Brussels Proposes AI Cybersecurity Strategy Amid Reliance on U.S. Models
Poinews.com – In response to the growing cybersecurity challenges brought by advanced AI systems, the European Commission has unveiled a strategy aimed at managing risks. However, the plan remains focused on recommendations and negotiations with U.S.-based AI firms, offering limited concrete solutions. As AI reshapes the digital threat landscape, malicious actors now deploy faster, more cost-effective, and complex cyberattacks, according to experts.
A European Approach to AI Security
The Commission’s initiative combines existing regulatory frameworks with new measures, forming a framework that critics argue prioritizes bureaucratic processes over decisive action. EU digital policy head Henna Virkkunen highlighted the dangers during a speech at the European Parliament, stating,
“Advanced AI models can generate cyber exploits in minutes or hours, at a cost far lower than human-led vulnerability discovery. Once weaponized, these flaws threaten our infrastructure and societal stability.”
Recent demonstrations by Anthropic’s top AI model, Mythos, underscore these risks. U.S. security agencies reported that Mythos uncovered exploitable weaknesses in sensitive government systems within hours. This capability led Washington to initially restrict exports of the model, but the U.S. Department of Commerce later eased those restrictions, restoring global access.
EU’s Dependency on U.S. Infrastructure
European authorities, including ENISA, secured limited access to Mythos through Anthropic’s Project Glasswing, following strong lobbying efforts by Brussels. While the plan outlines a structured method for EU entities to gain access to high-level AI tools, it also reveals the bloc’s reliance on U.S. innovation. MEP Aura Salla (Finland/EPP) emphasized,
“Our dependency goes beyond AI models—it’s about the infrastructure they depend on. Europe has robust research, but few companies at the cutting edge.”
The strategy includes guidelines for defending against AI-driven threats, such as accelerating vulnerability fixes. It also evaluates how critical systems are prepared for attacks. Bart Groothuis (Netherlands/Renew) warned,
“Cyber threats are no longer conventional. Hackers, empowered by AI, will operate at lightning speed and target your business operations relentlessly.”
Regulatory Challenges and Uncertainty
Despite the Commission’s efforts, the effectiveness of its AI Act remains in question. While the AI Office plans to collaborate with specialized evaluators to assess risks before market release, major AI labs like OpenAI and Anthropic have opted to engage the UK’s AI Security Institute instead. This decision reflects the lack of regulatory authority in Brussels, leaving the plan’s impact uncertain.

