity purposes," and to stand up a secure testing platform for critical sectors — energy, transport, health, finance, public administration. It launches an EU Grand Challenge on AI for cybersecurity and doubles down on AI Factories and future Gigafactories.
Notice what is absent. The plan does not touch semiconductor export controls, does not attribute or sanction state actors, and does not create a new cross-border data regime. It is layered on the existing stack: the AI Act, NIS2, the Cyber Resilience Act, DORA and the Cyber Solidarity Act. The heavier legislative artillery sits elsewhere — in the Cybersecurity Act 2 package tabled on January 20, 2026, which the Commission acknowledges was drafted specifically because "state threat actors leverage emerging technologies such as artificial intelligence (AI) to further scale and optimise their attacks," per the recitals of proposal COM(2026) 13 on EUR-Lex.
That proposal is the load-bearing document. It rewrites ENISA's mandate, revamps the European Cybersecurity Certification Framework, tightens ICT supply-chain rules, and — critically — obliges member states to adopt national migration plans to post-quantum cryptography to counter "harvest now, decrypt later" attacks. The Action Plan is the political wrapper; COM(2026) 13 and the companion Cybersecurity Act 2 regulation COM(2026) 11 are the enforceable text.
The uncomfortable dependency
Here is where the plan's logic runs into physics. Europe is regulating AI cyber risk while remaining structurally dependent on the same frontier labs it needs to police. Bruegel notes that France's Mistral, "the European Union's most serious attempt at a competitive AI presence, … operates at a scale that barely registers against frontier US or Chinese labs" and trained its flagship models on Microsoft Azure infrastructure, per a 2026 analysis by Bruegel.
The Commission concedes the point. Its Chips Act 2.0 proposal, tabled June 3, 2026, states that "the EU produces only around 10%" of the world's semiconductors and remains "dependent on … Asia for both mature and advanced nodes, including AI chips," per the primary text at EUR-Lex COM(2026) 503. Each planned AI Gigafactory will need at least the equivalent of 75,000 advanced AI compute accelerators — the exact class of Nvidia hardware Washington controls through export licensing.
That dependency is not theoretical. Carnegie Europe reports that a U.S. export-control directive now requires Anthropic to suspend access to its Fable 5 and Mythos 5 models for all foreign nationals, "including the company's own employees, effectively disabling the models for all customers," according to a July 6, 2026 paper by Raluca Csernatoni and Patryk Pawlak. Access to Europe's most powerful defensive tool can be switched off in Washington.
RUSI puts the political read plainly: Europe's "reliance on foreign countries for over 80% of digital products, services and infrastructure is now viewed as a direct risk to its resilience, exacerbated by turbulent relations with Washington and Beijing," in a 2026 commentary on the Tech Sovereignty Package. The Action Plan does not close that gap. It manages it.
Who benefits, who loses
The immediate beneficiaries of the plan are three groups. ENISA, whose mandate expands materially under Cybersecurity Act 2 and which now co-authors the Blueprint on secure access to frontier AI. The AI Factories network — nine EuroHPC supercomputers spanning Finland's Lumi to Germany's Jupiter, mapped by an EPRS briefing — which now has a legislative rationale for public procurement in critical sectors. And European open-source cyber vendors, which the plan explicitly encourages critical operators to adopt.
The complicated beneficiaries are US frontier labs. Anthropic, OpenAI, Google DeepMind and Microsoft will supply the models the Blueprint governs. They gain a European seal of trust in exchange for pre-market evaluation obligations under Article 55 of the AI Act — obligations already operationalised through the General-Purpose AI Code of Practice, per CSIS. The regulatory ratchet tightens; the market access stays open.
The losers are Chinese model providers and, quietly, EU member states that had hoped for weaker AI Act enforcement. The digital omnibus deal reached on April 27, 2026 postponed high-risk AI system obligations until December 2, 2027 but explicitly preserved the AI Act's "main provisions and risk-based approach," according to the European Parliament. Berlin, Paris and Warsaw wanted more simplification; they got a delay, not a rewrite.
The historical parallel
There is a useful parallel: 5G. In 2019–2020, the EU responded to a supply-chain threat it could not eliminate — Huawei's dominance — with a governance instrument, the 5G Toolbox, that member states implemented unevenly. Attribution of risk was outsourced to certification and vendor scoring. The same pattern is repeating with frontier AI. The Action Plan and Cybersecurity Act 2 give the EU procedural sovereignty (rules, audits, certifications) while structural sovereignty (chips, models, cloud) sits in Chips Act 2.0 and the Cloud and AI Development Act (CADA), whose sovereignty framework requires member-state risk assessments to determine which sub-sectors must run on European-controlled cloud, per COM(2026) 502 on EUR-Lex.
Whether that gambit works depends on a second-order question the Commission has not answered: what happens when Washington's next export order restricts a model an EU-certified operator is already using in critical infrastructure? The Blueprint offers "secure access" but not sovereign substitution.
Diplomat View
The Action Plan is the right instrument for the wrong half of the problem. Brussels can regulate model behaviour, force pre-market evaluations, and stand up ENISA-run testing platforms — and it will, because that is what its treaty powers allow. But the load-bearing decisions about who gets access to frontier cyber-capable AI are being made in San Francisco (by Anthropic, OpenAI) and Washington (by BIS export controls). The plan buys Europe procedural leverage and defensive muscle memory. It does not buy autonomy.
Forecast: within 12 months, the European Blueprint will formalise a preferred-partner arrangement with a handful of US frontier labs — a Project Glasswing analogue — because Mistral cannot yet supply the capability. The forecast is falsifiable if either (a) an EU-headquartered lab produces a frontier model that passes the Blueprint's evaluation independently of US compute, or (b) Washington issues an export order that forces the Commission to invoke CADA's sovereignty framework against a US provider. Either would signal that structural sovereignty is arriving faster than expected.
Watch next:
- September 2026: ENISA expected to publish the first draft of the European Blueprint for secure access to advanced AI.
- Q4 2026: European Parliament rapporteur report on the Cybersecurity Act 2 (COM(2026) 11), lead: Miroslav Hajnoš (EESC); trilogues to follow.
- December 2, 2026: AI Act watermarking obligations for AI-generated content begin to apply, under the amended timeline agreed in the digital omnibus.
- Q2 2027: Target date for final adoption of Chips Act 2.0, per the EPRS
briefing — the moment the compute-sovereignty question stops being rhetorical.
The bottom line: the EU's Action Plan on Cybersecurity and AI is a governance answer to a supply-chain problem, and its ceiling is set by hardware Europe does not yet make and models Europe does not yet train. Brussels has bought itself procedural sovereignty over frontier AI cyber risk; structural sovereignty remains a project, not a policy — and until Chips Act 2.0 and CADA deliver, the most consequential decisions about Europe's cyber defence will continue to be made in Washington and California.
Discover more

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
700 Activists Accuse PM Modi of MCC Breach
Over 700 activists allege PM Modi breached election code with a televised address attacking opposition parties just before state elections.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.