Easier to build, faster to launch and more destructive than ever before, cyberattacks are getting a significant boost from frontier artificial intelligence (AI) models. That was the message from European Union (EU) digital chief Henna Virkkunen at the early July 2026 launch of the EU’s Action Plan on Cybersecurity and Artificial Intelligence. Virkkunen raised concerns that advanced AI models can now build cyber exploits in minutes or hours, posing a direct threat to the security of critical infrastructure and society at large.
While AI is a powerful tool for attackers, it is also a powerful asset for cybersecurity. There is, thankfully, another side to the story. Organizations are leveraging AI to reduce their mean time to detect, respond and recover, and to stay ahead of advanced attacks.
The EU’s Action Plan on Cybersecurity and AI not only outlines a coordinated strategy for responding to AI-driven attacks, but also proposes a blueprint for structured access to advanced AI models for the use of IT security teams working within public authorities and private companies. This is an important step forward but, in today’s AI-fueled threat landscape, there are three areas that EU organizations need to consider if they want to keep hackers in check. In short, they must adapt to survive.
The first is control and sovereignty. This is particularly important in Europe, where technological sovereignty has become an increasingly strategic objective. Organizations need the ability to understand where their data has been created, moved and stored.
This is central to their ability to retain meaningful control over the technologies they depend on. In practice, this means avoiding architectures that lock them into specific providers or limit their ability to integrate new capabilities and retaining the freedom to move data in, between, and out of vendors and service providers as their needs evolve. Vendor lock-in is a procurement concern, and one that many organizations seek to escape from.
Open source can help address this challenge. It enables organizations to reduce dependence on any single supplier, combine multiple technologies, switch providers, maintain systems independently or engage local service providers to do so on their behalf. This contrasts with most closed-source IT security products, where continuity of service is by no means a given, especially as vendors can change their commercial terms or exit the market altogether.
Extract — continue reading at the source.