THE EU COMMISSION DRAFTS A PLAN ON AI AND CYBERSECURITY
The European Commission has presented an Action Plan on Cybersecurity and Artificial Intelligence to support the safe and responsible use of AI while strengthening Europe’s cybersecurity. Building on the EU’s existing legal framework on AI and cybersecurity, the Action Plan sets out a coordinated approach to help Member States, businesses and public authorities benefit from the opportunities offered by AI while addressing the new risks it creates. It focuses on 3 complementary objectives:
- Promoting the safe and responsible use of advanced AI
- Reinforcing the EU’s cybersecurity and resilience
- Scaling up Europe’s AI capabilities for cybersecurity
To promote the safe use of advanced AI, the Commission will strengthen Europe’s capacity to evaluate AI models before they are placed on the EU market, in line with the AI Act. It will also work with the European Union Agency for Cybersecurity (ENISA) to develop a European Blueprint for secure access to advanced AI systems for cybersecurity purposes and establish a secure testing platform to help organisations in critical sectors, such as energy, transport, health, finance and public administration, safely test and deploy AI solutions.
Moreover, to strengthen Europe’s technological leadership, the Commission will launch an EU Grand Challenge on AI for cybersecurity, bringing together companies, researchers and other stakeholders to develop innovative AI-powered cybersecurity solutions. The Commission hints that this will require a financial effort to boost European solutions.
The ECA insists on the industrial (and hence financial) dimension of this effort. Europe needs to develop its own solutions in a domain so essential for our autonomy, where we can leverage the experience of European cybersecurity vendors and that of AI systems European providers. And this must be an objective for 2026, no later !
DANISH DRUG MAKER NOVO NORDISK HACKED
Extortion gang Fulcrumsec has leaked on its darkweb site a second large set of data the group claims it stole in a June attack on Novo Nordisk. The latest data dump allegedly includes the Danish drug maker’s “complete enterprise Hugging Face artificial intelligence and machine learning ecosystem.” The leak was recognized last June 11, 2026. That data allegedly includes information pertaining to some 46 000 Danish healthcare professionals, 500 000 clinical investigators, and more than 2 850 named clinical trial personnel. Moreover, intellectual property on new health substances seem to have been compromised.
MORE ON THE LARGE DATA LEAK ON THE FRENCH TAX MANAGEMENT SYSTEM
The Prime Minister has decided to create a new entity to manage such crisis. What it will do which is not already possible is unclear. In fact, ANSSI, the national cybersecurity Agency, has the means and the knowledge. The issue is more a matter of authority and financial means. That a hacker succeeds infiltrating a system is one thing, that this hacker can then explore most if not all of the files is not acceptable. Simple sanitary rules can prevent this. Such rules must be implemented before the crisis, better than after. ANSSI should be entitled to enforce security measures on public systems. Regarding means and resources, France, as well as most European countries, doesn’t lack cybersecurity expertise, thanks to its vendors and cybersecurity service actors. Building links between public authorities and these private actors would prove efficient.



