Research reportCybersecurity and AI governanceResearch report

From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence

Zenodo deposit
Version
2.0

Abstract

This Rapid Strategic Assessment asks whether the European Union can convert a regulator's legal power to obtain access to advanced AI models into a usable capability to evaluate them, and to defend critical infrastructure against AI-enabled cyber threats. The method separates what the Union inherited from what the 2026 Action Plan on Cybersecurity and Artificial Intelligence introduced, and assigns each proposition to an evidence stage: policy design, institutionally reported implementation, independently corroborated implementation, or observed performance. The central finding is a conversion problem. Union law had the access power and the published procedure; the reviewed public record had no completed evaluation, no allocated protected compute, no published methodology and no repeatedly usable service. The Plan's contribution is to sequence the missing functions around a baseline it inherited. The research cut-off is 5 August 2026.

Document status

Independent research report with a stated evidence cut-off in the document. It has not undergone peer review.

Main contributions

  • Separates what the Union inherited from what the 2026 Action Plan introduced, and assigns every proposition to a stated evidence stage rather than to a general impression of progress.
  • States the conversion problem: the legal power to compel access to a model became applicable on 2 August 2026 while the personnel, compute, published methods, evaluator structure and protected environments an evaluation programme needs remain unevidenced in the public record.
  • Sets an indicator register with dated verification thresholds, so the assessment can be contradicted by observation at named review points rather than argued about.
  • Reports what the search did not find, and what surface it searched, instead of treating public silence as evidence of absence.

Stated limitations

  • Public sources only: it cannot observe classified, internal or commercially confidential activity, and absence of public evidence is not evidence that an internal capability does not exist.
  • An ex-ante assessment of readiness and of capability-development pathways, not an impact evaluation.
  • The readiness, absorption and dependency profiles are structured author assessments built on stated rules. They are not official EU ratings and do not substitute for organisation-level data.
  • Sector capacity is read from ecosystem-level evidence, which does not describe individual operators.

Public materials

Technical details
Authoritative archive
Zenodo
Date of this file
The proof of the date was requested on 6 August 2026 and is waiting for confirmation.
SHA-256
d614da255241aad22330fb551f75714b4e95e82e4a6f49c92f5190101e242b12
Timestamp receipt (.ots)
Timestamp receipt (.ots)
Where to find this work elsewhere

Citation

BibTeX
@techreport{Paone2026FromRulesTo,
  author = {Paone, Andrea},
  title = {From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence},
  month = aug,
  year = {2026},
  date = {2026-08-05},
  type = {Research report},
  version = {2.0},
  doi = {10.5281/zenodo.21810205},
  url = {https://doi.org/10.5281/zenodo.21810205},
  note = {Research report}
}
RIS
TY  - RPRT
AU  - Paone, Andrea
TI  - From Rules to Resilience: Assessing the EU's 2026 Action Plan on Cybersecurity and Artificial Intelligence
PY  - 2026
DA  - 2026-08-05
M3  - Research report
DB  - Zenodo
ET  - 2.0
DO  - 10.5281/zenodo.21810205
UR  - https://doi.org/10.5281/zenodo.21810205
N1  - Research report
KW  - European Union
KW  - artificial intelligence
KW  - AI security
KW  - cybersecurity
KW  - critical infrastructure
KW  - cyber policy
KW  - ENISA
KW  - NIS2
KW  - Cyber Solidarity Act
KW  - AI Act
KW  - implementation readiness
KW  - auditability
ER  -

Keywords