The European Commission has unveiled an Action Plan on Cybersecurity and Artificial Intelligence aimed at strengthening cyber resilience while reducing dependence on foreign AI providers. The plan sets out nine measures to widen trusted access to frontier AI models for vetted cybersecurity organizations, improve model evaluation, support vulnerability discovery and coordinated disclosure, and expand AI use in threat detection and incident response. It builds on existing frameworks including NIS2, the Cyber Resilience Act, and the AI Act, and reflects growing concern that advanced AI capabilities critical to cyber defense are concentrated among a small number of mostly non-European vendors.
The move comes as security researchers report that both legal exposure and AI access restrictions are hindering good-faith cyber defense work. A recent Lawfare-cited study found researchers in the U.S. and U.K. often abandon projects, limit disclosures, or avoid certain targets because of risks tied to terms of service, the CFAA, DMCA, CMA, defamation, and fraud claims. At the same time, researchers interviewed by TechCrunch said guardrails and vetted-access programs from major AI vendors can block exploit validation, reverse engineering, and vulnerability research, pushing some defenders toward locally run open-source models. OpenAI has separately promoted a trusted-access approach for cyber defense, underscoring a broader policy shift toward controlled but expanded AI availability for legitimate security work.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
TechCrunch reported that guardrails and vetted-access programs from major AI vendors are frustrating legitimate cybersecurity researchers, citing complaints about blocked vulnerability research and exploit-validation workflows.
The European Commission unveiled an Action Plan on Cybersecurity and Artificial Intelligence aimed at improving cyber resilience and reducing dependence on foreign AI providers through nine measures.
Lawfare published an article summarizing a research paper on how anti-hacking laws, contract terms, defamation, and fraud risks deter good-faith security research in the U.S. and U.K.
OpenAI published an announcement about scaling trusted access for cyber defense, describing a vetted-access approach for cybersecurity use of advanced AI systems.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourceteiss.co.uk
Open sourcelawfaremedia.org
Open sourceopenai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.