Thursday, 20 August 2026
BreakingNewsEU

Europe first. Updated automatically from the world's leading newsrooms.

← All headlines
Politico Europe· Politics

LAYING THE GROUNDWORK FOR AI-POWERED CYBERSECURITY

The EU’s Action Plan on Cybersecurity and AI lays the groundwork for new, AI-powered approaches to IT security but organizations need to ensure their security foundations are fit for purpose.

Published Thursday, 20 August 2026 at 08:25
Easier to build, faster to launch and more destructive than ever before, cyberattacks are getting a significant boost from frontier artificial intelligence (AI) models. That was the message from European Union (EU) digital chief Henna Virkkunen at the early July 2026 launch of the EU’s Action Plan on Cybersecurity and Artificial Intelligence. Virkkunen raised concerns that advanced AI models can now build cyber exploits in minutes or hours, posing a direct threat to the security of critical infrastructure and society at large. While AI is a powerful tool for attackers, it is also a powerful asset for cybersecurity. Rene van Haaster, vice president EMEA North, Elastic There is, thankfully, another side to the story. While AI is a powerful tool for attackers, it is also a powerful asset for cybersecurity. Organizations are leveraging AI to reduce their mean time to detect, respond and recover, and to stay ahead of advanced attacks. The EU’s Action Plan on Cybersecurity and AI not only outlines a coordinated strategy for responding to AI-driven attacks, but also proposes a blueprint for structured access to advanced AI models for the use of IT security teams working within public authorities and private companies. Adapt and survive This is an important step forward but, in today’s AI-fueled threat landscape, there are three areas that EU organizations need to consider if they want to keep hackers in check. In short, they must adapt to survive. The first is control and sovereignty. This is particularly important in Europe, where technological sovereignty has become an increasingly strategic objective. Organizations need the ability to understand where their data has been created, moved and stored. This is central to their ability to retain meaningful control over the technologies they depend on. In practice, this means avoiding architectures that lock them into specific providers or limit their ability to integrate new capabilities and retaining the freedom to move data in, between, and out of vendors and service providers as their needs evolve. Vendor lock-in is a procurement concern, and one that many organizations seek to escape from. Open source can help address this challenge. It enables organizations to reduce dependence on any single supplier, combine multiple technologies, switch providers, maintain systems independently or engage local service providers to do so on their behalf. This contrasts with most closed-source IT security products, where continuity of service is by no means a given, especially as vendors can change their commercial terms or exit the market altogether. Additional advantages lie in code being publicly available for inspection and modification. Open-source technologies are continuously reviewed, maintained and improved by a global development community of people working together to make updates, address gaps, fix bugs and test security tools. They are built by the community for the community and the benefit of the industry. The second consideration is economics. Typically, implementing IT security technologies involves a range of structural costs and licensing penalties from vendors that make little sense in a world of rising threats and stagnant or even shrinking budgets. Some of these costs introduce unnecessary risk, like per-device fees that may force organizations to leave lower-priority endpoints unguarded. Some organizations also pay extra costs associated with add-on technologies for automating security processes to coordinate response workflows. Others are dealing with the considerable financial risks involved in using large language models (LLMs) that don’t adequately explain or keep a record of decisions for auditing purposes. During incident response, there are also the high costs and delays attached to retrieving historical data for analytical purposes. Fragmented tools and restrictive pricing models force IT security teams into a risky game of balancing protection and cost. The objective

This is a syndicated summary. Read the full story at the original publisher:

Read on Politico Europe