DRKJfield journal · Dr. János Kopasz
Essay · Cybersecurity

One framework, finally: the EU's cyber + AI action plan

On 7 July the Commission put NIS2, DORA, the AI Act and Europe's dependence on foreign frontier models into a single document. Boards should read the structure, not just the contents.

Dr. János Kopasz · 10 July 2026 · 6 min read NIS2DORAAI Act

For two years, those of us advising on digital regulation have made the same argument in client work: GDPR, AI Act, NIS2 and DORA are not four subjects. They regulate the same systems, bought from the same vendors, run by the same teams, failing in the same incidents. On 7 July, the European Commission presented an action plan on cybersecurity and artificial intelligence that adopts precisely this reading at EU level. It is the first Commission document I can point a board to and say: this is how Brussels itself now connects the pieces.

What is in it

The plan works from AI's dual nature, it hardens defence and automates attack, and builds around a few concrete commitments. An EU capacity for evaluating AI models is to stand behind the AI Office, intended to be operational by 2027. With ENISA, the Commission plans a "European Blueprint" for the secure use of advanced AI in critical sectors, energy, transport, health, finance, public administration. A secure testing platform and an AI-cybersecurity "Grand Challenge" round it out. The details will evolve; action plans always do.

Why the structure matters more

Three readings, in ascending order of consequence.

For compliance teams: the plan signals that supervisory expectations under NIS2 and DORA will increasingly assume AI is in scope, both as a tool your security function uses and as a system your security function must secure. "Our AI project and our cyber program are separate" is becoming an answer regulators will not accept, because their own playbook no longer separates them.

For boards: the plan treats dependence on non-EU frontier models as a security question, not a procurement detail. That matches what the past months demonstrated in practice, access to leading models has been switched off and on by a foreign government's export-control decisions. If a model your operations depend on can be restricted by someone else's regulator, that is a concentration risk in the DORA/NIS2 sense, whatever your contract says. Boards already own that category of risk; this plan makes it hard to claim it was invisible.

For contracts: the practical translation is exit and substitution. AI and cloud agreements signed this year should answer: how quickly can we switch models or providers, who bears the cost, what happens to fine-tuned assets and logs, and does the vendor owe us notice when its own upstream model access changes? These clauses cost little at signature and a fortune retrofitted.

The quiet advantage

There is a business-development observation here too, offered with self-awareness. When the regulator consolidates the field into one framework, companies whose governance is already built as one layer, the argument of this journal, get a discount: one risk map, one vendor file, one incident process to point at, whichever supervisor is asking. Companies with five parallel programs will spend 2027 writing mapping tables between their own documents.

The action plan is not law and creates no obligations by itself. But supervisory documents like this are weather forecasts. This one says the fronts are merging.


Status note, 10 July 2026: based on the Commission's press materials of 7 July; implementation details (timelines, the Blueprint's scope, the evaluation capacity's mandate) remain to be specified. Commentary, not advice.

This essay is professional commentary, not legal advice, and not attributable to any firm or client. Facts and figures are as reported at the date of writing; regulatory positions change.