Skip to main content
Brussels Stopped Treating AI Governance and Cyber Compliance as Two Programs
All Insights
Regulatory Compliance·10 min read·

Brussels Stopped Treating AI Governance and Cyber Compliance as Two Programs

By Dritan Saliovski

Two documents landed in Brussels one day apart in July 2026, and neither made much noise outside the specialist press. On 7 July the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence. On 8 July it referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2, and asked the Court to fine them until they do. Read separately, one is a policy communication and the other is a procedural step in a long-running infringement case. Read together, they are the clearest statement yet of where European regulation of AI and cybersecurity is heading: toward a single supervisory picture, enforced by authorities that the Commission is now willing to penalise its own member states to bring into existence.

For organizations with an EU footprint, and for the investors who own them, the useful reading is not the plan's list of initiatives. It is the assumption underneath it, which the Commission states directly: the existing instruments are meant to operate as one framework. An AI governance program built in isolation from cyber compliance is not merely inefficient under that assumption. It is answering a question the supervisor is no longer asking in that form.

Key Takeaways

  • The Action Plan on Cybersecurity and AI, COM(2026) 577, was presented on 7 July 2026. It complements and coordinates the AI Act, NIS2, DORA, the CRA and the Cyber Solidarity Act rather than creating a new regime
  • It is not law. A Commission communication creates no obligations and has no compliance deadline. Its value is as a signal of supervisory direction, and it should be sold to your board as exactly that, nothing more
  • On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the CJEU over NIS2 transposition, requesting a lump sum plus daily penalties. The deadline they missed was 17 October 2024
  • On 2 August 2026 the Commission's enforcement powers over general-purpose AI providers become applicable, with fines up to 3% of annual total worldwide turnover or 15 million euro under Article 101. The obligations have applied since August 2025; what ends is the grace period
  • The cost of running AI governance and cyber compliance separately is now concrete: duplicate vendor assessments, duplicate evidence, and an uncovered gap where AI systems sit inside essential services
  • The planning assumption for late-transposing states should be a shorter runway, not a longer one, once national regimes complete under penalty pressure
7 July 2026Commission presents the Action Plan on Cybersecurity and AI, COM(2026) 577, coordinating five existing frameworksEuropean Commission, IP/26/1544
4 member statesIreland, Spain, France and the Netherlands referred to the CJEU over NIS2 transposition, with financial sanctions requestedEuropean Commission, 8 July 2026, IP/26/1499
17 Oct 2024The NIS2 transposition deadline the four referred member states missed, now 20 months pastDirective (EU) 2022/2555
3% / €15MMaximum fine for general-purpose AI providers once Commission enforcement powers apply from 2 August 2026EU AI Act, Article 101

What the Action Plan Actually Says

The Action Plan starts from a premise worth quoting in substance because it is unusually balanced for a document of this type: frontier AI models bring increased capabilities to strengthen preparedness and improve threat detection and response, and AI has already become a defining element of the threat landscape, enabling more automated, scalable and sophisticated offensive operations. The Commission is not writing an AI-is-dangerous document or an AI-will-save-us document. It is writing a both-at-once document, which is the correct posture and a reasonable sign that the drafting was informed by people who have looked at the evidence.

Three objectives structure it: promoting the safe use of advanced AI, strengthening EU cyber resilience, and expanding European AI capabilities for cybersecurity. The concrete measures follow from the third more than the first two. An EU model-evaluation capacity. An ENISA access blueprint. A secure testing platform, expected by the end of 2026, so organizations in energy, transport, health, finance and public administration can test and deploy AI solutions safely. A Critical Open Source Resilience Campaign. Funding attached to AI and cybersecurity projects.

The sentence that matters for planning purposes is the one about scope. The plan complements the EU's existing legal framework for AI and cybersecurity, including the AI Act, the Cyber Resilience Act, the NIS2 Directive, DORA and the Cyber Solidarity Act. It coordinates; it does not add. This is the difference between a document that generates a compliance workstream and a document that tells you how your existing workstreams are expected to relate to each other. Anyone presenting this plan to your board as a new obligation with a deadline has misread it, and that misreading is worth catching before it consumes a quarter of someone's budget.

The Enforcement Signal Sitting Next to It

The Action Plan on its own would be a directional document with no teeth. What gives the week its weight is what happened the following day.

On 8 July the Commission referred four member states to the Court of Justice for failing to notify measures transposing NIS2. The directive lays down standards for protecting network and information systems across 18 critical sectors, notably health, energy, transport and the public sector. The transposition deadline was 17 October 2024. The Commission sent letters of formal notice on 28 November 2024, followed by reasoned opinions on 7 May 2025, and has now asked the Court to impose a lump sum and ongoing daily penalties on all four until each formally notifies full transposition.

The referred states are not marginal jurisdictions. Ireland, France, the Netherlands and Spain host a substantial share of the EU's data centre capacity, cloud regions, pharmaceutical manufacturing and financial infrastructure, along with a large proportion of the European holdings of international investors. The Commission's willingness to seek financial penalties against exactly these four is the substantive news of the week, and it is what converts the Action Plan from aspiration into direction of travel.

Scroll right to see more
Diagram showing two events in July 2026 converging on a single outcome. On the left, 7 July 2026: the Action Plan on Cybersecurity and AI, COM(2026) 577, drawn as a coordinating layer across five existing instruments, the AI Act, NIS2, DORA, the Cyber Resilience Act and the Cyber Solidarity Act, with the note that it complements rather than replaces them and creates no new obligations. On the right, 8 July 2026: referrals of Ireland, Spain, France and the Netherlands to the Court of Justice over NIS2 transposition, with a lump sum plus daily penalties requested, against a transposition deadline of 17 October 2024. The two arrows meet at a single conclusion on the right: coordinated supervision, backed by enforcement pressure, arriving in the member states that were slowest to build it.
One week, two documents. The Action Plan states that the frameworks are meant to be read together; the referrals show the Commission spending political capital to make sure the authorities that read them actually exist.
Scroll right to see more

There is a second-order effect here that operators consistently underestimate. A late transposition is not a reprieve. Organizations in a slow member state have been living with an unsettled regime, obligations visible in outline, supervisory practice not yet built, enforcement not yet staffed. When that regime completes under penalty pressure, the authority does not arrive tentatively. It arrives with its powers defined and a strong institutional incentive to demonstrate that the delay has ended. The reasonable planning assumption is compression: the interval between the national law landing and the supervisor exercising it will be shorter in the late states than it was in the early ones.

Why the Convergence Is a Practical Problem, Not a Conceptual One

It is easy to nod along with the idea that AI governance and cyber compliance belong together, and then to do nothing about it, because the statement sounds like a principle rather than a work item. It is worth being specific about what the separation actually costs.

Consider a single deployment: an AI system embedded in an operational process at an entity in scope for NIS2, supplied by a third-party vendor, running on a cloud platform, at a company owned by a financial sponsor.

Scroll right to see more
FrameworkWhat it asks about this deploymentWho usually owns the answer
AI ActWhat is this system's classification, and are you provider or deployer? Do the Article 50 transparency duties apply from 2 August 2026?AI governance / legal
NIS2Is the operating entity essential or important? Are risk management measures adequate, and has supply chain due diligence been done on the vendor? Would an incident here be reportable?CISO / cyber compliance
DORAIf the entity is financial, is this a supported critical function, and does the contract meet the third-party requirements?Operational resilience
CRADoes the system ship as a product with digital elements, and does it meet security-by-design and reporting duties?Product security
Cyber Solidarity ActDoes this sit in a sector covered by EU-level preparedness and response mechanisms?Rarely owned at all
Scroll right to see more

Five questions, one deployment, and in most organizations at least three different owners who do not share a system of record. The result is not a heroic failure. It is a quiet, expensive mess: the same vendor assessed twice against different criteria; the same evidence produced twice in different formats for different auditors; and, in the gap between the programs, the exposure that only becomes visible when the frameworks are read together, which is precisely the exposure the Commission has now said it intends to supervise as a whole. We made this argument about vendor risk specifically in five frameworks, one vendor, and the July documents are the clearest official endorsement of it so far.

The fix is not a reorganization, which is the instinct and usually the wrong one. It is a single register of systems and vendors that each framework queries, so that the mapping work is done once and each regime draws from it. That is unglamorous and considerably cheaper than the alternative.

What This Means for Deal Teams

For investors, the July week changes the shape of a diligence question that has been getting asked badly.

The common version asks whether a target is NIS2 compliant, gets a yes backed by a policy document, and moves on. That question was always weak, and in the four referred states it is now close to meaningless, because in those jurisdictions the national regime is still being finalised under judicial pressure. A target cannot be compliant with a transposition that has not been notified, and a management team claiming otherwise is telling you something about its rigour rather than its posture.

The better questions are about readiness against a compressed runway. Which entities in the target group fall in scope, in which member states, and what is the transposition status in each? If the AI systems in the operating stack sit inside an in-scope entity, who is treating them as both an AI Act matter and a NIS2 matter, and can they show a single inventory that supports both? Where the target is a supplier to essential entities, what does its customers' supply chain due diligence require of it contractually, and can it meet that today? This is the same posture we set out for the Cyber Resilience Act in what deal teams should ask about the CRA, applied to a regime whose enforcement is arriving faster than most models assume.

For sponsors with portfolio companies in Ireland, France, the Netherlands or Spain, there is a straightforward action this quarter: identify which holdings are in scope, and get a real answer on their readiness before the national regimes settle. The value at risk is not a fine in the first instance. It is the remediation cost and the delay that a supervisory finding introduces into an exit process, at a moment nobody chooses.

The Honest Limits of a Policy Document

Two cautions, because the market will overstate this.

An action plan is not a regulation. Nothing in COM(2026) 577 obliges anyone to do anything, and there is no date by which to have done it. The measures it announces, the model-evaluation capacity, the ENISA blueprint, the secure testing platform, are commitments the Commission has made to itself, and EU capability-building commitments have a mixed delivery record. Judge them on arrival.

And the AI Act milestone that genuinely lands on 2 August 2026 is narrower than the coverage suggests. The Commission's enforcement powers over general-purpose AI providers become applicable, with fines up to 3% of annual total worldwide turnover or 15 million euro under Article 101, and the Article 50 transparency obligations become enforceable. The GPAI obligations themselves have applied since 2 August 2025; what ends is the grace period on enforcement. The high-risk regime, the part most organizations were actually building toward, is the part that moved, deferred by the Digital Omnibus into December 2027 and August 2028 depending on category. We covered that reshuffle in detail in the August 2 deadline just moved, and nothing in the July documents changes it.

The signal is real; the urgency should be placed accurately. What changed in July is not a new obligation. It is the confirmation that the supervisor intends to look at AI risk and cyber risk through one lens, and the demonstration that it will spend real political capital to make sure someone is holding that lens in every member state.

How Innovaiden Approaches It

The starting point is a single register rather than a new program. Innovaiden's cross-framework exposure review builds one inventory of the systems, vendors and entities in your EU footprint, then maps each framework's questions onto it: what the AI Act asks, what NIS2 asks, what DORA and the CRA ask, and where the answers conflict or go missing. The output is a map of duplicate work you can stop doing, gaps no current owner is accountable for, and a jurisdiction-by-jurisdiction view of where transposition status makes your runway shorter than your plan assumes. For sponsors, the same review runs across a portfolio, so the question of which holdings carry real regulatory exposure in the four referred states gets answered with evidence rather than with a questionnaire.

Work With Us

Map Your AI and Cyber Obligations as One Estate

Innovaiden maps where the AI Act, NIS2, DORA, the CRA and the Cyber Solidarity Act touch the same systems, vendors and evidence in your organization, and where running them as separate programs is producing duplicate work and uncovered gaps. Reach out to scope it against your estate and your EU footprint.

Get in Touch

Frequently Asked Questions

What is the EU Action Plan on Cybersecurity and Artificial Intelligence?

It is a Commission communication, COM(2026) 577, presented on 7 July 2026, setting out how the EU intends to handle the cybersecurity risks and opportunities created by the most advanced AI models. It has three stated objectives: promoting the safe use of advanced AI, strengthening EU cyber resilience, and expanding European AI capabilities for cybersecurity. Announced measures include an EU model-evaluation capacity, an ENISA access blueprint, a secure testing platform for critical sectors expected by the end of 2026, and a Critical Open Source Resilience Campaign. Importantly, it complements the existing legal framework rather than creating a new one: it coordinates the AI Act, NIS2, DORA, the Cyber Resilience Act and the Cyber Solidarity Act instead of adding a separate regime on top of them.

Does the Action Plan create new legal obligations for my organization?

No. A Commission action plan is a policy communication, not a regulation or a directive. It imposes no new duties directly and there is nothing in it to comply with on a deadline. What it does is tell you where supervisory attention and EU capability-building are going, and it states plainly that the existing instruments are meant to be read together. The obligations that bind you still come from the AI Act, NIS2, DORA, the CRA and their national transpositions. Treat the Action Plan as direction, not as a compliance deliverable, and be sceptical of anyone selling it as the latter.

What happened with the NIS2 referrals on 8 July 2026?

The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures transposing the NIS2 Directive, Directive (EU) 2022/2555, into national law. The transposition deadline was 17 October 2024. The Commission sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025 before escalating. In the referrals it asked the Court to impose a lump sum plus daily financial penalties running until each member state notifies complete transposition.

Why should a company care whether a member state is late transposing NIS2?

Because the transposition gap is what has been holding the practical enforcement pressure back, and it is now on a clock with a financial cost attached. Organizations operating in a late member state have had the awkward benefit of an unsettled national regime: obligations known in outline, supervisory practice not yet built. When transposition completes under penalty pressure, the national authority arrives with its powers and its incentives fully formed. The planning assumption should be that the interval between the law landing and the supervisor exercising it will be shorter in the late states than it was in the early ones, not longer.

What actually happens on 2 August 2026 under the AI Act?

Two things relevant here. The Commission's enforcement and penalty powers over providers of general-purpose AI models become applicable, with fines of up to 3% of annual total worldwide turnover or 15 million euro, whichever is higher, under Article 101. The obligations themselves are not new; they have applied since 2 August 2025. What ends is the grace period. Separately, the Article 50 transparency obligations become enforceable on the same date. The high-risk regime is the part that moved, deferred by the Digital Omnibus to December 2027 and August 2028 depending on the category.

We run AI governance and cyber compliance as separate programs. Is that now wrong?

It is now expensive and it is starting to be visibly out of step with how the EU frames the problem. Wrong is too strong for a policy signal, but consider what the separation costs you: the same vendors get assessed twice against different criteria, the same evidence is produced twice in different formats, and the exposure that only appears when you look across the frameworks, an AI system embedded in an essential service run by a critical supplier, sits in the gap between the two programs where neither owner is accountable for it. The practical fix is not a reorganization. It is a single register of systems and vendors that each framework queries, so the mapping is done once.

Which framework governs an AI system used inside an essential service?

Potentially several at once, which is the point. The AI Act governs it as an AI system, with obligations depending on its classification and your role as provider or deployer. NIS2 governs the risk management and incident reporting of the essential or important entity operating it, including supply chain due diligence on the vendor supplying it. If the entity is a financial one, DORA governs its ICT operational resilience and third-party arrangements. If the system ships as a product with digital elements, the CRA governs its security by design. These are not alternatives to be chosen between; they are different questions asked about the same deployment, and the answers have to be consistent.

Subscribe