Research reportCybersecurity and AI governanceResearch report
From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence
Abstract
This Rapid Strategic Assessment asks whether the European Union can convert a regulator's legal power to obtain access to advanced AI models into a usable capability to evaluate them, and to defend critical infrastructure against AI-enabled cyber threats. The method separates what the Union inherited from what the 2026 Action Plan on Cybersecurity and Artificial Intelligence introduced, and assigns each proposition to an evidence stage: policy design, institutionally reported implementation, independently corroborated implementation, or observed performance. The central finding is a conversion problem. Union law had the access power and the published procedure; the reviewed public record had no completed evaluation, no allocated protected compute, no published methodology and no repeatedly usable service. The Plan's contribution is to sequence the missing functions around a baseline it inherited. The research cut-off is 5 August 2026.
Document status
Independent research report with a stated evidence cut-off in the document. It has not undergone peer review.
Main contributions
- Separates what the Union inherited from what the 2026 Action Plan introduced, and assigns every proposition to a stated evidence stage rather than to a general impression of progress.
- States the conversion problem: the legal power to compel access to a model became applicable on 2 August 2026 while the personnel, compute, published methods, evaluator structure and protected environments an evaluation programme needs remain unevidenced in the public record.
- Sets an indicator register with dated verification thresholds, so the assessment can be contradicted by observation at named review points rather than argued about.
- Reports what the search did not find, and what surface it searched, instead of treating public silence as evidence of absence.
Stated limitations
- Public sources only: it cannot observe classified, internal or commercially confidential activity, and absence of public evidence is not evidence that an internal capability does not exist.
- An ex-ante assessment of readiness and of capability-development pathways, not an impact evaluation.
- The readiness, absorption and dependency profiles are structured author assessments built on stated rules. They are not official EU ratings and do not substitute for organisation-level data.
- Sector capacity is read from ecosystem-level evidence, which does not describe individual operators.
Public materials
Technical details
- Authoritative archive
- Zenodo
- Date of this file
- The proof of the date was requested on 6 August 2026 and is waiting for confirmation.
- SHA-256
d614da255241aad22330fb551f75714b4e95e82e4a6f49c92f5190101e242b12- Timestamp receipt (.ots)
- Timestamp receipt (.ots)
- Verification record
- AVR-AT-RR-2026-001-v2.0-J3IOM
Where to find this work elsewhere
Citation
BibTeX
@techreport{Paone2026FromRulesTo,
author = {Paone, Andrea},
title = {From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence},
month = aug,
year = {2026},
date = {2026-08-05},
type = {Research report},
version = {2.0},
doi = {10.5281/zenodo.21810205},
url = {https://doi.org/10.5281/zenodo.21810205},
note = {Research report}
}
RIS
TY - RPRT
AU - Paone, Andrea
TI - From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence
PY - 2026
DA - 2026-08-05
M3 - Research report
DB - Zenodo
ET - 2.0
DO - 10.5281/zenodo.21810205
UR - https://doi.org/10.5281/zenodo.21810205
N1 - Research report
KW - European Union
KW - artificial intelligence
KW - AI security
KW - cybersecurity
KW - critical infrastructure
KW - cyber policy
KW - ENISA
KW - NIS2
KW - Cyber Solidarity Act
KW - AI Act
KW - implementation readiness
KW - auditability
ER -