The European Commission's own announcement frames the plan around a fairly obvious tension: AI can strengthen cyber defences, and the same capability can be used by attackers to find vulnerabilities and automate intrusions faster than defenders can respond. The Commission's answer isn't a single new law - it's five coordinated measures, summarised well by techUK's briefing and HPCwire's AIwire coverage. The Commission will build EU capacity to independently evaluate advanced AI models before they reach the EU market, targeting operational status by 2027 and explicitly designed to support the AI Office's regulatory function. Alongside that, the Commission and ENISA will develop a blueprint for structured, secure access to advanced AI systems for cybersecurity purposes, and stand up a secure testing platform so organisations in energy, transport, health, finance and public administration can trial AI security tooling against simulated attack scenarios. Two further strands push cyber hygiene obligations onto organisations directly, and commit further funding through the EU's AI Factories and Gigafactories programme, including a new "Grand Challenge on AI for cybersecurity."
Why the date this landed on matters
None of that reads as urgent in isolation - evaluation capacity "operational by 2027" sounds like a problem for next year. The reason to read it carefully now is what else is due on 2 August 2026: enforcement of obligations under the AI Act's General-Purpose AI Code of Practice, the voluntary-turned-practical compliance mechanism that frontier model providers have been signing up to over the past year. The Commission publishing a plan to build its own independent evaluation capacity three weeks before those obligations start biting is not a coincidence of scheduling - it is a signal about where the regulatory model is heading. Self-attestation through a Code of Practice is the interim state, not the destination.
For any enterprise that has leaned on a vendor's Code of Practice signature as its due diligence evidence, that is worth sitting with. A voluntary code that a lab signs and largely self-assesses against is a materially weaker guarantee than a model that has been through independent, government-backed evaluation before it was allowed on the market - the kind of gate that pharmaceuticals and medical devices have operated under for decades. The EU has just said, in writing, that it intends to move toward the latter.
What "structured access" is likely to require of vendors
The ENISA blueprint for secure access to advanced AI systems deserves particular attention from anyone running procurement for AI vendors with EU exposure. A "structured access" framework, by definition, means the vendor has to expose more about how a model works and what it can do than a typical commercial API relationship currently requires. If that pattern lands the way similar frameworks have in financial services and critical infrastructure, expect it to translate into more detailed documentation obligations for vendors, and, over time, more evidence that enterprise buyers can request as part of standard due diligence rather than needing a special agreement to see it.
The named pilot sectors - energy, transport, health, finance and public administration - are also worth noting for reasons beyond compliance. Organisations in those sectors are the most likely candidates to be pulled into the secure testing platform early, whether as volunteers or as de facto pilots once the platform exists. Getting ahead of that by understanding what "testing platform" access might require is cheaper than being told to participate with no preparation.
- Ask every AI vendor with EU-facing deployments whether they've signed the GPAI Code of Practice, and what evidence they can show beyond the signature itself - test results, red-team summaries, model cards.
- Don't wait for the EU's own evaluation capacity to go live in 2027 - build an internal model evaluation checklist now, so you're not solely dependent on vendor self-attestation in the interim.
- If your organisation sits in energy, transport, health, finance or public administration, flag the ENISA secure testing platform to your compliance team as something to actively monitor, not just read about after the fact.
- Map this plan against your existing NIS2 and Cyber Resilience Act obligations - the Commission has explicitly positioned this as complementary to both, not a replacement.
- Revisit any AI vendor contract signed purely on the strength of "we comply with the AI Act" language, and check whether it references specific, checkable commitments rather than a general assurance.
The headline framing - "EU to test AI models for cybersecurity risk" - undersells what's actually happening here. This is Brussels signalling, three weeks ahead of real enforcement dates, that vendor self-assessment is a stopgap and independent evaluation is the direction of travel. Enterprises that treat the Code of Practice signature as the finish line are reading the timeline one step behind. Want a plain-English review of what your AI vendor contracts currently commit to versus what regulators are about to expect? Email sales@halfteck.com.