On 7 July 2026, Members of the European Parliament are scheduled to question the European Commission on its latest proposals on artificial intelligence and cybersecurity. According to the Parliament’s agenda, the Commission is expected to present an Action Plan on Cybersecurity and AI, with concrete measures to help EU member states and European companies address AI-related cyber risks and strengthen Europe’s advanced AI cybersecurity capabilities.
For cybersecurity leaders, this is an important signal. AI security is no longer limited to discussions about model safety, prompt injection, data leakage or secure development. It is becoming part of a wider European resilience agenda that connects regulation, digital sovereignty, operational security, supply-chain exposure and business continuity.
The timing is significant. The EU is already implementing a broad digital policy framework around the AI Act, NIS2, the Cyber Resilience Act, the Cybersecurity Act, the Digital Decade programme and wider technological sovereignty initiatives. The AI Act establishes a risk-based framework for AI systems, while the EU’s technology sovereignty agenda places AI, cloud, cybersecurity, semiconductors, quantum technologies and digital infrastructure within the same strategic picture.
The Commission’s recent position in the G7 cybersecurity context shows why this topic is becoming urgent. The Commission described generative AI and large language models as “dual-edged”: they can support defenders, but they can also be used by cyber offenders and can themselves become targets through attacks such as model poisoning, data breaches and misuse of AI-assisted vulnerability discovery or code generation.
This changes the discussion for boards and executive teams. The question is no longer whether the company is “using AI”. Most organisations already are, directly or indirectly, through productivity tools, cloud platforms, software development, customer support, analytics, security operations or third-party services. The more relevant question is whether the organisation understands where AI is connected to sensitive data, critical processes, privileged access, software delivery, customer decisions and regulated business activities.
For CISOs, the immediate challenge is to move AI security from policy documents into operational control. AI tools should be treated as part of the enterprise technology environment, with ownership, risk classification, access control, monitoring, vendor assessment and incident response procedures. Shadow AI use, unmanaged browser extensions, experimental agents and unapproved integrations can create real exposure even when no traditional “system implementation project” exists.
For boards, the issue is oversight. AI-related cyber risk cuts across several governance areas at the same time: data protection, cybersecurity, operational resilience, outsourcing, software assurance, legal liability and regulatory compliance. This makes it unsuitable for purely technical reporting. Boards need a concise view of which AI use cases are approved, which are still experimental, which third parties are involved, what sensitive data is exposed, and how incidents involving AI systems would be detected, escalated and reported.
The EU policy direction also suggests that companies should expect more structured expectations around defensive AI capabilities. The Parliament’s note refers not only to addressing risks from AI, but also to strengthening Europe’s advanced AI cybersecurity capabilities. This matters because AI will not only increase attack speed. It will also become part of defensive operations, including threat detection, vulnerability management, fraud monitoring, secure coding, incident triage and cyber intelligence.
However, defensive use of AI should not be confused with uncontrolled automation. Organisations will need clear rules for human oversight, logging, decision authority and recovery. This is especially important where AI tools can recommend or execute actions affecting identity systems, network controls, software repositories, customer data, payment flows or regulated operations.
The broader European context is also about dependency. The 2026 State of the Digital Decade report highlights remaining European dependencies in strategic technologies, including cloud services and cybersecurity, while also noting rapid growth in AI adoption by businesses. This means AI-related cyber risk is not only an internal security matter. It is also a supply-chain and strategic autonomy issue.
For organisations operating in Europe, the practical response should start now. Companies should maintain an inventory of AI use across the business, classify AI-supported processes by business criticality, assess vendors and cloud dependencies, define acceptable use rules, update incident response plans for AI-related scenarios, and ensure that cybersecurity, legal, privacy, procurement and business owners work from the same risk picture.
The expected EU action plan is unlikely to be the final word on AI and cybersecurity. But it marks a clear direction: AI risk is entering the same board-level category as cyber resilience, operational continuity and regulatory accountability. Organisations that still treat AI as a collection of isolated experiments may soon find that their governance model is behind both the technology and the policy environment.
