EU's AI Cyber Action Plan Exposes US Depend
Brussels' reliance on US AI models revealed in new cybersecurity plan
Model Diplomat8 min readEurope

EU's AI Cyber Action Plan Exposes Brussels' Dependence on US Models
The European Commission's July 7 action plan on AI and cybersecurity is less a regulatory push than an admission: Europe still has to negotiate access to the frontier models that now define the threat.
The plan the European Commission unveiled on July 7, 2026 is being sold as a shield against AI-driven cyberattacks; read closely, it is a receipt for Europe's dependence on American labs. Brussels is standing up an evaluation capacity, a structured-access blueprint, an EU Grand Challenge and a promise to bankroll sovereign compute — but the models it must evaluate, access and eventually rival are all built in California. That is the story: an ostensibly regulatory document whose most consequential lines are about negotiated access to Anthropic and OpenAI, not about rules the EU can enforce alone.
What the Commission actually adopted
The Action Plan on Cybersecurity and Artificial Intelligence, published by the European Commission on July 7, sets out six workstreams. The Commission will "help establish an EU evaluation capacity" for advanced models under the AI Act, work with ENISA on a "European blueprint for structured access" to frontier models, launch a shared testing platform with the Joint Research Centre, tighten NIS2/CRA/DORA implementation, mobilise the AI Factories and Gigafactories announced in the Tech Sovereignty Package, and run an EU Grand Challenge to seed European AI-for-cyber companies.
The framing is defensive. Digital chief Henna Virkkunen told MEPs that "these advanced AI models can now build cyber exploits in minutes or hours at a fraction of the cost of vulnerability discovery by trained humans," according to reporting by Times Network on the plenary debate. The reference point was Anthropic's Claude Mythos, which US security agencies said last month had identified exploitable vulnerabilities in "highly sensitive US government computer systems within a few hours." The Commission's own
digital-strategy portal now lists the July 2026 plan as a formal complement to the AI Act, the Cyber Resilience Act, NIS2, DORA and the Cyber Solidarity Act.
The Parliament had already telegraphed the scrutiny session in a July 6 agenda note, saying MEPs would "quiz the Commission on its latest proposals," per the European Parliament. That framing matters: this is a Commission communication, not a regulation. There is no new legal duty on any AI developer that did not exist on July 6.
The Mythos shock that reshaped the file
To understand the plan, rewind twelve weeks. On June 12, the US Department of Commerce ordered Anthropic to disable Fable 5 and Mythos 5 worldwide, citing national-security concerns after Amazon researchers reportedly identified a jailbreak of the cyber-guardrails. The CSIS analysis of the order noted that Commerce imposed a worldwide license requirement — including on Anthropic's foreign national employees — an unprecedented use of export controls against an AI service, not a chip.
The shockwave was diplomatic. According to Al Jazeera, Canadian Prime Minister Mark Carney warned G7 counterparts that "the situation we're in collectively right now with Mythos and Fable is something that can happen with over-reliance." Bruno Retailleau, a French presidential candidate, called Anthropic a "wake-up call" that "a nation that depends on others for its technology is a nation that can be unplugged overnight." Commerce quietly reversed the restrictions in late June, a U-turn that
Chatham House called "mixed signals on AI governance." The
Council on Foreign Relations went further: "Allies will not adopt a model if its performance can be silently throttled by its developer."
By the time Virkkunen took the podium on July 7, the Commission was answering a specific question posed by Berlin, Paris and Rome after Mythos: what happens when Washington can, in a single Friday afternoon letter, turn off the AI stack Europe's cyber defenders were meant to use? The plan's answer is honest and awkward — a blueprint to formalise the very access channel that the US just proved it could revoke.
The tell: "structured access" is not sovereignty
The load-bearing phrase in the plan is "structured access." That is a term of art from a 2022 paper by DeepMind's Toby Shevlane, describing "controlled, arm's length interactions" with AI systems rather than open release, published on arXiv. Its adoption in an EU communication is telling: Brussels is not asking to build Mythos, it is asking for a stable API to it.
That was reinforced during the plenary debate. Finnish EPP MEP Aura Salla told the chamber, per Times Network, that "our dependency is not primarily about AI models. It is about the infrastructure they rely on. Europe has strong AI research, but too few companies operating at this frontier." ENISA gained restricted access to Mythos through Anthropic's Project Glasswing "following intense lobbying by Brussels," the same account reports — an ad hoc arrangement the plan now attempts to institutionalise.
Meanwhile, the AI Act's pre-market evaluation regime — the one lever the EU could in theory wield against Anthropic and OpenAI — is already softening. In November 2025, the Commission's Digital Omnibus proposed delaying "stricter risk-management and oversight rules for 'high-risk' AI until 2027," according to Al Jazeera. Virkkunen herself framed the delay as boosting competitiveness. Leiden's Gianclaudio Malgieri told the paper the reforms risked "moving the EU model closer to a more permissive, industry-driven approach." That is the backdrop against which US labs are being asked to submit voluntarily to European model evaluations — with, as
Times Network notes, OpenAI and Anthropic to date preferring the UK AI Security Institute precisely because it "holds no regulatory power."
The financial-sector flank: ECB moves first
The most operationally binding move on July 7 came not from Berlaymont but from Frankfurt. The European Central Bank gave euro-zone banks four months to submit plans countering AI-enabled cyber threats — a prescriptive step the Federal Reserve and Bank of England explicitly declined to match, according to reporting by Blade Intel and the
Financial Times. The ECB is essentially operationalising what the
IMF financial counsellor Tobias Adrian argued in May: that "cybersecurity" must now be treated "as a core financial stability issue" because Mythos could "find and exploit vulnerabilities in every major operating system and web browser — even when used by non-experts."
The IMF's June 29 policy note sharpens the concern into a specific mechanism: "the main financial stability concern lies less in new types of cyberattacks than in the scale effects AI can unleash across common technologies." That is the systemic risk logic the ECB is pricing in — and that supervisors in Washington and London are, for now, not.
The macroprudential architecture behind the move is not new. The ESRB flagged frontier AI as a "severe" systemic cyber risk earlier this year, and the IMF's 2025 Financial Sector Assessment Program urged EU authorities to "use a systemic risk impact scenario in the next cyber stress test for banks" and to finalise the EU-wide Systemic Cyber Incident Coordination Framework. The ECB's four-month clock is the first supervisor to convert that IMF prescription into a binding timeline.
Who wins, who loses
The winners are not primarily European. Anthropic and OpenAI gain a formal European channel for their most powerful models — the "trusted-partner" scheme G7 leaders discussed in June, per Al Jazeera, is essentially what the Commission is now building bilaterally. Structured access legitimises the commercial primacy of two US labs inside the EU cybersecurity stack, at the same moment that the AI Act's constraints are being loosened for competitiveness.
Two smaller winners: Paris-based Mistral, which Marcin Jerzewski of the European Values Center told Al Jazeera is "the EU's only major homegrown frontier-model competitor," and whichever consortia win pieces of the AI Factories and Gigafactories build-out. The Commission's
AI Continent Action Plan from April 2025 already earmarked up to €200 billion in InvestAI mobilisation and pledged to "more than triple" EuroHPC AI computing capacity. But CSIS's analysis is blunt about timelines: "the initiative will take months to be launched … and even longer to be accomplished."
The clear loser is the theory of AI sovereignty as autarky. A Brookings report by Cameron Kerry and Saurabh Mishra argues that "full-stack AI sovereignty is structurally infeasible for almost any country," because AI is a transnational stack with concentrated choke points. The July 7 plan is, in effect, the EU implicitly accepting that thesis and pivoting to what Brookings calls "managed interdependence" — mapping dependencies, diversifying suppliers, and embedding portability. The plan's language on evaluation capacity and structured access reads exactly like Brookings' prescription. The rhetoric of sovereign AI remains; the substance is negotiated access.
The second-order loser: US export-control credibility. The whiplash of the June ban and reversal has, per CFR, created "widespread uncertainty in the cybersecurity market." Every additional Brussels initiative anchored to "reducing reliance on non-European security solutions" — a phrase from the
Commission's plan — is a tax on Washington's ability to leverage the US AI stack as a diplomatic instrument.
The parallel: 5G Toolbox, not GDPR
The historical parallel to reach for is not GDPR. It is the 2020 5G Cybersecurity Toolbox, itself a Commission communication that pushed Member States toward de-risking Huawei without directly banning it. Like the 5G Toolbox, the July 7 plan is a coordination instrument, not a hard-law regulation. It creates political cover, harmonises risk assessments and channels procurement — but it leaves the binding choices to capitals and the technical choices to firms Brussels does not own.
The Cybersecurity Act 2 proposal, tabled January 20, 2026, does provide harder tools — including a mechanism for the Commission to designate "high-risk suppliers" from third countries — but that file is with Parliament's ITRE committee, rapporteur Marketa Gregorova (Greens/EFA, Czechia), and will not be operational before 2027 at the earliest, per an
EPRS briefing. Until then, the July 7 plan is the operational vehicle — and it operates via persuasion.
What to watch
- Autumn 2026, G7 Cybersecurity Working Group meeting: The Commission has committed to advance the AI-cyber priorities before the presidency transfers to Washington for 2027, per the
Commission. A US administration hostile to EU regulatory reach will inherit the file.
- November 2026, ECB deadline: Euro-zone banks' AI cyber plans due. Any material divergence from Fed/BoE approaches will test whether prudential supervision or model access becomes the binding constraint on how European finance uses frontier AI.
- 2027, AI Act high-risk obligations: Delayed from the original schedule under the Digital Omnibus. If the Parliament weakens them further, the "EU evaluation capacity" the plan announces will have nothing to evaluate against.
- Mistral's next model release: The only European datapoint that could reduce the plan's dependency footprint. Every quarter without a frontier-tier EU release is a quarter in which structured access remains the ceiling of European ambition.
Diplomat View
The July 7 plan will be remembered as the moment the EU formally accepted that "sovereign AI" is a slogan and "managed interdependence" is the policy. The falsifiable call: within 18 months, the Commission's structured-access blueprint will function as the EU's operative AI-security instrument, while the AI Act's evaluation regime — softened by the Digital Omnibus and outmatched by the pace of Mythos-tier releases — will not meaningfully gate any US frontier model from the European market. What would change that forecast: a genuine frontier release from Mistral or an EU Gigafactory-trained model at Mythos capability by end-2027, or a Commission willingness to actually invoke Article 51 systemic-risk designations against a US lab. Neither looks likely on today's evidence. The plan is competent risk management. It is not the industrial strategy that Retailleau, Carney and Salla were asking for — and Brussels knows it.
Discover more

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
Delhi CM Rekha Gupta Blasts Opposition's Delm
Delhi CM Rekha Gupta's remarks on women's quota defeat reveal BJP's strategy for the 2029 Lok Sabha elections, focusing on delimitation.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.