In one page5 August 2026

From Rules to Resilience in one page

What this work says, for a reader who will not read all of it. Written about version 1.1 and reviewed before publication.

Research question

Does the European Union's 2026 Action Plan on cybersecurity and artificial intelligence turn a very extensive body of regulation into capability a defender can use, particularly in critical infrastructure? The question is deliberately about capability rather than intent: a plan can be coherent, funded and on schedule and still have produced nothing usable. Only the second thing can be measured.

Main result

At the research cut-off of 17 July 2026, the Plan's specifically AI-related operational layer was still largely prospective. What worked was inherited: the Cybersecurity Reserve, the CSIRTs Network, EU-CyCLONe, DORA, the AI Office and the AI Factories all pre-dated the Plan and were not created by it. Its own distinctive measures, third-party model evaluation, structured access, protected testing and the AI-assisted vulnerability-remediation challenge, were concentrated in design and early mobilisation. The Plan's immediate contribution is therefore to organise a pathway: orchestration and sequencing, not capability already in hand. The report states that as its central proposition and gives it moderate confidence, while giving high confidence to the finding that no operational outcome could yet be attributed to the Plan. The multidimensional readiness profile explains why one maturity label will not do: a mandate can be clear while resources, technical services, user access and operational effects remain absent.

Method

Three instruments, applied to public sources checked one at a time. First a baseline: what existed before the Plan, so that it is not credited with what it inherited. Second, additionality rules separating inherited mechanisms, redirected capabilities and Plan-specific measures. Third, a readiness profile across five dimensions, each scored 0 to 2 conservatively: missing public evidence scores nothing, a future deadline or a political commitment does not count as technical readiness, and deployed infrastructure does not establish access to every service it is meant to offer. Pages that change over time are handled under a stated protocol, and divergences found after the cut-off are recorded in an appendix rather than quietly corrected.

Why it matters

Anyone planning around the Plan needs to know what exists and what has been announced, and in press material the two look much alike. The distinction has consequences: critical sectors differ in their capacity to absorb common European capabilities, finance is comparatively better placed, electricity combines strong governance with specific industrial-systems constraints, healthcare has high need and uneven local capacity. And technological dependencies can create common points of failure even while European governance and infrastructure expand.

What it does not prove

The work relies on public sources and cannot observe classified, internal or commercially confidential activity: absence of public evidence is not evidence that an internal capability does not exist. Ten days between the Plan's publication and the cut-off make any causal evaluation impossible, which the report states as a limit of the timing rather than of the method. NIS360 assesses sector ecosystems, not individual operators. Experimental autonomy benchmarks may not transfer to live, defended, heterogeneous systems, and their run counts should be read as versioned measurements rather than fixed capabilities. The readiness, absorption and dependency profiles are structured author assessments built on stated rules: they are not official EU ratings and do not substitute for organisation-level data.

Open questions

The report bound itself to being contradicted by dated observations. By 17 January 2027 the first results should be visible: an adopted access blueprint defining eligible users, access depth and safeguards; an accessible ENISA-JRC testing platform with an onboarding route and at least one industrial environment; published Grand Challenge rules with a path from prototype to adoption. The second review point is 17 July 2027, for model-evaluation capacity and for the Reserve. Three questions stay open: whether those services become accessible and repeatedly used with observable outcomes, whether divergence between institutions, national authorities, sectors and suppliers materialises, and whether dependencies turn into common points of failure.

Written about version
1.1
Editorial review
5 August 2026
Go to the publication