Cyberattacks are becoming easier to build, faster to launch, and more destructive than ever, thanks to a significant boost from frontier artificial intelligence (AI) models. This was noted by the EU's digital chief, Henna Virkkunen, at the launch of the EU Action Plan on Cybersecurity and Artificial Intelligence in early July 2026.
Virkkunen expressed concern about the fact that advanced AI models can now build cyber exploits in minutes or hours, posing a direct threat to the security of critical infrastructure and society in general. However, AI is also a powerful tool for defenders. Organizations are leveraging AI to reduce detection, response and recovery times, maintaining an advantage against advanced attacks.
The EU Action Plan on Cybersecurity and AI not only outlines a coordinated strategy to respond to AI-driven attacks, but also proposes a framework for structured access to advanced AI models for cybersecurity teams working in public authorities and private companies. European organizations must consider three key areas to keep hackers at bay.
The first is control and sovereignty. In Europe, technological sovereignty has become an increasingly important strategic objective. Organizations need the capacity to understand where their data has been created, moved and stored. Open source can help address this challenge, allowing organizations to reduce dependence on a single vendor and retain the freedom to move data between vendors as their needs evolve.
The second consideration is economics. Implementing cybersecurity technologies typically involves structural costs and vendor licensing penalties that make little sense in a context of growing threats and stagnant or even declining budgets. Many teams are seeking platforms that consolidate monitoring, alerts and response, where prices are based on computing power and storage.
The third consideration is readiness for innovation: security with AI agents. AI agents can relieve the pressure on overwhelmed analysts in security operations centres (SOCs) by automatically handling tasks such as data collection, threat prioritization and response planning. The transition towards an SOC with agents is already underway, automating high-volume and repetitive tasks to free up human analysts for work that demands human judgment.


