Immediate Objectives
Immediate Objectives
IO-1
Build a Member State Alliance for Supply Chain Security
IO-1
Build a Member State Alliance for Supply Chain Security
Why it matters
Reliable access to frontier AI models and compute (‘frontier AI access’) will be essential for Europe’s security and economic prosperity in a world with transformative AI. At present, Europe is dependent on foreign providers for frontier AI access. While Europe does have assets that could strengthen its bargaining position with these providers, these are dispersed across Member States. A coalition of Member States that allows countries to pool their leverage can increase collective bargaining power in negotiations to ensure reliable frontier AI access.
Why it matters
Reliable access to frontier AI models and compute (‘frontier AI access’) will be essential for Europe’s security and economic prosperity in a world with transformative AI. At present, Europe is dependent on foreign providers for frontier AI access. While Europe does have assets that could strengthen its bargaining position with these providers, these are dispersed across Member States. A coalition of Member States that allows countries to pool their leverage can increase collective bargaining power in negotiations to ensure reliable frontier AI access.
Recommendations at the Union level
Recommendations at the Union level
01
Make the ACI explicitly consider the Alliance’s decisions
Very high
01
Make the ACI explicitly consider the Alliance’s decisions
Very high
02
Ensure the Union trade commitments do not foreclose Alliance escalation options
High
02
Ensure the Union trade commitments do not foreclose Alliance escalation options
High
03
Lead negotiations within the Union’s competence, backed by the Alliance
High
03
Lead negotiations within the Union’s competence, backed by the Alliance
High
04
Collaborate with trusted partners to add their assets to Europe’s position
High
04
Collaborate with trusted partners to add their assets to Europe’s position
High
01
Make the ACI explicitly consider the Alliance’s decisions
01
Make the ACI explicitly consider the Alliance’s decisions
Action
The Commission should explicitly prepare to use the ACI in cases related to frontier AI access, setting in place a framework that allows it to be deployed quickly in support of the Member State Alliance. To do this, the Commission should:
Action
The Commission should explicitly prepare to use the ACI in cases related to frontier AI access, setting in place a framework that allows it to be deployed quickly in support of the Member State Alliance. To do this, the Commission should:
(i) Adopt guidance allowing Alliance members to file submissions as duly substantiated requests under Article 4(1) ACI. This should include an evidence template built around the ACI’s definition of coercion and consider the factors that the Commission and Council must weigh, including a pattern of interference. There should be an accelerated timeline for completing the examination of member requests that is substantially shorter than the ACI’s current recommended four month period in Article 4(2) ACI.
(ii) Identify the appropriate Union response measures for a frontier AI access case, including worked examples drawn from the ACI’s list of Union response measures in Annex I ACI, and specifying the conditions under which response measures would be lifted. Additional measures can be considered, which may require an amendment to ACI Annex I.
(iii) Prepare a ‘fast path’, meaning a shorter period for engagement with the third country (Articles 6 and 7 ACI), and readiness of response measures, in accordance with Article 8(10) ACI.
(iv) Consider amending ACI with additional restrictions on access to critical technologies as an explicit consideration in coercion assessment.
(i) Adopt guidance allowing Alliance members to file submissions as duly substantiated requests under Article 4(1) ACI. This should include an evidence template built around the ACI’s definition of coercion and consider the factors that the Commission and Council must weigh, including a pattern of interference. There should be an accelerated timeline for completing the examination of member requests that is substantially shorter than the ACI’s current recommended four month period in Article 4(2) ACI.
(ii) Identify the appropriate Union response measures for a frontier AI access case, including worked examples drawn from the ACI’s list of Union response measures in Annex I ACI, and specifying the conditions under which response measures would be lifted. Additional measures can be considered, which may require an amendment to ACI Annex I.
(iii) Prepare a ‘fast path’, meaning a shorter period for engagement with the third country (Articles 6 and 7 ACI), and readiness of response measures, in accordance with Article 8(10) ACI.
(iv) Consider amending ACI with additional restrictions on access to critical technologies as an explicit consideration in coercion assessment.
Implementation
Potential instruments:
The ACI, especially Article 4, Article 5, Article 8 and Annex I.
New Commission notice or guidance detailing the conditions under which a request can be deemed ‘duly substantiated’.
Amendment to the ACI through a legislative proposal.
Potential first steps (next 12 months):
Q4 2026: Commission drafts the guidance and evidence templates for frontier AI access with the Alliance’s secretariat.
Q1 2027: Publication of guidance, including internal worked examples of response measures.
Q2 2027: Conduct Alliance tabletop exercises for different application scenarios.
Q3 2027: Set the content and timing of an amendment to ACI.
Success indicators: Timely publication of guidance and template, along with worked examples and completion of tabletop exercise.
Implementation
Potential instruments:
The ACI, especially Article 4, Article 5, Article 8 and Annex I.
New Commission notice or guidance detailing the conditions under which a request can be deemed ‘duly substantiated’.
Amendment to the ACI through a legislative proposal.
Potential first steps (next 12 months):
Q4 2026: Commission drafts the guidance and evidence templates for frontier AI access with the Alliance’s secretariat.
Q1 2027: Publication of guidance, including internal worked examples of response measures.
Q2 2027: Conduct Alliance tabletop exercises for different application scenarios.
Q3 2027: Set the content and timing of an amendment to ACI.
Success indicators: Timely publication of guidance and template, along with worked examples and completion of tabletop exercise.
Considerations
The ACI’s coercion test is based on intent; if a nation restricts access to a critical technology but does not demand anything from the Union or a Member State in exchange for access to the technology, this action likely does not pass the test. As such, the US government’s June 2026 suspension of Fable 5 would probably not have passed the test on its own. However, if there were a documented pattern of the US linking frontier AI access to European policy choices, this would pass the test. If there is no pattern of this kind, Union recommendation 2 below may need to be applied instead.
Annex I ACI lists restrictions on the export of goods, including goods subject to export control, as a permitted response measure. Therefore, an equipment measure of the kind described under national recommendation 2 would not require an Annex I amendment.
Considerations
The ACI’s coercion test is based on intent; if a nation restricts access to a critical technology but does not demand anything from the Union or a Member State in exchange for access to the technology, this action likely does not pass the test. As such, the US government’s June 2026 suspension of Fable 5 would probably not have passed the test on its own. However, if there were a documented pattern of the US linking frontier AI access to European policy choices, this would pass the test. If there is no pattern of this kind, Union recommendation 2 below may need to be applied instead.
Annex I ACI lists restrictions on the export of goods, including goods subject to export control, as a permitted response measure. Therefore, an equipment measure of the kind described under national recommendation 2 would not require an Annex I amendment.
02
Ensure the Union trade commitments do not foreclose Alliance escalation options
02
Ensure the Union trade commitments do not foreclose Alliance escalation options
Action
Trade policy is an exclusive EU competence. This may constrain the Alliance’s escalation options, with tariff legislation determining how quickly Europe can respond to an access restriction. New trade commitments should not foreclose the Alliance’s escalation options, and the EU should resolve conflicts with existing commitments in a way that keeps escalation options open. The Alliance should have legal clarity on how a potential restriction would be interpreted at an EU level. To do this, the Commission should:
Action
Trade policy is an exclusive EU competence. This may constrain the Alliance’s escalation options, with tariff legislation determining how quickly Europe can respond to an access restriction. New trade commitments should not foreclose the Alliance’s escalation options, and the EU should resolve conflicts with existing commitments in a way that keeps escalation options open. The Alliance should have legal clarity on how a potential restriction would be interpreted at an EU level. To do this, the Commission should:
(i) Audit existing EU trade commitments and instruments against each escalation step mapped out in national recommendation 2, recording results in a register. For any conflicts identified, decide and record how it would be resolved, for example by amending, reserving or allowing the commitment to lapse at its next review. At least one lawful route for each step of the Alliance’s escalation chain should be retained.
(ii) Together with the Alliance, prepare the suspension mechanism outlined in Article 3(1), points (b) and (c), of Regulation (EU) 2026/1455 for frontier AI access cases. The Commission could also issue guidance to ensure that assessments consider restrictions on frontier AI access to EU operators as relevant, and draft the corresponding implementing act in case restriction takes place, including which of the preferences under Articles 1 and 2 would be suspended first. The preferences on AI inputs should be retained so that Europe’s own buildout is not harmed by a suspension.
(iii) Prevent new commitments from foreclosing steps outlined in the escalation chain. This could be achieved by inserting new language into negotiating mandates under Article 218 of the Treaty on the Functioning of the European Union (TFEU) and in the work plans of economic security dialogues to include security exceptions pertaining to frontier AI access. This would make sure that escalation measures taken by the Alliance to maintain its essential security interests do not put it in breach of the agreement.
(iv) Propose EU legislation under Article 207(2) TFEU that gives Member States discretion to activate steps in the escalation chain.
(i) Audit existing EU trade commitments and instruments against each escalation step mapped out in national recommendation 2, recording results in a register. For any conflicts identified, decide and record how it would be resolved, for example by amending, reserving or allowing the commitment to lapse at its next review. At least one lawful route for each step of the Alliance’s escalation chain should be retained.
(ii) Together with the Alliance, prepare the suspension mechanism outlined in Article 3(1), points (b) and (c), of Regulation (EU) 2026/1455 for frontier AI access cases. The Commission could also issue guidance to ensure that assessments consider restrictions on frontier AI access to EU operators as relevant, and draft the corresponding implementing act in case restriction takes place, including which of the preferences under Articles 1 and 2 would be suspended first. The preferences on AI inputs should be retained so that Europe’s own buildout is not harmed by a suspension.
(iii) Prevent new commitments from foreclosing steps outlined in the escalation chain. This could be achieved by inserting new language into negotiating mandates under Article 218 of the Treaty on the Functioning of the European Union (TFEU) and in the work plans of economic security dialogues to include security exceptions pertaining to frontier AI access. This would make sure that escalation measures taken by the Alliance to maintain its essential security interests do not put it in breach of the agreement.
(iv) Propose EU legislation under Article 207(2) TFEU that gives Member States discretion to activate steps in the escalation chain.
Implementation
Potential instruments:
Regulation (EU) 2026/1455, Article 3(1) and its suspension mechanism. A Commission implementing act can suspend the preferences granted by Articles 1 and 2 under the examination procedure of the Trade Barriers Committee. The examination procedure should be based on substantiated information, which could be supplied via a Member State from the Alliance.
Commission notice or guidance on the possibility of using Article 3(1) of Regulation (EU) 2026/1455 for responding to frontier AI access restrictions.
Inserting standard language into the negotiating directives under Article 218 TFEU, as well as into the annual work plans of the EU’s economic security dialogues.
Potential first steps (next 12 months):
Q2 2027: Commission begins an audit of potential conflicts with the Alliance’s escalation chain.
Q3 2027: Completed register of all conflicts with the escalation chain; issued guidance on what counts as a frontier AI access restriction; draft implementing act(s); standard language is approved for use in negotiating mandates and dialogues; final decision on whether legislation under Article 207(2) TFEU is required for any steps in the Alliance’s escalation chain.
Success indicators: Completed register of conflicts with escalation chain; guidance published and implementing act drafted; standard language around security exceptions inserted into all new negotiating mandates; each step of the escalation chain has a lawful route.
Implementation
Potential instruments:
Regulation (EU) 2026/1455, Article 3(1) and its suspension mechanism. A Commission implementing act can suspend the preferences granted by Articles 1 and 2 under the examination procedure of the Trade Barriers Committee. The examination procedure should be based on substantiated information, which could be supplied via a Member State from the Alliance.
Commission notice or guidance on the possibility of using Article 3(1) of Regulation (EU) 2026/1455 for responding to frontier AI access restrictions.
Inserting standard language into the negotiating directives under Article 218 TFEU, as well as into the annual work plans of the EU’s economic security dialogues.
Potential first steps (next 12 months):
Q2 2027: Commission begins an audit of potential conflicts with the Alliance’s escalation chain.
Q3 2027: Completed register of all conflicts with the escalation chain; issued guidance on what counts as a frontier AI access restriction; draft implementing act(s); standard language is approved for use in negotiating mandates and dialogues; final decision on whether legislation under Article 207(2) TFEU is required for any steps in the Alliance’s escalation chain.
Success indicators: Completed register of conflicts with escalation chain; guidance published and implementing act drafted; standard language around security exceptions inserted into all new negotiating mandates; each step of the escalation chain has a lawful route.
Considerations
Common commercial policy is exclusively an EU competence, and any existing national discretion here is usually read narrowly by the European Court of Justice. New national discretion related to frontier AI access restrictions will need to be legislated first.
Under Article 3 of Regulation (EU) 2026/1455, the EU can only withdraw the preferential treatment granted by the Regulation under its own Articles 1 and 2 and Annexes I to III. As a result, while ordinary tariff rates can be returned to goods covered by the regulation, tariff rates cannot affect services, impose new duties, or exceed its annexes. The deterrence value of the Regulation is therefore the commercial value of the preferences set out in the Regulation. Measures beyond changing the Regulation’s existing penalties require the ACI (see Union recommendation 1 above).
Considerations
Common commercial policy is exclusively an EU competence, and any existing national discretion here is usually read narrowly by the European Court of Justice. New national discretion related to frontier AI access restrictions will need to be legislated first.
Under Article 3 of Regulation (EU) 2026/1455, the EU can only withdraw the preferential treatment granted by the Regulation under its own Articles 1 and 2 and Annexes I to III. As a result, while ordinary tariff rates can be returned to goods covered by the regulation, tariff rates cannot affect services, impose new duties, or exceed its annexes. The deterrence value of the Regulation is therefore the commercial value of the preferences set out in the Regulation. Measures beyond changing the Regulation’s existing penalties require the ACI (see Union recommendation 1 above).
03
Lead negotiations within the Union’s competence, backed by the Alliance
03
Lead negotiations within the Union’s competence, backed by the Alliance
Action
The Commission should lead negotiations on Europe’s frontier AI access, according to its competence, on the basis of the position granted by the Member State Alliance (national recommendation 3). A breach of contractual assurances given to the Union or Member States should also be treated as grounds for considering the response steps outlined under Union recommendations 1 and 2. To do this, the Commission should:
Action
The Commission should lead negotiations on Europe’s frontier AI access, according to its competence, on the basis of the position granted by the Member State Alliance (national recommendation 3). A breach of contractual assurances given to the Union or Member States should also be treated as grounds for considering the response steps outlined under Union recommendations 1 and 2. To do this, the Commission should:
(i) Negotiate assurances on frontier AI access within existing trade and economic security dialogues and in formal agreements. The assurances should include at a minimum: consultation with the Commission before any restrictions affecting EU operators take place; continuity of frontier AI access for particular European public entities during any restricted periods; and eligibility of EU entities for vetted access programmes.
(ii) Attach these assurances to any agreements on compute buildout, to ensure that EU investment commitments are matched by access commitments.
(iii) State explicitly in agreements what would constitute a breach and that a breach is grounds for considering the response steps outlined in Union recommendations 1 and 2, as well as for the escalation chain in national recommendation 3.
(iv) Designate a Commission liaison for the Member State Alliance to ensure national preparations inform negotiations taken at the EU-level.
(i) Negotiate assurances on frontier AI access within existing trade and economic security dialogues and in formal agreements. The assurances should include at a minimum: consultation with the Commission before any restrictions affecting EU operators take place; continuity of frontier AI access for particular European public entities during any restricted periods; and eligibility of EU entities for vetted access programmes.
(ii) Attach these assurances to any agreements on compute buildout, to ensure that EU investment commitments are matched by access commitments.
(iii) State explicitly in agreements what would constitute a breach and that a breach is grounds for considering the response steps outlined in Union recommendations 1 and 2, as well as for the escalation chain in national recommendation 3.
(iv) Designate a Commission liaison for the Member State Alliance to ensure national preparations inform negotiations taken at the EU-level.
Implementation
Potential instruments:
Commission decision to designate a liaison to the Alliance.
The European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes, which is due from the Commission and ENISA in late 2026. This can serve as the template for trusted access arrangements.
Trade agreements and economic security dialogues to negotiate assured access.
Potential first steps (next 12 months):
Q4 2026: The Commission designates a liaison and compiles an inventory of EU assurances already given or received on frontier AI access across existing frameworks.
Q1 2027: Draft assurance requests based on the Alliance’s position; agree a breach clause template with the Legal Service.
Q2 2027: Raise requests with relevant governments within existing dialogues.
Q3 2027: Include breach clauses in new agreements on access or compute.
Success indicators: Commission Liaison in place; inventory of existing assurances completed; first frontier AI access assurance obtained and first agreement containing a breach clause.
Implementation
Potential instruments:
Commission decision to designate a liaison to the Alliance.
The European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes, which is due from the Commission and ENISA in late 2026. This can serve as the template for trusted access arrangements.
Trade agreements and economic security dialogues to negotiate assured access.
Potential first steps (next 12 months):
Q4 2026: The Commission designates a liaison and compiles an inventory of EU assurances already given or received on frontier AI access across existing frameworks.
Q1 2027: Draft assurance requests based on the Alliance’s position; agree a breach clause template with the Legal Service.
Q2 2027: Raise requests with relevant governments within existing dialogues.
Q3 2027: Include breach clauses in new agreements on access or compute.
Success indicators: Commission Liaison in place; inventory of existing assurances completed; first frontier AI access assurance obtained and first agreement containing a breach clause.
Considerations
An assurance from a foreign government promising continuity of frontier AI access in all circumstances is likely not obtainable. Instead, negotiations should focus on procedure: foreign governments must consult EU counterparts before placing any restrictions affecting EU operators, provide a notice period, and create avenues for EU public bodies to obtain access to restricted models. This should include restrictions framed as security measures, such as the June 2026 Anthropic Fable restrictions.
Negotiating counterparts will likely ask for comparable assurances from the EU in return, such as predictable licencing and servicing of European chip-making equipment or the removal of procurement criteria they consider discriminatory. National recommendation 2 provides some guidance on the mirror commitments that European negotiators should be prepared to give.
Assurance will only be robust if the EU responds to breaches in a credible way. For a breach clause to be effective, the first steps in the Alliance’s escalation chain should be relatively low cost.
Purchase intentions and investment commitments have already been considered in the EU’s 2025 trade frameworks, without being attached to matching frontier AI access terms. Member States are doing the same bilaterally, for instance by signing the Pax Silica agreement. Commitments of this sort could make reliable assurance harder to obtain (see national recommendation 3).
Considerations
An assurance from a foreign government promising continuity of frontier AI access in all circumstances is likely not obtainable. Instead, negotiations should focus on procedure: foreign governments must consult EU counterparts before placing any restrictions affecting EU operators, provide a notice period, and create avenues for EU public bodies to obtain access to restricted models. This should include restrictions framed as security measures, such as the June 2026 Anthropic Fable restrictions.
Negotiating counterparts will likely ask for comparable assurances from the EU in return, such as predictable licencing and servicing of European chip-making equipment or the removal of procurement criteria they consider discriminatory. National recommendation 2 provides some guidance on the mirror commitments that European negotiators should be prepared to give.
Assurance will only be robust if the EU responds to breaches in a credible way. For a breach clause to be effective, the first steps in the Alliance’s escalation chain should be relatively low cost.
Purchase intentions and investment commitments have already been considered in the EU’s 2025 trade frameworks, without being attached to matching frontier AI access terms. Member States are doing the same bilaterally, for instance by signing the Pax Silica agreement. Commitments of this sort could make reliable assurance harder to obtain (see national recommendation 3).
04
Collaborate with trusted partners to add their assets to Europe's position
04
Collaborate with trusted partners to add their assets to Europe's position
Action
The EU should build a coalition of trusted non-European partners that can add to Europe’s bargaining position and receive benefits in return, for example, through their technology, computing capacity, energy, or critical minerals. While they would not be part of the Alliance’s closed track, the Commission should negotiate reciprocal arrangements with these partners, such as access parity and continuity commitments or early warning about restrictions, and coordinate when restrictions from frontier providers occur. As many of the relevant partners and the EU itself signed the June 2026 Pax Silica declaration, the Commission should decide whether the EU’s position should be pursued inside this framework or alongside it.
Action
The EU should build a coalition of trusted non-European partners that can add to Europe’s bargaining position and receive benefits in return, for example, through their technology, computing capacity, energy, or critical minerals. While they would not be part of the Alliance’s closed track, the Commission should negotiate reciprocal arrangements with these partners, such as access parity and continuity commitments or early warning about restrictions, and coordinate when restrictions from frontier providers occur. As many of the relevant partners and the EU itself signed the June 2026 Pax Silica declaration, the Commission should decide whether the EU’s position should be pursued inside this framework or alongside it.
Implementation
Potential instruments:
EU Digital Partnerships and the annual Digital Partnership Council work plans (which include Japan, Korea, Canada, and Singapore).
The G7 Coordination Platform on Economic Coercion; bilateral economic security dialogues.
The Pax Silica declaration, whose signatories include (along with the EU and certain Member States) Australia, Japan, Norway, Korea, and the United Kingdom.
The Strategic Partnerships on Semiconductors outlined in the Chips Act 2.0 proposal (in the June 2026 Tech Sovereignty Package).
The international cooperation provision of the ACI, under which the Commission may consult or cooperate with other countries affected by similar economic coercion.
Potential first steps (next 12 months):
Q4 2026: Assessment of partner assets and dependencies; decision on whether the Commission will work inside or alongside Pax Silica.
Q1 2027: Frontier AI access and resilience deliverables placed in the 2027 Digital Partnership Council work plans.
Q2 2027: First reciprocal operational arrangement agreed with external partners.
Q3 2027: First joint exercise with a partner coordinating on how to respond to a frontier AI access restriction.
Success indicators: Position on Pax Silica adopted; live operational arrangements and exercises with external partners.
Implementation
Potential instruments:
EU Digital Partnerships and the annual Digital Partnership Council work plans (which include Japan, Korea, Canada, and Singapore).
The G7 Coordination Platform on Economic Coercion; bilateral economic security dialogues.
The Pax Silica declaration, whose signatories include (along with the EU and certain Member States) Australia, Japan, Norway, Korea, and the United Kingdom.
The Strategic Partnerships on Semiconductors outlined in the Chips Act 2.0 proposal (in the June 2026 Tech Sovereignty Package).
The international cooperation provision of the ACI, under which the Commission may consult or cooperate with other countries affected by similar economic coercion.
Potential first steps (next 12 months):
Q4 2026: Assessment of partner assets and dependencies; decision on whether the Commission will work inside or alongside Pax Silica.
Q1 2027: Frontier AI access and resilience deliverables placed in the 2027 Digital Partnership Council work plans.
Q2 2027: First reciprocal operational arrangement agreed with external partners.
Q3 2027: First joint exercise with a partner coordinating on how to respond to a frontier AI access restriction.
Success indicators: Position on Pax Silica adopted; live operational arrangements and exercises with external partners.
Considerations
Engagement with partners can take place bilaterally through Member States as well as through the Commission.
Considerations
Engagement with partners can take place bilaterally through Member States as well as through the Commission.
Recommendations at the national level
Recommendations at the national level
01
Found the Member State Alliance for Supply Chain Security by the end of 2026
Very high
01
Found the Member State Alliance for Supply Chain Security by the end of 2026
Very high
02
Use the Alliance secretariat to map actual and projected bottlenecks and leverage
Very high
02
Use the Alliance secretariat to map actual and projected bottlenecks and leverage
Very high
03
Use the Alliance to agree rules of engagement when negotiating frontier AI access
Very high
03
Use the Alliance to agree rules of engagement when negotiating frontier AI access
Very high
01
Found the Member State Alliance for Supply Chain Security by the end of 2026
01
Found the Member State Alliance for Supply Chain Security by the end of 2026
Action
As Europe’s AI supply chain assets are held by different Member States, with different owners and different national legal contexts, they have never been leveraged in tandem, and individual Member States who try to exercise leverage face individual retaliation. A standing Alliance holding these assets could act collectively to improve their collective position. Member States should:
Action
As Europe’s AI supply chain assets are held by different Member States, with different owners and different national legal contexts, they have never been leveraged in tandem, and individual Member States who try to exercise leverage face individual retaliation. A standing Alliance holding these assets could act collectively to improve their collective position. Member States should:
(i) Found a Member State Alliance to negotiate European frontier AI access. This Alliance should, in the first instance, include the Netherlands, Germany, and France as the Member States hosting high value AI supply chain assets. The Alliance should act as one party and respond together if frontier AI access is restricted. The Alliance should be open to any EU state that contributes assets that are supply chain chokepoints, funding for the Alliance’s staff, or a political commitment to act in tandem with collectively agreed Alliance decisions, on the understanding that the Alliance prepares and the EU executes trade measures.
(ii) Convene prospective Alliance members to sign a founding declaration. This should specify that decisions will be weighted by contribution. The Alliance should have an open track (with observers), and a closed track for members only. If the Alliance wants to respond to restrictions, this will happen through EU instruments, reflecting exclusive EU competence over commercial policy and trade.
(iii) Staff a secretariat (of around 8 to 12 experts) for the Alliance seconded from national ministries, including experts in supply chains, export controls, and trade law. Task the secretariat with implementing the work plan set out in national recommendations 2 and 3. Request a Commission liaison as point of contact (see Union recommendation 3).
(i) Found a Member State Alliance to negotiate European frontier AI access. This Alliance should, in the first instance, include the Netherlands, Germany, and France as the Member States hosting high value AI supply chain assets. The Alliance should act as one party and respond together if frontier AI access is restricted. The Alliance should be open to any EU state that contributes assets that are supply chain chokepoints, funding for the Alliance’s staff, or a political commitment to act in tandem with collectively agreed Alliance decisions, on the understanding that the Alliance prepares and the EU executes trade measures.
(ii) Convene prospective Alliance members to sign a founding declaration. This should specify that decisions will be weighted by contribution. The Alliance should have an open track (with observers), and a closed track for members only. If the Alliance wants to respond to restrictions, this will happen through EU instruments, reflecting exclusive EU competence over commercial policy and trade.
(iii) Staff a secretariat (of around 8 to 12 experts) for the Alliance seconded from national ministries, including experts in supply chains, export controls, and trade law. Task the secretariat with implementing the work plan set out in national recommendations 2 and 3. Request a Commission liaison as point of contact (see Union recommendation 3).
Member State mode
Coalition, including Member States with relevant AI supply chain positions. Other Member States may join under the contribution rules specified above.
Member State mode
Coalition, including Member States with relevant AI supply chain positions. Other Member States may join under the contribution rules specified above.
Implementation
Potential instruments:
The Alliance can be founded through an intergovernmental declaration, letter of intent or memorandum of understanding outside of the EU Treaties. A possible model is the Semicon Coalition announced by the Dutch government in 2025 or the 2018 European Intervention Initiative.
National secondment and budget lines for secretariat.
Classified information sharing agreement for members.
Designated Commission liaison (see Union-level recommendations above).
Potential first steps (next 12 months):
Q4 2026: Agree on the founding declaration with core Alliance members, setting out the purpose, membership rules, and position on Pax Silica. Invite prospective members, agree a secretariat budget, and designate a Commission liaison.
Q1 2027: Fully staffed secretariat and classified information sharing arrangement in place; first work programme adopted and started.
Q3 2027: Review of membership and contributions.
Success indicators: Founding declaration successfully agreed and signed by core members, with Alliance membership including countries covering lithography, optics, research and compute. Mapping (Union recommendation 2) underway and Secretariat staffed up.
Implementation
Potential instruments:
The Alliance can be founded through an intergovernmental declaration, letter of intent or memorandum of understanding outside of the EU Treaties. A possible model is the Semicon Coalition announced by the Dutch government in 2025 or the 2018 European Intervention Initiative.
National secondment and budget lines for secretariat.
Classified information sharing agreement for members.
Designated Commission liaison (see Union-level recommendations above).
Potential first steps (next 12 months):
Q4 2026: Agree on the founding declaration with core Alliance members, setting out the purpose, membership rules, and position on Pax Silica. Invite prospective members, agree a secretariat budget, and designate a Commission liaison.
Q1 2027: Fully staffed secretariat and classified information sharing arrangement in place; first work programme adopted and started.
Q3 2027: Review of membership and contributions.
Success indicators: Founding declaration successfully agreed and signed by core members, with Alliance membership including countries covering lithography, optics, research and compute. Mapping (Union recommendation 2) underway and Secretariat staffed up.
Considerations
Commercial policy is an EU competence. The Alliance must therefore operate as a political coalition that coordinates, prepares, and advocates, rather than being the vehicle through which responses to restrictions are taken. These responses will instead come through EU instruments, with Member States only acting within the discretion they have under EU law (see national recommendation 3 below).
Since cooperation comes first, the foreign country on which Europe's access most depends should be offered an observer seat in the Alliance's open track (the negotiating position, pooled procurement, partnerships, and assurances).
It is not in Europe’s interest to take an aggressive posture that could be seen as undermining free trade or attempt to interfere with foreign domestic regulation of AI development. The Alliance needs to restrict itself to reacting only to genuine coercive action.
Considerations
Commercial policy is an EU competence. The Alliance must therefore operate as a political coalition that coordinates, prepares, and advocates, rather than being the vehicle through which responses to restrictions are taken. These responses will instead come through EU instruments, with Member States only acting within the discretion they have under EU law (see national recommendation 3 below).
Since cooperation comes first, the foreign country on which Europe's access most depends should be offered an observer seat in the Alliance's open track (the negotiating position, pooled procurement, partnerships, and assurances).
It is not in Europe’s interest to take an aggressive posture that could be seen as undermining free trade or attempt to interfere with foreign domestic regulation of AI development. The Alliance needs to restrict itself to reacting only to genuine coercive action.
02
Use the Alliance secretariat to map actual and projected bottlenecks and leverage
02
Use the Alliance secretariat to map actual and projected bottlenecks and leverage
Action
The Commission already maps EU semiconductor dependencies and bottlenecks under the Chips Act, while Member States have taken part in collective risk assessments on semiconductors and AI. There is not, however, a record of where other countries depend on Europe, or a mapping of who may lawfully decide to use an asset for leverage or what using it would cost. This is a gap that the Alliance would aim to fill.
Action
The Commission already maps EU semiconductor dependencies and bottlenecks under the Chips Act, while Member States have taken part in collective risk assessments on semiconductors and AI. There is not, however, a record of where other countries depend on Europe, or a mapping of who may lawfully decide to use an asset for leverage or what using it would cost. This is a gap that the Alliance would aim to fill.
(i) Use the Alliance secretariat to produce a classified map of Europe’s leverage points in the AI supply chain. This could include, inter alia, lithography machines, optics, and research on semiconductors, as well as computing capacity and energy. This map should include a record of which foreign actors depend on which assets, how quickly this dependency can be reduced, the time lag of any restrictions, whether the leverage is likely to decrease as AI becomes transformative and as other states reduce their dependencies, which lawful authorities may decide to restrict access, and how third countries could respond (for example through tariffs or cloud access restrictions).
(ii) On the basis of this mapping, create a potential escalation chain for each asset. This could include, for instance, reduced servicing of equipment; reduced research collaboration; restricting access to public procurement; or placing conditions on export licencing. The chain should include an estimated cost and effect on Europe of each step, and whether the necessary action should be taken at European or national level.
(iii) The map should be updated continuously.
(i) Use the Alliance secretariat to produce a classified map of Europe’s leverage points in the AI supply chain. This could include, inter alia, lithography machines, optics, and research on semiconductors, as well as computing capacity and energy. This map should include a record of which foreign actors depend on which assets, how quickly this dependency can be reduced, the time lag of any restrictions, whether the leverage is likely to decrease as AI becomes transformative and as other states reduce their dependencies, which lawful authorities may decide to restrict access, and how third countries could respond (for example through tariffs or cloud access restrictions).
(ii) On the basis of this mapping, create a potential escalation chain for each asset. This could include, for instance, reduced servicing of equipment; reduced research collaboration; restricting access to public procurement; or placing conditions on export licencing. The chain should include an estimated cost and effect on Europe of each step, and whether the necessary action should be taken at European or national level.
(iii) The map should be updated continuously.
Member State mode
Coalition, including Member States with relevant AI supply chain positions (e.g. the Netherlands, Germany, Belgium, France, Austria); others can join under the contribution rules from national recommendation 1.
Member State mode
Coalition, including Member States with relevant AI supply chain positions (e.g. the Netherlands, Germany, Belgium, France, Austria); others can join under the contribution rules from national recommendation 1.
Implementation
Potential instruments:
The strategic mapping prepared via Articles 19 and 20 of the Chips Act, shared with Member States and the European Semiconductor Board.
Collective risk assessments on advanced semiconductors and AI carried out with Member States under Commission Recommendation (EU) 2023/2113.
The Commission could be invited, through the European Semiconductor Board, to task the JRC with extending the monitoring under Articles 19 and 20 of the Chips Act with reverse dependency indicators, showing where third country supply chains depend on EU suppliers.
National inventories of operators in critical supply chains maintained under the Internal Market Emergency and Resilience Act, and the supply risk monitoring and stress tests under Articles 20 to 25 of the Critical Raw Materials Act for materials inputs.
The European database on data centres under Article 12 of the Energy Efficiency Directive and Delegated Regulation (EU) 2024/1364, for computing capacity and energy.
National mandates to economic security units and export licensing authorities.
Potential first steps (next 12 months):
Q4 2026: Core Alliance members agree on the scope and purpose of the mapping and how classified materials will be handled; the completed Chips Act mapping results are obtained through the European Semiconductor Board; finish a complete first inventory of assets and who may lawfully decide levers and escalation steps that make use of them.
Q1 2027: Completed interviews with companies and assessment of dependencies, substitution time, leverage longevity, and retaliation channels; drafting of detailed escalation chains.
Q2 2027: An escalation chain, based on a mapping of dependencies and available levers, is approved and circulated to Alliance members, with gaps and risks communicated to national governments.
Q4 2027: First six month refresh is completed.
Success indicators: Escalation chain is approved by the steering group and circulated to members by the end of Q2 2027, with every asset assessed. Levers list adopted as the input to national recommendation 3 by Q3 2027. First refresh completed by the end of 2027.
Implementation
Potential instruments:
The strategic mapping prepared via Articles 19 and 20 of the Chips Act, shared with Member States and the European Semiconductor Board.
Collective risk assessments on advanced semiconductors and AI carried out with Member States under Commission Recommendation (EU) 2023/2113.
The Commission could be invited, through the European Semiconductor Board, to task the JRC with extending the monitoring under Articles 19 and 20 of the Chips Act with reverse dependency indicators, showing where third country supply chains depend on EU suppliers.
National inventories of operators in critical supply chains maintained under the Internal Market Emergency and Resilience Act, and the supply risk monitoring and stress tests under Articles 20 to 25 of the Critical Raw Materials Act for materials inputs.
The European database on data centres under Article 12 of the Energy Efficiency Directive and Delegated Regulation (EU) 2024/1364, for computing capacity and energy.
National mandates to economic security units and export licensing authorities.
Potential first steps (next 12 months):
Q4 2026: Core Alliance members agree on the scope and purpose of the mapping and how classified materials will be handled; the completed Chips Act mapping results are obtained through the European Semiconductor Board; finish a complete first inventory of assets and who may lawfully decide levers and escalation steps that make use of them.
Q1 2027: Completed interviews with companies and assessment of dependencies, substitution time, leverage longevity, and retaliation channels; drafting of detailed escalation chains.
Q2 2027: An escalation chain, based on a mapping of dependencies and available levers, is approved and circulated to Alliance members, with gaps and risks communicated to national governments.
Q4 2027: First six month refresh is completed.
Success indicators: Escalation chain is approved by the steering group and circulated to members by the end of Q2 2027, with every asset assessed. Levers list adopted as the input to national recommendation 3 by Q3 2027. First refresh completed by the end of 2027.
Considerations
The Commission has mapped EU dependencies on other countries for semiconductors under Articles 19 and 20 of the Chips Act. The recommended mapping extends its scope and documents how other countries depend on Europe, as well as how assets could gain or lose value over time, especially as transformative AI arrives. It should be an annex to the Chips Act mapping.
Considerations
The Commission has mapped EU dependencies on other countries for semiconductors under Articles 19 and 20 of the Chips Act. The recommended mapping extends its scope and documents how other countries depend on Europe, as well as how assets could gain or lose value over time, especially as transformative AI arrives. It should be an annex to the Chips Act mapping.
03
Use the Alliance to agree rules of engagement when negotiating frontier AI access
03
Use the Alliance to agree rules of engagement when negotiating frontier AI access
Action
For leverage to be credible, a foreign counterpart must know in advance that the Alliance will act together. They must believe that Alliance members cannot be negotiated or settled with individually, that a Council majority for an EU response exists, and that the costs of retaliation will be shared among members. The Alliance should fix these conditions in advance of any frontier AI access restriction incident that they need to respond to. To do this, the Alliance should:
Action
For leverage to be credible, a foreign counterpart must know in advance that the Alliance will act together. They must believe that Alliance members cannot be negotiated or settled with individually, that a Council majority for an EU response exists, and that the costs of retaliation will be shared among members. The Alliance should fix these conditions in advance of any frontier AI access restriction incident that they need to respond to. To do this, the Alliance should:
(i) Agree a common negotiating position towards the foreign countries on which Europe’s frontier AI access depends. This position could include, for instance, the starting offer that Europe should make; the escalation options developed under national recommendation 2 with the legal basis for each; and which level (EU or national) should act with which instrument at each step of the chain. Once adopted, this position should be transmitted to the Commission to apply this position in negotiations with the foreign counterparts.
(ii) Agree a consultation process for applying national measures, such as export licensing on chokepoint items, and for bilateral arrangements on frontier AI access offered to individual members, to ensure that members consult with each other before acting and commit to follow a joint position when one is reached. Members should not settle national controls on their own without consultation.
(iii) Support the fast-tracking of the EU response to coercion. Agree on an Alliance standard for assessing cases that fits the coercion definition in the ACI. Commit publicly to supporting a Council determination once that standard has been met, and work to secure a qualified majority in the Council (which may require support from non-Alliance Member States). Request the Commission to set a short period for engagement.
(iv) Agree on how the costs of retaliation by a third country will be shared, to prevent one member from being exposed to individual pressure. For example, the burden could be allocated according to members’ economic size, similar to EU budget contributions, with extra considerations for members that contribute chokepoint assets or are particularly exposed to potential retaliation.
(i) Agree a common negotiating position towards the foreign countries on which Europe’s frontier AI access depends. This position could include, for instance, the starting offer that Europe should make; the escalation options developed under national recommendation 2 with the legal basis for each; and which level (EU or national) should act with which instrument at each step of the chain. Once adopted, this position should be transmitted to the Commission to apply this position in negotiations with the foreign counterparts.
(ii) Agree a consultation process for applying national measures, such as export licensing on chokepoint items, and for bilateral arrangements on frontier AI access offered to individual members, to ensure that members consult with each other before acting and commit to follow a joint position when one is reached. Members should not settle national controls on their own without consultation.
(iii) Support the fast-tracking of the EU response to coercion. Agree on an Alliance standard for assessing cases that fits the coercion definition in the ACI. Commit publicly to supporting a Council determination once that standard has been met, and work to secure a qualified majority in the Council (which may require support from non-Alliance Member States). Request the Commission to set a short period for engagement.
(iv) Agree on how the costs of retaliation by a third country will be shared, to prevent one member from being exposed to individual pressure. For example, the burden could be allocated according to members’ economic size, similar to EU budget contributions, with extra considerations for members that contribute chokepoint assets or are particularly exposed to potential retaliation.
Member State mode
Coalition, including Member States with relevant AI supply chain positions (e.g. the Netherlands, Germany, Belgium, France, Austria); others are able to join using the contribution rules from national recommendation 1.
Member State mode
Coalition, including Member States with relevant AI supply chain positions (e.g. the Netherlands, Germany, Belgium, France, Austria); others are able to join using the contribution rules from national recommendation 1.
Implementation
Potential instruments:
National controls on non-listed items adopted and notified under Articles 9 and 10 of the Dual Use Regulation, which limit them to public security and human rights grounds.
The Commission can examine a duly substantiated request and the Council then determines coercion by qualified majority within eight weeks under Article 5, and response measures may in justified cases apply without a prior call to cease under Article 8(10). Members of the Alliance can commit to their votes in advance via a political declaration coordinated in the Council's Trade Policy Committee.
An intergovernmental cost sharing agreement, on the model of the 2014 agreement on contributions to the Single Resolution Fund.
Potential first steps (next 12 months):
Q1 2027: Finance ministries draft the burden-sharing agreement. A consultation process is drafted, and an Alliance standard for assessing frontier AI access cases in line with the coercion definition of the ACI.
Q2 2027: Members agree on the template for the rules of engagement based on the mapping obtained via national recommendation 2.
Q3 2027: Members agree on the burden-sharing agreement, a consultation process, and the standard for meeting the coercion test. Members commit publicly to supporting a Council determination once that standard has been met, and to work to secure a qualified majority in the Council.
Success indicators: Position adopted and transmitted to the Commission by Q3 2027; written support for a Council determination from all members of the Alliance, provided that all members find that a particular access restriction constitutes coercion. Cost-sharing agreement signed by all members of the Alliance.
Implementation
Potential instruments:
National controls on non-listed items adopted and notified under Articles 9 and 10 of the Dual Use Regulation, which limit them to public security and human rights grounds.
The Commission can examine a duly substantiated request and the Council then determines coercion by qualified majority within eight weeks under Article 5, and response measures may in justified cases apply without a prior call to cease under Article 8(10). Members of the Alliance can commit to their votes in advance via a political declaration coordinated in the Council's Trade Policy Committee.
An intergovernmental cost sharing agreement, on the model of the 2014 agreement on contributions to the Single Resolution Fund.
Potential first steps (next 12 months):
Q1 2027: Finance ministries draft the burden-sharing agreement. A consultation process is drafted, and an Alliance standard for assessing frontier AI access cases in line with the coercion definition of the ACI.
Q2 2027: Members agree on the template for the rules of engagement based on the mapping obtained via national recommendation 2.
Q3 2027: Members agree on the burden-sharing agreement, a consultation process, and the standard for meeting the coercion test. Members commit publicly to supporting a Council determination once that standard has been met, and to work to secure a qualified majority in the Council.
Success indicators: Position adopted and transmitted to the Commission by Q3 2027; written support for a Council determination from all members of the Alliance, provided that all members find that a particular access restriction constitutes coercion. Cost-sharing agreement signed by all members of the Alliance.
Considerations
Member States may only introduce national export controls where EU law permits, as common commercial policy is exclusively an EU competence. The Dual-Use Regulation permits export controls for public security or human rights reasons, but the European Court of Justice has tended to read such national grounds narrowly.
The ACI’s coercion test requires that restrictions carry the intent of preventing or modifying an action by the EU or Member State. This may be shown, for example, through a documented pattern of linking access decisions to previous European policy choices. If no such pattern can be shown, the EU can otherwise trigger a suspension clause in relevant trade agreements. In cases where the coercion test is met, the Alliance should work to reduce the time it takes for the EU to respond. It could do so by filing a request that specifies the measure, pattern and injury caused, as well as by having the text pre-agreed in Coreper so that the Council Presidency can table the decision at its next meeting as adopted with minimal discussion. The Alliance can also ask the Commission to set a short period for engagement or, in certain cases, to apply response measures without a prior call to cease (Article 8(10) ACI).
Considerations
Member States may only introduce national export controls where EU law permits, as common commercial policy is exclusively an EU competence. The Dual-Use Regulation permits export controls for public security or human rights reasons, but the European Court of Justice has tended to read such national grounds narrowly.
The ACI’s coercion test requires that restrictions carry the intent of preventing or modifying an action by the EU or Member State. This may be shown, for example, through a documented pattern of linking access decisions to previous European policy choices. If no such pattern can be shown, the EU can otherwise trigger a suspension clause in relevant trade agreements. In cases where the coercion test is met, the Alliance should work to reduce the time it takes for the EU to respond. It could do so by filing a request that specifies the measure, pattern and injury caused, as well as by having the text pre-agreed in Coreper so that the Council Presidency can table the decision at its next meeting as adopted with minimal discussion. The Alliance can also ask the Commission to set a short period for engagement or, in certain cases, to apply response measures without a prior call to cease (Article 8(10) ACI).
IO-2
Make Europe’s institutions ready to act in a world with transformative AI
IO-2
Make Europe’s institutions ready to act in a world with transformative AI
Why it matters
Implementing this strategy depends on institutions that can track, decide, and deliver at the pace of frontier AI. In a world with transformative AI, governments will need to deliberate, make, and act on decisions regarding AI at pace. This will require governments having informed decision-makers and advisors, access to information and data regarding AI, and the ability to use capable AI systems to augment their work.
Why it matters
Implementing this strategy depends on institutions that can track, decide, and deliver at the pace of frontier AI. In a world with transformative AI, governments will need to deliberate, make, and act on decisions regarding AI at pace. This will require governments having informed decision-makers and advisors, access to information and data regarding AI, and the ability to use capable AI systems to augment their work.
Recommendations at the Union level
Recommendations at the Union level
01
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives
Very high
01
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives
Very high
02
Empower the AI Office as an invaluable centre of expertise on AI
Very high
02
Empower the AI Office as an invaluable centre of expertise on AI
Very high
03
Rapidly expand access to frontier AI across EU institutions
Very high
03
Rapidly expand access to frontier AI across EU institutions
Very high
04
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutions needed for transformative AI
High
04
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutions needed for transformative AI
High
01
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives
01
Ensure that the Commission President and College of Commissioners are well-informed on transformative AI developments and able to execute on strategic objectives
Action
Ensure that top political decision-makers are well-informed about the latest trends and developments in transformative AI and their potential implications. While there are existing special advisors to Commissioners, this is on a part-time basis of 25 days per year on average. As AI becomes an increasingly important topic for high-level decisions, this part-time arrangement may prove insufficient for keeping leadership informed of fast-moving developments. Leadership’s awareness of developments in AI could be improved by employing a full-time, technical frontier AI advisor to the President. This advisor should be an individual with relevant experience of frontier AI, for example, through having worked at a frontier AI provider. They should be called upon to input on high-level deliberations relevant to transformative AI, and be provided with a direct, two-way line of communication to the AI Office. The Commission should also establish a Transformative AI Task Force of approximately 15 staff to support the advisor. This task force should be given a mandate that includes driving implementation of this strategy's recommended strategy across Directorates-General (DGs), running demonstrations and briefings for senior officials, and coordinating with the EEAS and relevant security structures.
Action
Ensure that top political decision-makers are well-informed about the latest trends and developments in transformative AI and their potential implications. While there are existing special advisors to Commissioners, this is on a part-time basis of 25 days per year on average. As AI becomes an increasingly important topic for high-level decisions, this part-time arrangement may prove insufficient for keeping leadership informed of fast-moving developments. Leadership’s awareness of developments in AI could be improved by employing a full-time, technical frontier AI advisor to the President. This advisor should be an individual with relevant experience of frontier AI, for example, through having worked at a frontier AI provider. They should be called upon to input on high-level deliberations relevant to transformative AI, and be provided with a direct, two-way line of communication to the AI Office. The Commission should also establish a Transformative AI Task Force of approximately 15 staff to support the advisor. This task force should be given a mandate that includes driving implementation of this strategy's recommended strategy across Directorates-General (DGs), running demonstrations and briefings for senior officials, and coordinating with the EEAS and relevant security structures.
Implementation
Potential instruments:
The advisor function and the Transformative AI Task Force can be established via executive decision.
Articles 14–15 of C(2025) 4716 allow for Principal Advisors to be employed in the Secretariat-General as 2(a) temporary agents, on an AD14 pay grade.
Communication channels between political leadership and the AI Office can be established without formal action.
Potential first steps (next 12 months):
Q4 2026: The Commission President announces the appointment of the technical frontier AI advisor. Recruitment efforts commence, with predefined conflict of interest rules for candidates previously employed by frontier AI providers.
Q1 2027: Advisor appointed and announcement published.
Q2 2027: The Task Force enters operation, staffed by both secondees and new hires. The first briefing to the Commission president, Commissioners, and Directors-General is held by the technical advisor.
Success indicators: Appointment of president’s technical advisor made. Task Force employees and secondees in post. Quarterly briefings held.
Implementation
Potential instruments:
The advisor function and the Transformative AI Task Force can be established via executive decision.
Articles 14–15 of C(2025) 4716 allow for Principal Advisors to be employed in the Secretariat-General as 2(a) temporary agents, on an AD14 pay grade.
Communication channels between political leadership and the AI Office can be established without formal action.
Potential first steps (next 12 months):
Q4 2026: The Commission President announces the appointment of the technical frontier AI advisor. Recruitment efforts commence, with predefined conflict of interest rules for candidates previously employed by frontier AI providers.
Q1 2027: Advisor appointed and announcement published.
Q2 2027: The Task Force enters operation, staffed by both secondees and new hires. The first briefing to the Commission president, Commissioners, and Directors-General is held by the technical advisor.
Success indicators: Appointment of president’s technical advisor made. Task Force employees and secondees in post. Quarterly briefings held.
Considerations
The Task Force should be tasked with coordinating and tracking policy delivery rather than duplicating the technical and regulatory functions of the AI Office. It should provide a quarterly stocktake of progress on implementation across DGs to the Commission President and relevant Commissioners.
The AI Office, as the commission’s centre of AI expertise, should have a direct reporting line to the advisor, with confidentiality arrangements in place in line with Article 78 of the AI Act.
The primary value of the technical advisor will be their technical credibility and hands-on experience with frontier AI. The selection process should prioritise finding candidates with these qualities.
Considerations
The Task Force should be tasked with coordinating and tracking policy delivery rather than duplicating the technical and regulatory functions of the AI Office. It should provide a quarterly stocktake of progress on implementation across DGs to the Commission President and relevant Commissioners.
The AI Office, as the commission’s centre of AI expertise, should have a direct reporting line to the advisor, with confidentiality arrangements in place in line with Article 78 of the AI Act.
The primary value of the technical advisor will be their technical credibility and hands-on experience with frontier AI. The selection process should prioritise finding candidates with these qualities.
02
Empower the AI Office as an invaluable centre of expertise on AI
02
Empower the AI Office as an invaluable centre of expertise on AI
Action
Three immediate actions should be taken to cement the AI Office’s status as a centre of subject-matter expertise within the Commission. Firstly, direct, two-way lines of communication should be established between senior Commission officials and subject-matter experts within the AI Office. Existing in-house expertise should be utilised to inform key decision-makers through briefings, workshops, and regular communication. Secondly, AI Office hiring should be reformed so that it can hire and utilise world-class subject-matter expertise. Concrete actions include: reducing the time from first interview to offer to six weeks or less; hiring employees as temporary agents rather than contract agents, so that they can serve beyond a six-year term; standing up a dedicated headhunting capability with a talent-scouting remit; increasing pay grades beyond typical civil servant levels for technical hires; hiring on merit alone, using nationality derogations for outstanding non-EU technical hires; and allowing more flexibility for remote work. In parallel, the AI Office should be provided with sufficient administrative and operational staff, so that scarce technical talent can focus on technical tasks where their talent is best used. Thirdly, the AI Office should be provided with dedicated additional funding to provide staff with large amounts of compute and API credits for using frontier AI systems to assist their work.
Action
Three immediate actions should be taken to cement the AI Office’s status as a centre of subject-matter expertise within the Commission. Firstly, direct, two-way lines of communication should be established between senior Commission officials and subject-matter experts within the AI Office. Existing in-house expertise should be utilised to inform key decision-makers through briefings, workshops, and regular communication. Secondly, AI Office hiring should be reformed so that it can hire and utilise world-class subject-matter expertise. Concrete actions include: reducing the time from first interview to offer to six weeks or less; hiring employees as temporary agents rather than contract agents, so that they can serve beyond a six-year term; standing up a dedicated headhunting capability with a talent-scouting remit; increasing pay grades beyond typical civil servant levels for technical hires; hiring on merit alone, using nationality derogations for outstanding non-EU technical hires; and allowing more flexibility for remote work. In parallel, the AI Office should be provided with sufficient administrative and operational staff, so that scarce technical talent can focus on technical tasks where their talent is best used. Thirdly, the AI Office should be provided with dedicated additional funding to provide staff with large amounts of compute and API credits for using frontier AI systems to assist their work.
Implementation
Potential instruments:
High-level AI expertise could be employed as Article 2(a) temporary agents under the Conditions of Employment of Other Servants of the European Union (CEOS), rather than as Article 3(b) contract agents, allowing for permanent contracts.
Pay grades of AD7–AD11 should be used for technical hires, applying exemptions to years of prior experience by Article 13(4) of C(2025) 4716 where necessary.
Nationality derogations are possible under Articles 12(2)(a) and 82(3)(a) of the staff regulation.
The Large-Scale Review can be used as a framing vehicle for piloting flexible recruitment.
Potential first steps (next 12 months):
Q4 2026: The AI Office and DG HR agree on an expedited hiring pathway for urgent hires, and review the default contract terms for AI Office recruitment. The Large-Scale Review's final recommendations (to be published by the end of 2026) name AI Office recruitment as a pilot for flexible technical hiring. DG BUDG requests additional temporary-agent posts in the 2027 draft budget.
Q1 2027: Headhunting team operational.
Q2 2027: First cohort of hires employed as temporary agents, and offers given to current staff employed as contract agents to convert to temporary agents.
Q4 2027: First year recruitment metrics published.
Success indicators: Median days from first interview to offer. Share of expert hires engaged as temporary agents. 12-month retention of senior staff.
Implementation
Potential instruments:
High-level AI expertise could be employed as Article 2(a) temporary agents under the Conditions of Employment of Other Servants of the European Union (CEOS), rather than as Article 3(b) contract agents, allowing for permanent contracts.
Pay grades of AD7–AD11 should be used for technical hires, applying exemptions to years of prior experience by Article 13(4) of C(2025) 4716 where necessary.
Nationality derogations are possible under Articles 12(2)(a) and 82(3)(a) of the staff regulation.
The Large-Scale Review can be used as a framing vehicle for piloting flexible recruitment.
Potential first steps (next 12 months):
Q4 2026: The AI Office and DG HR agree on an expedited hiring pathway for urgent hires, and review the default contract terms for AI Office recruitment. The Large-Scale Review's final recommendations (to be published by the end of 2026) name AI Office recruitment as a pilot for flexible technical hiring. DG BUDG requests additional temporary-agent posts in the 2027 draft budget.
Q1 2027: Headhunting team operational.
Q2 2027: First cohort of hires employed as temporary agents, and offers given to current staff employed as contract agents to convert to temporary agents.
Q4 2027: First year recruitment metrics published.
Success indicators: Median days from first interview to offer. Share of expert hires engaged as temporary agents. 12-month retention of senior staff.
Considerations
In transformative AI scenarios, the required spending on compute and API credits for AI Office staff could be at least as large as employee salaries.
The current form of fixed-term contract agent employment, which is capped at six years, will eventually lead to the AI Office losing senior expertise, starting in mid-2030.
While pay grades that are competitive with industry are unrealistic, parity with peer public institutions, such as the UK AISI, is achievable and should be the minimum target.
The dedicated headhunting team should make sure to be aligned with the team leads regarding the desired profiles of new hires.
Considerations
In transformative AI scenarios, the required spending on compute and API credits for AI Office staff could be at least as large as employee salaries.
The current form of fixed-term contract agent employment, which is capped at six years, will eventually lead to the AI Office losing senior expertise, starting in mid-2030.
While pay grades that are competitive with industry are unrealistic, parity with peer public institutions, such as the UK AISI, is achievable and should be the minimum target.
The dedicated headhunting team should make sure to be aligned with the team leads regarding the desired profiles of new hires.
03
Rapidly expand access to frontier AI across EU institutions
03
Rapidly expand access to frontier AI across EU institutions
Action
In order to keep pace with consumers and firms deploying increasingly powerful frontier tools, European institutions need access to these same capabilities. Building on initiatives like GPT@EC, the Commission should ensure there is minimal lag between the capabilities of tools made available to EU staff and the frontier. Model access should be secured across the service through a central procurement process. Common rules for data classification, security, sovereignty, and permitted use should provide clear legal guidance for acceptable use. In addition, the European Data Protection Supervisor (EDPS) should issue guidelines to facilitate safe and legal AI-assisted and automated decision-making in areas vulnerable to service flooding to increase resilience.
Action
In order to keep pace with consumers and firms deploying increasingly powerful frontier tools, European institutions need access to these same capabilities. Building on initiatives like GPT@EC, the Commission should ensure there is minimal lag between the capabilities of tools made available to EU staff and the frontier. Model access should be secured across the service through a central procurement process. Common rules for data classification, security, sovereignty, and permitted use should provide clear legal guidance for acceptable use. In addition, the European Data Protection Supervisor (EDPS) should issue guidelines to facilitate safe and legal AI-assisted and automated decision-making in areas vulnerable to service flooding to increase resilience.
Implementation
Potential instruments:
DIGIT could use framework contracts to centrally procure frontier AI tools for use across the Commission. Procurement conditions should ensure that providers do not have access to sensitive data per the Commission's sovereign-cloud framework. Procurement should be inter-institutional from the outset, ensuring that the Parliament, Council, and other relevant institutions and bodies of the Union can be contracting authorities. Models should be chosen on capability regardless of origin, with the proposed CADA Article 32 preferences only being applied in cases where EU models are competitive with the frontier AI models.
The Commission could invite EDPS to develop guidance on AI-assisted decision-making and on the conditions for implementation of automated decision-making in accordance with Regulation (EU) 2018/1725.
The EDPS sandbox for the institutions under AI Act Article 57(3) could be used to develop tools to support automated decision-making within the European institutions, such as oversight design, monitoring requirements, and an appeals process.
Potential first steps (next 12 months):
Q4 2026: The Commission updates guidance for the procurement of AI models, with a focus on eliminating the gap between the tools available to institutions and those available to the public. EU institutions identify services that are most vulnerable to AI-driven service flooding.
Q1 2027: The AI Office coordinates with EDPS on sandbox testing.
Q2 2027: Reduce duplication and pool resources through joint projects with Member States.
Success indicators:
Reliable access to frontier capabilities, as measured by the time lag between public frontier model release and internal roll-out of the model by the Commission.
EDPS guidelines for AI-assisted decision-making published.
Monthly active users of catalogue tools as a share of all staff, to measure adoption.
Implementation
Potential instruments:
DIGIT could use framework contracts to centrally procure frontier AI tools for use across the Commission. Procurement conditions should ensure that providers do not have access to sensitive data per the Commission's sovereign-cloud framework. Procurement should be inter-institutional from the outset, ensuring that the Parliament, Council, and other relevant institutions and bodies of the Union can be contracting authorities. Models should be chosen on capability regardless of origin, with the proposed CADA Article 32 preferences only being applied in cases where EU models are competitive with the frontier AI models.
The Commission could invite EDPS to develop guidance on AI-assisted decision-making and on the conditions for implementation of automated decision-making in accordance with Regulation (EU) 2018/1725.
The EDPS sandbox for the institutions under AI Act Article 57(3) could be used to develop tools to support automated decision-making within the European institutions, such as oversight design, monitoring requirements, and an appeals process.
Potential first steps (next 12 months):
Q4 2026: The Commission updates guidance for the procurement of AI models, with a focus on eliminating the gap between the tools available to institutions and those available to the public. EU institutions identify services that are most vulnerable to AI-driven service flooding.
Q1 2027: The AI Office coordinates with EDPS on sandbox testing.
Q2 2027: Reduce duplication and pool resources through joint projects with Member States.
Success indicators:
Reliable access to frontier capabilities, as measured by the time lag between public frontier model release and internal roll-out of the model by the Commission.
EDPS guidelines for AI-assisted decision-making published.
Monthly active users of catalogue tools as a share of all staff, to measure adoption.
Considerations
There are barriers to current procurement mechanisms reliably guaranteeing access to frontier AI systems, for example the length of time that procurement awards generally take. Procurement to guarantee frontier AI access would require faster timelines to approval.
Procurement contracts should include clauses on exportability of data and workflows in order to prevent lock-in or dependence on a single provider.
Considerations
There are barriers to current procurement mechanisms reliably guaranteeing access to frontier AI systems, for example the length of time that procurement awards generally take. Procurement to guarantee frontier AI access would require faster timelines to approval.
Procurement contracts should include clauses on exportability of data and workflows in order to prevent lock-in or dependence on a single provider.
04
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutional structures needed for transformative AI.
04
Convene leaders, officials, and subject matter experts to ideate, plan, and action the creation of new institutional structures needed for transformative AI.
Action
Hold a series of convenings that bring together senior Commission officials, AI Office experts, and independent subject-matter experts to brainstorm, plan, and action the creation of new institutional structures that will prepare European institutions for transformative AI. This could include institutional structures that improve foresight and strategic awareness, such as, an AI Strategic Foresight Unit, staffed with dedicated frontier AI experts, created within the AI Office, the Secretariat-General, DG IDEA, or elsewhere; Transformative AI Fellows appointed to DG IDEA; or the seconding of AI Office experts or hiring of other frontier AI experts to EU delegations and offices in San Francisco and Beijing. But there are likely other purposes and more ambitious institutional structures that should be considered (e.g. information sharing, emergency preparedness, evaluation capacity, incident investigation, a Union-level AI agency). Clear ownership should be assigned to an individual or group of individuals to push forward this process. The process could be facilitated by the AI Office, reporting to Commission leadership, by planning what sessions and inputs will be needed to come up with ideas and who needs to be in the room to best brainstorm, plan, and action such new institutional structures.
Action
Hold a series of convenings that bring together senior Commission officials, AI Office experts, and independent subject-matter experts to brainstorm, plan, and action the creation of new institutional structures that will prepare European institutions for transformative AI. This could include institutional structures that improve foresight and strategic awareness, such as, an AI Strategic Foresight Unit, staffed with dedicated frontier AI experts, created within the AI Office, the Secretariat-General, DG IDEA, or elsewhere; Transformative AI Fellows appointed to DG IDEA; or the seconding of AI Office experts or hiring of other frontier AI experts to EU delegations and offices in San Francisco and Beijing. But there are likely other purposes and more ambitious institutional structures that should be considered (e.g. information sharing, emergency preparedness, evaluation capacity, incident investigation, a Union-level AI agency). Clear ownership should be assigned to an individual or group of individuals to push forward this process. The process could be facilitated by the AI Office, reporting to Commission leadership, by planning what sessions and inputs will be needed to come up with ideas and who needs to be in the room to best brainstorm, plan, and action such new institutional structures.
Implementation
Potential instruments:
Internal communication by owner and Commission leadership signalling intent to convene discussions on this topic.
Informal internal convening of relevant stakeholders.
Potential first steps (next 12 months):
October 2026: Assign ownership for planning and hosting the convenings.
Q4 2026: Collect input, plan session formats, and send out initial invitations.
Q1 2027 onwards: Hold series of planned convenings.
Implementation
Potential instruments:
Internal communication by owner and Commission leadership signalling intent to convene discussions on this topic.
Informal internal convening of relevant stakeholders.
Potential first steps (next 12 months):
October 2026: Assign ownership for planning and hosting the convenings.
Q4 2026: Collect input, plan session formats, and send out initial invitations.
Q1 2027 onwards: Hold series of planned convenings.
Considerations
Such convenings likely need to happen in stages to ensure ideation, planning, and actioning stages occur sufficiently and that the right individuals are present for each session.
Collecting input from Commission and AI Office officials will be a valuable source of institutional knowledge and expertise for current institutional bottlenecks and frictions.
Evaluating the successes and failures of other frontier AI institutional structures in other countries or regions will be a valuable exercise.
Frontier AI and other subject matter expertise (e.g. security, emergency preparedness, intelligence and national security) should be drawn on internally to the Commission and European institutions. Where needed external expert consultation can strengthen ideation and implementation processes.
Considerations
Such convenings likely need to happen in stages to ensure ideation, planning, and actioning stages occur sufficiently and that the right individuals are present for each session.
Collecting input from Commission and AI Office officials will be a valuable source of institutional knowledge and expertise for current institutional bottlenecks and frictions.
Evaluating the successes and failures of other frontier AI institutional structures in other countries or regions will be a valuable exercise.
Frontier AI and other subject matter expertise (e.g. security, emergency preparedness, intelligence and national security) should be drawn on internally to the Commission and European institutions. Where needed external expert consultation can strengthen ideation and implementation processes.
Recommendations at the national level
Recommendations at the national level
01
Build national technical AI assessment capacity and frontier AI expertise
High
01
Build national technical AI assessment capacity and frontier AI expertise
High
02
Appoint senior frontier AI advisors with direct access to the head of government
Very high
02
Appoint senior frontier AI advisors with direct access to the head of government
Very high
03
Collect, analyse, and publish national statistics on AI diffusion and adoption
High
03
Collect, analyse, and publish national statistics on AI diffusion and adoption
High
04
Ensure a baseline of AI literacy across all government departments
High
04
Ensure a baseline of AI literacy across all government departments
High
01
Build national technical AI assessment capacity and frontier AI expertise
01
Build national technical AI assessment capacity and frontier AI expertise
Action
Establish or scale an in-house national technical unit for assessing frontier AI and advising government. The designated unit should be tasked with providing senior decision-makers with assessments of frontier AI progress, impacts, and policy implications. The Unit should actively maintain links to other Member States’ analogous bodies, national security authorities, and the EU AI Office. These Units should be given autonomy and flexibility in hiring and staffing, including derogations from national civil-service pay grades, ring-fenced funding, and access to compute and AI tools in order to attract, empower, and retain top-level subject-matter staff.
Action
Establish or scale an in-house national technical unit for assessing frontier AI and advising government. The designated unit should be tasked with providing senior decision-makers with assessments of frontier AI progress, impacts, and policy implications. The Unit should actively maintain links to other Member States’ analogous bodies, national security authorities, and the EU AI Office. These Units should be given autonomy and flexibility in hiring and staffing, including derogations from national civil-service pay grades, ring-fenced funding, and access to compute and AI tools in order to attract, empower, and retain top-level subject-matter staff.
Member State mode
All Member States, with unit size proportional to Member State size. All Member States should establish, at a minimum, a core unit of 5–10 subject-matter experts. Some Member States may wish to expand this to a national AISI, such as the one recently announced by Germany. Neighboring Member States may wish to pool resources and form regional partnerships (e.g. Nordics, Baltics).
Member State mode
All Member States, with unit size proportional to Member State size. All Member States should establish, at a minimum, a core unit of 5–10 subject-matter experts. Some Member States may wish to expand this to a national AISI, such as the one recently announced by Germany. Neighboring Member States may wish to pool resources and form regional partnerships (e.g. Nordics, Baltics).
Implementation
Potential instruments:
Options include a ministerial decision to establish a new unit or extend an existing government body, legislative action, or formal partnership with existing research institutes, with specifics depending on national institutional arrangements.
Potential first steps (next 12 months):
Q4 2026: Identify and designate a suitable host institution for the advisory unit. Secure a designated operating budget for the next national budget cycle.
Q1 2027: Appoint founding leadership positions through an open international search, with pay-derogation instruments adopted.
Q2–Q3 2027: Establish the core team of subject-matter experts, and begin advising and analysis tasks.
Indicator: Technical full-time equivalent employees in post against target. Multi-annual budget secured. 12-month retention of technical staff.
Implementation
Potential instruments:
Options include a ministerial decision to establish a new unit or extend an existing government body, legislative action, or formal partnership with existing research institutes, with specifics depending on national institutional arrangements.
Potential first steps (next 12 months):
Q4 2026: Identify and designate a suitable host institution for the advisory unit. Secure a designated operating budget for the next national budget cycle.
Q1 2027: Appoint founding leadership positions through an open international search, with pay-derogation instruments adopted.
Q2–Q3 2027: Establish the core team of subject-matter experts, and begin advising and analysis tasks.
Indicator: Technical full-time equivalent employees in post against target. Multi-annual budget secured. 12-month retention of technical staff.
Considerations
This recommendation operationalises Article 70(3) of the AI Act, which obliges Member States to provide national competent authorities with adequate technical, financial, and human resources, including personnel with an in-depth understanding of AI technologies.
Units could be established in government departments, regulators, cybersecurity agencies, or otherwise, depending on each Member State’s institutional structure.
Considerations
This recommendation operationalises Article 70(3) of the AI Act, which obliges Member States to provide national competent authorities with adequate technical, financial, and human resources, including personnel with an in-depth understanding of AI technologies.
Units could be established in government departments, regulators, cybersecurity agencies, or otherwise, depending on each Member State’s institutional structure.
02
Appoint senior frontier AI advisors with direct access to the head of government
02
Appoint senior frontier AI advisors with direct access to the head of government
Action
Member States should appoint a technically credible senior frontier AI advisor reporting directly to the head of government. The advisor should serve as a link between the national technical unit recommended above, ensuring that their analysis and recommendations inform strategy and agenda setting at the highest level of government. As such, they should be allowed regular briefings with the head of government and their cabinet, the ability to escalate urgent developments, and participation in high-level cabinet discussions relevant to transformative AI. The advisor should be an individual with practical expertise on frontier AI topics, for example, through working at a frontier AI provider, and should be supported by a small dedicated team.
Action
Member States should appoint a technically credible senior frontier AI advisor reporting directly to the head of government. The advisor should serve as a link between the national technical unit recommended above, ensuring that their analysis and recommendations inform strategy and agenda setting at the highest level of government. As such, they should be allowed regular briefings with the head of government and their cabinet, the ability to escalate urgent developments, and participation in high-level cabinet discussions relevant to transformative AI. The advisor should be an individual with practical expertise on frontier AI topics, for example, through working at a frontier AI provider, and should be supported by a small dedicated team.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
National executive decision to appoint a senior frontier AI advisor to the head of government.
Support team staffed partly through secondment, for example, from national research centres.
Potential first steps (next 12 months):
Q4 2026: Advisor profile defined and recruitment search launched, including nationals working in frontier labs abroad.
Q1 2027: Appointment made and support team operational.
Q2 2027: Begin regular briefings between the senior frontier AI advisor and head of government and relevant cabinet members. Establish a procedure for the advisor to escalate urgent developments.
Success indicators: Appointment made with published mandate. Briefings held per quarter. Documented technical input into national positions on issues relevant to transformative AI.
Implementation
Potential instruments:
National executive decision to appoint a senior frontier AI advisor to the head of government.
Support team staffed partly through secondment, for example, from national research centres.
Potential first steps (next 12 months):
Q4 2026: Advisor profile defined and recruitment search launched, including nationals working in frontier labs abroad.
Q1 2027: Appointment made and support team operational.
Q2 2027: Begin regular briefings between the senior frontier AI advisor and head of government and relevant cabinet members. Establish a procedure for the advisor to escalate urgent developments.
Success indicators: Appointment made with published mandate. Briefings held per quarter. Documented technical input into national positions on issues relevant to transformative AI.
Considerations
Relevant direct expertise with frontier AI should be prioritised relative to total years of experience when making appointments. Frontier AI is a new and fast-moving area, meaning that total years of experience is often uncorrelated with relevant expertise.
Considerations
Relevant direct expertise with frontier AI should be prioritised relative to total years of experience when making appointments. Frontier AI is a new and fast-moving area, meaning that total years of experience is often uncorrelated with relevant expertise.
03
Collect, analyse, and publish national statistics on AI diffusion and adoption
03
Collect, analyse, and publish national statistics on AI diffusion and adoption
Action
Member States should strengthen national measurement of AI diffusion and adoption across businesses, households, and the public sector. National statistics institutes (NSIs) should be instructed to collect and analyse data pertaining to national AI diffusion and adoption, and publish results on a regular cadence. Efforts should focus on extending coverage of existing statistics, for example, by analysing specific tasks being automated across jobs, comparing the extent of AI uptake between SMEs and larger firms, or identifying sectors or roles that are adopting AI systems the fastest. Results should be shared with other Member States on a common calendar, for example, through Eurostat.
Action
Member States should strengthen national measurement of AI diffusion and adoption across businesses, households, and the public sector. National statistics institutes (NSIs) should be instructed to collect and analyse data pertaining to national AI diffusion and adoption, and publish results on a regular cadence. Efforts should focus on extending coverage of existing statistics, for example, by analysing specific tasks being automated across jobs, comparing the extent of AI uptake between SMEs and larger firms, or identifying sectors or roles that are adopting AI systems the fastest. Results should be shared with other Member States on a common calendar, for example, through Eurostat.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
Instructing national statistics institutes to include additional AI-relevant variables or modules to existing surveys.
Existing surveys of Information and Communications Technology (ICT) use conducted through the European Statistical System, expanded to include fine-grained AI-specific variables.
Partnering with AI providers and other data holders, including through data-sharing agreements, to obtain (aggregated) statistics on AI usage.
Coordination with other Member States through Eurostat, to harmonise core variables, allowing for Europe-wide comparisons.
Potential first steps (next 12 months):
Q4 2026: NSIs identify existing gaps in existing AI adoption statistics. Agree on a common variable set through the European Statistical System.
Q1–Q2 2027: Pilot expanded measures of AI use, focusing on public-sector adoption in the first instance.
Q3 2027: Publish the results of the public-sector pilot, and share through the European Statistical System.
Indicator: Annual publication delivered. Coverage across enterprises, individuals, and the public sector. Partnerships with private-sector data holders.
Implementation
Potential instruments:
Instructing national statistics institutes to include additional AI-relevant variables or modules to existing surveys.
Existing surveys of Information and Communications Technology (ICT) use conducted through the European Statistical System, expanded to include fine-grained AI-specific variables.
Partnering with AI providers and other data holders, including through data-sharing agreements, to obtain (aggregated) statistics on AI usage.
Coordination with other Member States through Eurostat, to harmonise core variables, allowing for Europe-wide comparisons.
Potential first steps (next 12 months):
Q4 2026: NSIs identify existing gaps in existing AI adoption statistics. Agree on a common variable set through the European Statistical System.
Q1–Q2 2027: Pilot expanded measures of AI use, focusing on public-sector adoption in the first instance.
Q3 2027: Publish the results of the public-sector pilot, and share through the European Statistical System.
Indicator: Annual publication delivered. Coverage across enterprises, individuals, and the public sector. Partnerships with private-sector data holders.
Considerations
Relevant data may be collected in partnership with AI providers, such as through Google’s Activity, Task, Landscape, and Adoption Study (ATLAS) project.
Considerations
Relevant data may be collected in partnership with AI providers, such as through Google’s Activity, Task, Landscape, and Adoption Study (ATLAS) project.
04
Ensure a baseline of AI literacy across all government departments
04
Ensure a baseline of AI literacy across all government departments
Action
Member States should adopt a government-wide AI literacy programme to ensure that all civil servants are equipped with the knowledge and skills they need to understand and effectively use AI systems. The programme should be made available to staff in every department, with formats tailored to the department and seniority. For example, senior policymakers should receive short, high-quality briefings and demonstrations covering the capabilities and risks of frontier AI systems, and possible trajectories of further development. In addition, junior civil servants should receive practical training that covers how to use AI tools effectively and responsibly, with more rigorous training for staff in specialist sectors such as procurement, healthcare, or security.
Action
Member States should adopt a government-wide AI literacy programme to ensure that all civil servants are equipped with the knowledge and skills they need to understand and effectively use AI systems. The programme should be made available to staff in every department, with formats tailored to the department and seniority. For example, senior policymakers should receive short, high-quality briefings and demonstrations covering the capabilities and risks of frontier AI systems, and possible trajectories of further development. In addition, junior civil servants should receive practical training that covers how to use AI tools effectively and responsibly, with more rigorous training for staff in specialist sectors such as procurement, healthcare, or security.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instrument:
Executive decision establishing a baseline AI-literacy across government.
Department-specific training offered through ministries.
The national AI unit, recommended above, should coordinate the programme, for example, setting the syllabus and partnering with universities and research institutes to deliver specialist modules.
Potential first steps (next 12 months):
Q4 2026: Departments’ existing AI use mapped. Programme and completion targets adopted. Baseline curriculum adopted, and roles or departments requiring further specialist training identified.
Q1–Q2 2027: Senior official briefing and demonstration series delivered. Working-level modules launched.
Q3 2027: Completion rates and effectiveness statistics published per department. Curriculum updated in light of recent developments.
Indicator: Share of senior officials participating in training. Improvement on task-based assessment. Adoption and effective use of AI systems.
Implementation
Potential instrument:
Executive decision establishing a baseline AI-literacy across government.
Department-specific training offered through ministries.
The national AI unit, recommended above, should coordinate the programme, for example, setting the syllabus and partnering with universities and research institutes to deliver specialist modules.
Potential first steps (next 12 months):
Q4 2026: Departments’ existing AI use mapped. Programme and completion targets adopted. Baseline curriculum adopted, and roles or departments requiring further specialist training identified.
Q1–Q2 2027: Senior official briefing and demonstration series delivered. Working-level modules launched.
Q3 2027: Completion rates and effectiveness statistics published per department. Curriculum updated in light of recent developments.
Indicator: Share of senior officials participating in training. Improvement on task-based assessment. Adoption and effective use of AI systems.
Considerations
It is important that the curriculum covers topics, developments, and events that may have emerged shortly before the course is operational. The field of AI is advancing incredibly fast, and a curriculum that does not include developments from the preceding six months will be significantly outdated. This also means that there must be processes for iterative and continual updating of the course curriculum.
Considerations
It is important that the curriculum covers topics, developments, and events that may have emerged shortly before the course is operational. The field of AI is advancing incredibly fast, and a curriculum that does not include developments from the preceding six months will be significantly outdated. This also means that there must be processes for iterative and continual updating of the course curriculum.
IO-3
Secure Europe's share of global AI compute
IO-3
Secure Europe's share of global AI compute
Why it matters
Compute is the physical infrastructure on which all AI applications depend. In a world with transformative AI, access to AI compute will be a prerequisite to a region’s economic prosperity and national security, just like access to energy is today. Hosting this infrastructure on EU soil increases the bloc’s geopolitical weight and reduces its reliance on revocable foreign access.
Why it matters
Compute is the physical infrastructure on which all AI applications depend. In a world with transformative AI, access to AI compute will be a prerequisite to a region’s economic prosperity and national security, just like access to energy is today. Hosting this infrastructure on EU soil increases the bloc’s geopolitical weight and reduces its reliance on revocable foreign access.
Recommendations at the Union level
Recommendations at the Union level
01
Host at least 15% of global AI computing capacity by 2030
Very high
01
Host at least 15% of global AI computing capacity by 2030
Very high
02
Create a Rapid AI Infrastructure team within the European Commission
Very high
02
Create a Rapid AI Infrastructure team within the European Commission
Very high
03
Upgrade CADA’s data centre acceleration zones
Very high
03
Upgrade CADA’s data centre acceleration zones
Very high
04
Mobilise €25 billion of EU public funding for AI compute
High
04
Mobilise €25 billion of EU public funding for AI compute
High
01
Host at least 15% of global AI computing capacity by 2030
01
Host at least 15% of global AI computing capacity by 2030
Action
Set a Union-level target in the Cloud and AI Development Act (CADA) of hosting at least 15% of global AI compute on EU soil by 2030, in rough proportion to the EU’s 18% share of global GDP, currently projected at 45 GW of total facility power (against a 300 GW global capacity). Attach three obligations: (i) the Commission should adopt, and periodically update by delegated act, a methodology for estimating installed Union and global AI compute capacity, taking into account computational performance, energy-efficiency improvements and other relevant technical parameters; (ii) the Commission should publish annually the projected power capacity required for the EU to meet its 15% target on the current global compute trajectory; (iii) within six months of CADA’s entry into force, Member States should each share a national contribution plan describing their intended contributions towards the compute target. Member States should report annually on their progress, while the Commission should assess aggregate progress and, where it falls short, make recommendations to Member States on how to align national contributions with the Union-level target (following the approach of the Energy Union Governance Regulation (EU) 2018/1999).
Action
Set a Union-level target in the Cloud and AI Development Act (CADA) of hosting at least 15% of global AI compute on EU soil by 2030, in rough proportion to the EU’s 18% share of global GDP, currently projected at 45 GW of total facility power (against a 300 GW global capacity). Attach three obligations: (i) the Commission should adopt, and periodically update by delegated act, a methodology for estimating installed Union and global AI compute capacity, taking into account computational performance, energy-efficiency improvements and other relevant technical parameters; (ii) the Commission should publish annually the projected power capacity required for the EU to meet its 15% target on the current global compute trajectory; (iii) within six months of CADA’s entry into force, Member States should each share a national contribution plan describing their intended contributions towards the compute target. Member States should report annually on their progress, while the Commission should assess aggregate progress and, where it falls short, make recommendations to Member States on how to align national contributions with the Union-level target (following the approach of the Energy Union Governance Regulation (EU) 2018/1999).
Implementation
Potential instruments: Amendments to CADA (COM(2026) 502), including by adding an Annex with the plan and reporting template, updatable by delegated act.
Potential first steps (next 12 months):
October 2026: The Commission endorses the 15% target and signals support for corresponding amendments to the co-legislators.
October–November 2026: The Commission builds the measurement and forecasting capacity.
Late 2026: The 15% target is introduced into legislative negotiations through amendments in Parliament and/or Council.
Mid-2027: The European Parliament’s position and the Council’s general approach include the target.
September 2027: The Commission publishes an updated global compute capacity projection, providing the basis for a later delegated act that updates the GW figure corresponding to the 15% target.
Success indicator: share of global installed AI compute hosted on EU soil by 2030.
Implementation
Potential instruments: Amendments to CADA (COM(2026) 502), including by adding an Annex with the plan and reporting template, updatable by delegated act.
Potential first steps (next 12 months):
October 2026: The Commission endorses the 15% target and signals support for corresponding amendments to the co-legislators.
October–November 2026: The Commission builds the measurement and forecasting capacity.
Late 2026: The 15% target is introduced into legislative negotiations through amendments in Parliament and/or Council.
Mid-2027: The European Parliament’s position and the Council’s general approach include the target.
September 2027: The Commission publishes an updated global compute capacity projection, providing the basis for a later delegated act that updates the GW figure corresponding to the 15% target.
Success indicator: share of global installed AI compute hosted on EU soil by 2030.
Considerations
The target is expressed as a share rather than an absolute GW figure so that it remains meaningful under different scenarios of global AI compute growth.
The 15% target could also be inserted into the EU’s Digital Decade Policy Programme 2030, while CADA contains the binding obligations.
The definition of ‘AI compute’ should rule out general cloud capacity unsuited for AI workloads. Reports of existing AI compute capacity should only include operational AI data centres (measured as total facility power), rather than merely announced projects or sites not yet energised.
Negotiators should resist any trilogue compromise that moves the target into a non-binding recital or turns it into a mere aspiration.
Considerations
The target is expressed as a share rather than an absolute GW figure so that it remains meaningful under different scenarios of global AI compute growth.
The 15% target could also be inserted into the EU’s Digital Decade Policy Programme 2030, while CADA contains the binding obligations.
The definition of ‘AI compute’ should rule out general cloud capacity unsuited for AI workloads. Reports of existing AI compute capacity should only include operational AI data centres (measured as total facility power), rather than merely announced projects or sites not yet energised.
Negotiators should resist any trilogue compromise that moves the target into a non-binding recital or turns it into a mere aspiration.
02
Create a Rapid AI Infrastructure team within the European Commission
02
Create a Rapid AI Infrastructure team within the European Commission
Action
By 2027, establish a dedicated Commission task force mandated to steer the buildout to the 15% target. The task force should have 30–50 staff, with at least 50% external experts with relevant backgrounds (e.g. in data centre financing and development, grid engineering and emergency infrastructure planning, including experts with military logistics backgrounds). Their mandate should include setting and monitoring intermediate GW milestones, and coordinating Member State and local governments, site owners, energy companies, grid operators, investors, construction companies and AI companies to facilitate strategically important projects.
Action
By 2027, establish a dedicated Commission task force mandated to steer the buildout to the 15% target. The task force should have 30–50 staff, with at least 50% external experts with relevant backgrounds (e.g. in data centre financing and development, grid engineering and emergency infrastructure planning, including experts with military logistics backgrounds). Their mandate should include setting and monitoring intermediate GW milestones, and coordinating Member State and local governments, site owners, energy companies, grid operators, investors, construction companies and AI companies to facilitate strategically important projects.
Implementation
Potential instruments: This would be a decision about the Commission’s internal organisation; no legislation required. Industry professionals should be recruited mainly as temporary agents.
Potential first steps (next 12 months):
October 2026: The Commission announces the task force and internally fixes its mandate, the reporting line, and a sunset (e.g. 2031).
October–December 2026: The Commission recruits an operational head and relevant experts; operational core begins work.
January 2027: Core team is fully functional.
March 2027: First quarterly buildout scoreboard published internally (list of projects, GW at final investment decision, GW under construction, GW energised, major blockers).
July 2027: Full team is fully functional.
Success indicators: Number of staff in an operational task force; share of external experts with relevant backgrounds; projects under active coordination (measured in GW); measured reduction in time to power for coordinated projects versus national baselines.
Implementation
Potential instruments: This would be a decision about the Commission’s internal organisation; no legislation required. Industry professionals should be recruited mainly as temporary agents.
Potential first steps (next 12 months):
October 2026: The Commission announces the task force and internally fixes its mandate, the reporting line, and a sunset (e.g. 2031).
October–December 2026: The Commission recruits an operational head and relevant experts; operational core begins work.
January 2027: Core team is fully functional.
March 2027: First quarterly buildout scoreboard published internally (list of projects, GW at final investment decision, GW under construction, GW energised, major blockers).
July 2027: Full team is fully functional.
Success indicators: Number of staff in an operational task force; share of external experts with relevant backgrounds; projects under active coordination (measured in GW); measured reduction in time to power for coordinated projects versus national baselines.
Considerations
For the Rapid AI Infrastructure team to be successful, the Commission should take into account the recommendations on how to build technical state capacity from Immediate Objective 2.
Considerations
For the Rapid AI Infrastructure team to be successful, the Commission should take into account the recommendations on how to build technical state capacity from Immediate Objective 2.
03
Upgrade CADA's data centre acceleration zones
03
Upgrade CADA's data centre acceleration zones
Action
Increase the impact of CADA’s acceleration zone regime by anchoring it in, and extending, the EU’s existing regime for accelerating permits. Specifically: (i) grant AI data centres in acceleration zones a presumption of overriding public interest for the purposes of EU nature and water²¹ legislation, mirroring Article 16f of the Renewable Energy Directive; (ii) classify all acceleration zone projects as strategic projects under the Environmental Assessments Regulation (COM(2025) 984), following the precedent of the Industrial Accelerator Act. Specify that permits must be granted or refused within three months after receipt of complete documentation (in contrast to CADA’s proposed 12 months), with approval presumed where the deadline is missed (except where EU environmental law prohibits this); (iii) oblige Member States to issue the front-loaded ‘aggregated baseline permits’ envisaged by CADA within six months of zone designation; and (iv) turn sustainability KPIs based on the Energy Efficiency Directive into a single harmonised benchmark, barring Member States from gold-plating zone requirements.
Action
Increase the impact of CADA’s acceleration zone regime by anchoring it in, and extending, the EU’s existing regime for accelerating permits. Specifically: (i) grant AI data centres in acceleration zones a presumption of overriding public interest for the purposes of EU nature and water²¹ legislation, mirroring Article 16f of the Renewable Energy Directive; (ii) classify all acceleration zone projects as strategic projects under the Environmental Assessments Regulation (COM(2025) 984), following the precedent of the Industrial Accelerator Act. Specify that permits must be granted or refused within three months after receipt of complete documentation (in contrast to CADA’s proposed 12 months), with approval presumed where the deadline is missed (except where EU environmental law prohibits this); (iii) oblige Member States to issue the front-loaded ‘aggregated baseline permits’ envisaged by CADA within six months of zone designation; and (iv) turn sustainability KPIs based on the Energy Efficiency Directive into a single harmonised benchmark, barring Member States from gold-plating zone requirements.
Implementation
Potential instruments: Amendments to CADA (COM(2026) 502).
Potential first steps (next 12 months):
October 2026: The Commission endorses the suggested amendments and signals support to the co-legislators.
Late 2026: The amendments are tabled in the legislative negotiations in Parliament and/or Council.
Mid-to-late 2027: Trilogues open; co-legislators back the acceleration zone provisions.
Success indicators: Median time from complete application to permit for projects in acceleration zones ≤ 3 months.
Implementation
Potential instruments: Amendments to CADA (COM(2026) 502).
Potential first steps (next 12 months):
October 2026: The Commission endorses the suggested amendments and signals support to the co-legislators.
Late 2026: The amendments are tabled in the legislative negotiations in Parliament and/or Council.
Mid-to-late 2027: Trilogues open; co-legislators back the acceleration zone provisions.
Success indicators: Median time from complete application to permit for projects in acceleration zones ≤ 3 months.
Considerations
The proposed three-month permit-granting period should begin when the relevant authority receives complete documentation. However, documentation requirements for data centres may not be standardised, which could make local authorities slower at handling applications for novel projects. To address this, the co-legislators could consider measures that build on and extend existing permit acceleration regimes such as the Renewable Energy Directive (RED) III. For example, they could require that an exhaustive documentation checklist is published for each zone in advance and that documentation is deemed complete if the authority does not respond within 30 days; the authority may make a single request for further information that pauses rather than restarts the three month period.
Considerations
The proposed three-month permit-granting period should begin when the relevant authority receives complete documentation. However, documentation requirements for data centres may not be standardised, which could make local authorities slower at handling applications for novel projects. To address this, the co-legislators could consider measures that build on and extend existing permit acceleration regimes such as the Renewable Energy Directive (RED) III. For example, they could require that an exhaustive documentation checklist is published for each zone in advance and that documentation is deemed complete if the authority does not respond within 30 days; the authority may make a single request for further information that pauses rather than restarts the three month period.
04
Mobilise €25 billion of EU public funding for AI compute
04
Mobilise €25 billion of EU public funding for AI compute
Action
Commit €25 billion of EU-level public funding to the compute buildout, starting immediately through existing programmes such as InvestEU and continuing at scale under the 2028–2034 Multiannual Financial Framework (MFF). Use loan guarantees and advance purchase commitments as a demand-side backstop²² to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
Action
Commit €25 billion of EU-level public funding to the compute buildout, starting immediately through existing programmes such as InvestEU and continuing at scale under the 2028–2034 Multiannual Financial Framework (MFF). Use loan guarantees and advance purchase commitments as a demand-side backstop²² to de-risk strategically important private data centre projects and increase the share of European-only AI compute.
Implementation
Potential instruments: Until the next MFF applies, initial funding could come from the €30 billion InvestEU Fund and the European Investment Bank (EIB) Group’s TechEU programme. From 2028, additional funding could be drawn from the proposed €48.5 billion Digital Leadership budget of the Competitiveness Fund and the €405 billion cohesion budget. The EIB Group would be a natural delivery unit both for the loan guarantees and for structuring potential equity co-investments. Creating a new Important Project of Common European Interest (IPCEI) for Frontier AI Compute would provide the State-aid framework through which Member States could commit their €75 billion share.
Potential first steps (next 12 months):
Late 2026: Amendments are tabled in the negotiations on the Competitiveness Fund regulation – a potential vehicle for a minimum AI compute share in the Digital Leadership window – and on the National and Regional Partnership Plans regulation, establishing AI compute infrastructure as a priority category eligible for cohesion funding.
December 2026: Interested Member States pre-notify the IPCEI for Frontier AI Compute.
April 2027: First InvestEU-backed guarantees for AI data centre projects on the market.
September 2027: First framework for advance purchase commitments created.
Success indicators: Value of guarantees and purchase commitments signed per year; private capital mobilised per public euro; amount of GW of European-only compute at final investment decision.
Implementation
Potential instruments: Until the next MFF applies, initial funding could come from the €30 billion InvestEU Fund and the European Investment Bank (EIB) Group’s TechEU programme. From 2028, additional funding could be drawn from the proposed €48.5 billion Digital Leadership budget of the Competitiveness Fund and the €405 billion cohesion budget. The EIB Group would be a natural delivery unit both for the loan guarantees and for structuring potential equity co-investments. Creating a new Important Project of Common European Interest (IPCEI) for Frontier AI Compute would provide the State-aid framework through which Member States could commit their €75 billion share.
Potential first steps (next 12 months):
Late 2026: Amendments are tabled in the negotiations on the Competitiveness Fund regulation – a potential vehicle for a minimum AI compute share in the Digital Leadership window – and on the National and Regional Partnership Plans regulation, establishing AI compute infrastructure as a priority category eligible for cohesion funding.
December 2026: Interested Member States pre-notify the IPCEI for Frontier AI Compute.
April 2027: First InvestEU-backed guarantees for AI data centre projects on the market.
September 2027: First framework for advance purchase commitments created.
Success indicators: Value of guarantees and purchase commitments signed per year; private capital mobilised per public euro; amount of GW of European-only compute at final investment decision.
Considerations
European-only data centres are, at a minimum, located on EU soil and owned and operated by a European organisation.
Loan guarantees and purchase commitments should be reserved for projects that would not otherwise happen. They should include appropriate fees that reflect the risk taken on.
The Competitiveness Fund has been proposed but not agreed yet, and the Commission’s proposal deliberately avoids ring-fencing within its policy windows to preserve flexibility. Co-legislators should nonetheless explore legal avenues for fixing a minimum spending share for AI compute in the Digital Leadership window itself, following the precedent of thematic minimum shares in other EU programmes (e.g. Horizon Europe’s climate target). If the Digital Leadership budget shrinks in negotiations, the compute share should be defended on account of its strategic importance for European prosperity and security.
The exact allocation between loan guarantees and demand-side backstops should be set in an implementing act, as the two instruments differ in their budgetary properties.
Considerations
European-only data centres are, at a minimum, located on EU soil and owned and operated by a European organisation.
Loan guarantees and purchase commitments should be reserved for projects that would not otherwise happen. They should include appropriate fees that reflect the risk taken on.
The Competitiveness Fund has been proposed but not agreed yet, and the Commission’s proposal deliberately avoids ring-fencing within its policy windows to preserve flexibility. Co-legislators should nonetheless explore legal avenues for fixing a minimum spending share for AI compute in the Digital Leadership window itself, following the precedent of thematic minimum shares in other EU programmes (e.g. Horizon Europe’s climate target). If the Digital Leadership budget shrinks in negotiations, the compute share should be defended on account of its strategic importance for European prosperity and security.
The exact allocation between loan guarantees and demand-side backstops should be set in an implementing act, as the two instruments differ in their budgetary properties.
Recommendations at the national level
Recommendations at the national level
01
Strengthen the social contract around AI data centres
Very high
01
Strengthen the social contract around AI data centres
Very high
02
Prepare and market shovel-ready sites ahead of CADA
Very high
02
Prepare and market shovel-ready sites ahead of CADA
Very high
03
Reduce ‘time to power’ for AI data centres
Very high
03
Reduce ‘time to power’ for AI data centres
Very high
04
Accelerate planning and permitting for AI data centres
Very high
04
Accelerate planning and permitting for AI data centres
Very high
05
Mobilise €75 billion of national public funding for AI compute
High
05
Mobilise €75 billion of national public funding for AI compute
High
01
Strengthen the social contract around AI data centres
01
Strengthen the social contract around AI data centres
Action
(i) Ensure that host municipalities receive a share of the local business taxes generated by an AI data centre, allocated based on its total installed facility power, (ii) make it easy for data centre developers to invest in local community infrastructure, (iii) require large operators to bear the incremental electricity system costs of their projects rather than socialising them onto households and small businesses.
Action
(i) Ensure that host municipalities receive a share of the local business taxes generated by an AI data centre, allocated based on its total installed facility power, (ii) make it easy for data centre developers to invest in local community infrastructure, (iii) require large operators to bear the incremental electricity system costs of their projects rather than socialising them onto households and small businesses.
Member State mode
Universal.
Member State mode
Universal.
Implementation
Potential instruments: National legislation for municipal revenue-sharing and community benefits; the national regulatory authority’s network-tariff methodology for cost allocation.
Potential first steps (next 12 months):
October 2026: National regulatory authorities begin to prepare the cost-allocation methodology.
December 2026: National legislation drafted to allow community benefits and create a revenue-sharing scheme.
June 2027: National legislation is passed.
Success indicators: Share of new data centre capacity covered by community-benefit agreements; regulators verify that projects have not increased prices for local households or small businesses.
Implementation
Potential instruments: National legislation for municipal revenue-sharing and community benefits; the national regulatory authority’s network-tariff methodology for cost allocation.
Potential first steps (next 12 months):
October 2026: National regulatory authorities begin to prepare the cost-allocation methodology.
December 2026: National legislation drafted to allow community benefits and create a revenue-sharing scheme.
June 2027: National legislation is passed.
Success indicators: Share of new data centre capacity covered by community-benefit agreements; regulators verify that projects have not increased prices for local households or small businesses.
Considerations
Since AI data centres employ comparatively few people relative to invested capital, tax shares for host municipalities should be allocated based on total installed facility power rather than payroll.
Without a legislative basis, voluntary developer payments to local communities risk being classified as undue advantage under anti-corruption law.
Considerations
Since AI data centres employ comparatively few people relative to invested capital, tax shares for host municipalities should be allocated based on total installed facility power rather than payroll.
Without a legislative basis, voluntary developer payments to local communities risk being classified as undue advantage under anti-corruption law.
02
Prepare and market shovel-ready sites ahead of CADA
02
Prepare and market shovel-ready sites ahead of CADA
Action
(i) Publish, within six months and without waiting for CADA’s adoption, a national inventory of potential AI data centre sites, each with the potential for at least 100 MW fully operational capacity by 2030, including data on available construction area and grid capacity, on-site electrical infrastructure (e.g. substations), previous environmental assessments, owners and relevant stakeholders, and other relevant information.
(ii) Designate the most promising sites (or collections of sites) as data centre acceleration zones, as envisaged by CADA and the amendments in Union-level recommendation 3 above, and ideally going beyond CADA’s minimum of one per Member State.
(iii) Reach out to site owners, AI companies, data centre developers, investors, and local authorities to gauge interest in building at those sites.
Action
(i) Publish, within six months and without waiting for CADA’s adoption, a national inventory of potential AI data centre sites, each with the potential for at least 100 MW fully operational capacity by 2030, including data on available construction area and grid capacity, on-site electrical infrastructure (e.g. substations), previous environmental assessments, owners and relevant stakeholders, and other relevant information.
(ii) Designate the most promising sites (or collections of sites) as data centre acceleration zones, as envisaged by CADA and the amendments in Union-level recommendation 3 above, and ideally going beyond CADA’s minimum of one per Member State.
(iii) Reach out to site owners, AI companies, data centre developers, investors, and local authorities to gauge interest in building at those sites.
Member State mode
Collective – every Member State contributes sites.
Member State mode
Collective – every Member State contributes sites.
Implementation
Potential instruments: National legislation and administrative direction for designating acceleration zones, following the model of national renewables acceleration areas under RED III; a designated national agency acting as a single point of contact for parties interested in data centre development at the relevant sites.
Potential first steps (next 12 months):
October–December 2026: Prepare and disseminate the national inventory.
January 2027: Outreach to interested parties begins.
July 2027: Designate the first acceleration zones.
Success indicators: GW capacity of designated sites; GW capacity of listed sites with signed developer commitments.
Implementation
Potential instruments: National legislation and administrative direction for designating acceleration zones, following the model of national renewables acceleration areas under RED III; a designated national agency acting as a single point of contact for parties interested in data centre development at the relevant sites.
Potential first steps (next 12 months):
October–December 2026: Prepare and disseminate the national inventory.
January 2027: Outreach to interested parties begins.
July 2027: Designate the first acceleration zones.
Success indicators: GW capacity of designated sites; GW capacity of listed sites with signed developer commitments.
Considerations
Member States with cheap and abundant energy (e.g. France, Spain, Portugal, the Nordic countries) or repurposable industrial brownfields (e.g. Germany, Poland, Romania) should contribute disproportionately to the aggregate.
Industry experience suggests that foreign companies seeking to build AI data centres sometimes do not know about attractive sites in Member States, and successful agreements often require active matchmaking to bring the relevant stakeholders together.
Considerations
Member States with cheap and abundant energy (e.g. France, Spain, Portugal, the Nordic countries) or repurposable industrial brownfields (e.g. Germany, Poland, Romania) should contribute disproportionately to the aggregate.
Industry experience suggests that foreign companies seeking to build AI data centres sometimes do not know about attractive sites in Member States, and successful agreements often require active matchmaking to bring the relevant stakeholders together.
03
Reduce ‘time to power’ for AI data centres
03
Reduce ‘time to power’ for AI data centres
Action
Reduce the time that it takes to energise a data centre – either by connecting it to the grid or generating power on site – in order to make it fully operational. Measures include: (i) prioritising AI data centres in the grid connection queue, especially in the acceleration zones described in Union-level recommendation 3 above, (ii) facilitating Flexible Connection Agreements (FCAs) to use existing grid capacity more efficiently, (iii) accelerating permitting for power plants, transmission lines, and on-site generation, and (iv) using public procurement to support emerging power technologies such as fuel cells.
Action
Reduce the time that it takes to energise a data centre – either by connecting it to the grid or generating power on site – in order to make it fully operational. Measures include: (i) prioritising AI data centres in the grid connection queue, especially in the acceleration zones described in Union-level recommendation 3 above, (ii) facilitating Flexible Connection Agreements (FCAs) to use existing grid capacity more efficiently, (iii) accelerating permitting for power plants, transmission lines, and on-site generation, and (iv) using public procurement to support emerging power technologies such as fuel cells.
Member State mode
Universal.
Member State mode
Universal.
Implementation
Potential instruments: (i) National regulatory authority decisions or legal amendments introducing readiness- and policy-based grid connection criteria (as supported explicitly by the Commission's December 2025 grid-connection guidance). (ii) National regulatory authorities’ implementation of the EU's framework for FCAs (Article 6a of Directive (EU) 2019/944). (iii) National implementation and possibly extension of the EU permitting-acceleration regime (RED III for generation, the Grids Package and TEN-E for transmission); potentially including on-site generation within the aggregated baseline permits of data centre acceleration zones. (iv) Public tenders for backup and on-site power that explicitly invite emerging technologies such as fuel cells, using the innovation-procurement instruments of the EU public procurement directives.
Potential first steps (next 12 months):
October–December 2026: National regulatory authorities and grid operators draft queue prioritisation criteria and a national FCA template.
January 2027: First innovation-procurement tenders specifying emerging power technologies published.
April 2027: Queue criteria and FCA framework adopted.
July 2027: First FCA offers issued to zone projects.
September 2027: Accelerated permitting secured through national legislation.
Success indicators: Median time from connection application to signed connection agreement for data centre projects; MW of Flexible Connection Agreements signed.
Implementation
Potential instruments: (i) National regulatory authority decisions or legal amendments introducing readiness- and policy-based grid connection criteria (as supported explicitly by the Commission's December 2025 grid-connection guidance). (ii) National regulatory authorities’ implementation of the EU's framework for FCAs (Article 6a of Directive (EU) 2019/944). (iii) National implementation and possibly extension of the EU permitting-acceleration regime (RED III for generation, the Grids Package and TEN-E for transmission); potentially including on-site generation within the aggregated baseline permits of data centre acceleration zones. (iv) Public tenders for backup and on-site power that explicitly invite emerging technologies such as fuel cells, using the innovation-procurement instruments of the EU public procurement directives.
Potential first steps (next 12 months):
October–December 2026: National regulatory authorities and grid operators draft queue prioritisation criteria and a national FCA template.
January 2027: First innovation-procurement tenders specifying emerging power technologies published.
April 2027: Queue criteria and FCA framework adopted.
July 2027: First FCA offers issued to zone projects.
September 2027: Accelerated permitting secured through national legislation.
Success indicators: Median time from connection application to signed connection agreement for data centre projects; MW of Flexible Connection Agreements signed.
Considerations
Experts regard ‘time to power’ as the single most important factor for AI data centre developers when selecting sites. In leading data centre regions in the US, GW-scale clusters are often energised in two years or less. This is usually achieved by relying on on-site power generation or a combination of on-site and grid power.
A recent study found that Flexible Connection Agreements could unlock over 15 GW of additional AI compute by 2030 in the major European power markets (France, Germany, Iberia and the Nordics, including Norway).
Member States that decide to facilitate on-site power generation may consider capping the share of fossil fuels used (e.g. at 50% of capacity).
Considerations
Experts regard ‘time to power’ as the single most important factor for AI data centre developers when selecting sites. In leading data centre regions in the US, GW-scale clusters are often energised in two years or less. This is usually achieved by relying on on-site power generation or a combination of on-site and grid power.
A recent study found that Flexible Connection Agreements could unlock over 15 GW of additional AI compute by 2030 in the major European power markets (France, Germany, Iberia and the Nordics, including Norway).
Member States that decide to facilitate on-site power generation may consider capping the share of fossil fuels used (e.g. at 50% of capacity).
04
Accelerate planning and permitting for AI data centres
04
Accelerate planning and permitting for AI data centres
Action
Shorten the permitting process for AI data centres to a maximum of 6 months, country-wide and beyond just in the acceleration zones mentioned in Union-level recommendation 3, by (i) introducing national caps for permitting timelines, (ii) expanding the administrative capacity handling data centre applications; (iii) adopting approval-by-default where authorities miss deadlines (insofar as this is consistent with EU environmental law), (iv) allowing developers to begin (reversible) construction at their own risk while approvals are pending, and (v) repealing national requirements stricter than the relevant EU floor.
Action
Shorten the permitting process for AI data centres to a maximum of 6 months, country-wide and beyond just in the acceleration zones mentioned in Union-level recommendation 3, by (i) introducing national caps for permitting timelines, (ii) expanding the administrative capacity handling data centre applications; (iii) adopting approval-by-default where authorities miss deadlines (insofar as this is consistent with EU environmental law), (iv) allowing developers to begin (reversible) construction at their own risk while approvals are pending, and (v) repealing national requirements stricter than the relevant EU floor.
Member State mode
Universal.
Member State mode
Universal.
Implementation
Potential instruments: National permitting legislation; single points of contact to handle the entire permitting process; budget direction for administrative capacity; amendments to relevant national or sub-national laws to prevent gold-plating of EU laws.
Potential first steps (next 12 months):
October–December 2026: The responsible ministry prepares the permitting bill and accompanying amendments to sectoral law.
March 2027: The parliament passes all relevant legislation.
May 2027: Single points of contact operational; additional budget and staffing granted to permitting authorities.
September 2027: First applications successfully processed under the new regime.
Success indicator: Median duration from complete application to permit for AI data centres.
Implementation
Potential instruments: National permitting legislation; single points of contact to handle the entire permitting process; budget direction for administrative capacity; amendments to relevant national or sub-national laws to prevent gold-plating of EU laws.
Potential first steps (next 12 months):
October–December 2026: The responsible ministry prepares the permitting bill and accompanying amendments to sectoral law.
March 2027: The parliament passes all relevant legislation.
May 2027: Single points of contact operational; additional budget and staffing granted to permitting authorities.
September 2027: First applications successfully processed under the new regime.
Success indicator: Median duration from complete application to permit for AI data centres.
Considerations
In 2022, Germany passed the LNG (Liquefied Natural Gas) Acceleration Act in just 10 days to reduce dependence on Russian gas, thereby setting a precedent for how fast national legislators can act to protect a country against threats to its sovereignty and economic security.
Considerations
In 2022, Germany passed the LNG (Liquefied Natural Gas) Acceleration Act in just 10 days to reduce dependence on Russian gas, thereby setting a precedent for how fast national legislators can act to protect a country against threats to its sovereignty and economic security.
05
Mobilise €75 billion of national public funding for AI compute
05
Mobilise €75 billion of national public funding for AI compute
Action
Collectively commit €75 billion of national public funding to the compute buildout. Use loan guarantees and advance purchase commitments as a demand-side backstop to de-risk strategically important private data centre projects and increase the share of European-only AI compute. For the most sensitive use cases, such as AI workloads in national security or defence, Member States should consider direct equity investment into AI data centres alongside private sector partners to ensure that the most critical AI infrastructure is publicly co-owned.
Action
Collectively commit €75 billion of national public funding to the compute buildout. Use loan guarantees and advance purchase commitments as a demand-side backstop to de-risk strategically important private data centre projects and increase the share of European-only AI compute. For the most sensitive use cases, such as AI workloads in national security or defence, Member States should consider direct equity investment into AI data centres alongside private sector partners to ensure that the most critical AI infrastructure is publicly co-owned.
Member State mode
Collective – every Member State contributes, scaled by economic weight.
Member State mode
Collective – every Member State contributes, scaled by economic weight.
Implementation
Potential instruments: National budget commitments and promotional banks, coordinated through a novel IPCEI for Frontier Compute.
Potential first steps (next 12 months):
October–January 2026: Member States agree on individual IPCEI contributions and open pre-notification talks with the Commission.
March 2027: National budget lines and promotional bank mandates adopted; promotional banks design the loan guarantees and advance purchase commitments.
May 2027: First loan-guarantee products for AI data centre projects on the market.
September 2027: First loan guarantees/advance purchase commitments signed.
Success indicators: Amount committed in national budgets; amount of GW of European-only compute at final investment decision.
Implementation
Potential instruments: National budget commitments and promotional banks, coordinated through a novel IPCEI for Frontier Compute.
Potential first steps (next 12 months):
October–January 2026: Member States agree on individual IPCEI contributions and open pre-notification talks with the Commission.
March 2027: National budget lines and promotional bank mandates adopted; promotional banks design the loan guarantees and advance purchase commitments.
May 2027: First loan-guarantee products for AI data centre projects on the market.
September 2027: First loan guarantees/advance purchase commitments signed.
Success indicators: Amount committed in national budgets; amount of GW of European-only compute at final investment decision.
Considerations
European-only data centres are, at a minimum, located on EU soil and owned and operated by a European organisation.
Loan guarantees and purchase commitments should be reserved for projects that would not otherwise happen. They should include appropriate fees that reflect the risk taken on
Considerations
European-only data centres are, at a minimum, located on EU soil and owned and operated by a European organisation.
Loan guarantees and purchase commitments should be reserved for projects that would not otherwise happen. They should include appropriate fees that reflect the risk taken on
IO-4
Ensure resilience to AI crises
IO-4
Ensure resilience to AI crises
Why it matters
Transformative AI poses severe risks to Europe, its citizens, and its institutions. Many of these risks cannot be fully managed upstream by Europe. As such, Europe should aim to bolster its resilience to risks from transformative AI – that is, its capacity to resist, absorb, recover from, and adapt to risks should they occur.
Why it matters
Transformative AI poses severe risks to Europe, its citizens, and its institutions. Many of these risks cannot be fully managed upstream by Europe. As such, Europe should aim to bolster its resilience to risks from transformative AI – that is, its capacity to resist, absorb, recover from, and adapt to risks should they occur.
Recommendations at the Union level
Recommendations at the Union level
01
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans
Very high
01
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans
Very high
02
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents
High
02
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents
High
03
Strengthen cooperation between AI expertise and national security and intelligence authorities
High
03
Strengthen cooperation between AI expertise and national security and intelligence authorities
High
04
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures
High
04
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures
High
01
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans
01
Implement the Action Plan on Cybersecurity and Artificial Intelligence and develop corresponding CBRN and loss of control action plans
Action
With the Action Plan on Cybersecurity and Artificial Intelligence, Europe has established promising foundations for improving cyber-resilience as AI systems become more capable. The Commission should translate the Action Plan’s commitments into operational measures through adequate funding, clear institutional ownership, and defined deadlines. In particular, the Plan’s blueprint for structured access to advanced AI capabilities for cybersecurity should be converted into operational access arrangements before such access becomes urgently necessary. In parallel, the Commission should publish corresponding plans for chemical, biological, radiological, and nuclear (CBRN) and loss of control risks.
Potential concrete actions to include in the Action Plan on CBRN-security and AI could include: updating the legal limit for workplace exposure to UV (currently fixed in Directive 2006/25/EC) to enable controlled trial deployments of higher doses of far-UVC for antiviral filtering in hospitals; and increasing the number of sites covered by the Directorate-General for Health Emergency Preparedness and Response Authority (DG HERA) and the JRC’s ongoing wastewater monitoring initiatives to provide a more comprehensive monitoring system for harmful pathogens in water systems. These initiatives could also be extended to include detection of AI-engineered pathogens through metagenomic sequencing of samples. The Action Plan could also consider actions for preventing the misuse of specialised AI tools, designed specifically for aiding biological or chemical research, such as Evo 2, a genome-modelling AI model that has been shown to be able to generate coherent, genome-length DNA sequences. Finally, it could lay out a plan for coordinating emergency response to AI-enabled CBRN incidents at the Union level, complementing national emergency preparedness plans (see national recommendation 4 below).
The content of an AI Loss of Control Action Plan would likely have to change as our understanding of the risks (and how to assess and mitigate them) evolves. An AI Loss of Control Action Plan could include a reaffirmation of Commission’s intention to use its enforcement powers to incentivise providers of general-purpose models with systemic risks to assess and mitigate loss of control risks, and to conduct its own loss of control model evaluations (or contract them to a third party). Key example mitigations could be preserving chain-of-thought monitorability, having in place scalable and comprehensive monitoring of internally deployed agents, and ensuring that reward learning techniques used do not result in misalignment. Additionally, it could lay out a plan to improve emergency preparedness by bolstering Europe’s detection, containment, response, and resilience capabilities²³ and ensuring sufficient funding is mobilised to improve them. For example, this could be achieved by monitoring for unauthorised autonomous AI agents across EU-regulated critical and government infrastructure, implementing sandbox and isolation standards for AI evaluations conducted in the EU, ensuring sufficient human expert reserve capacity for dealing with crises, and establishing trusted back-up models and non-AI fallbacks for essential functions across government and critical infrastructure. Finally, the Action Plan could catalyse initiatives to build understanding of loss of control risks and the technologies needed to enable oversight and governance, this could include (a) building EU loss of control evaluation and incident investigation capacity, (b) making concerted efforts to build assurance technologies (Immediate Objective 5) to also help with international coordination, (c) building structured access and secure evaluation infrastructure, (d) advancing standards and technology for agent identification, logging, and attribution. The Action Plan should consider how such innovations and capacity building could best be incentivised.
Action
With the Action Plan on Cybersecurity and Artificial Intelligence, Europe has established promising foundations for improving cyber-resilience as AI systems become more capable. The Commission should translate the Action Plan’s commitments into operational measures through adequate funding, clear institutional ownership, and defined deadlines. In particular, the Plan’s blueprint for structured access to advanced AI capabilities for cybersecurity should be converted into operational access arrangements before such access becomes urgently necessary. In parallel, the Commission should publish corresponding plans for chemical, biological, radiological, and nuclear (CBRN) and loss of control risks.
Potential concrete actions to include in the Action Plan on CBRN-security and AI could include: updating the legal limit for workplace exposure to UV (currently fixed in Directive 2006/25/EC) to enable controlled trial deployments of higher doses of far-UVC for antiviral filtering in hospitals; and increasing the number of sites covered by the Directorate-General for Health Emergency Preparedness and Response Authority (DG HERA) and the JRC’s ongoing wastewater monitoring initiatives to provide a more comprehensive monitoring system for harmful pathogens in water systems. These initiatives could also be extended to include detection of AI-engineered pathogens through metagenomic sequencing of samples. The Action Plan could also consider actions for preventing the misuse of specialised AI tools, designed specifically for aiding biological or chemical research, such as Evo 2, a genome-modelling AI model that has been shown to be able to generate coherent, genome-length DNA sequences. Finally, it could lay out a plan for coordinating emergency response to AI-enabled CBRN incidents at the Union level, complementing national emergency preparedness plans (see national recommendation 4 below).
The content of an AI Loss of Control Action Plan would likely have to change as our understanding of the risks (and how to assess and mitigate them) evolves. An AI Loss of Control Action Plan could include a reaffirmation of Commission’s intention to use its enforcement powers to incentivise providers of general-purpose models with systemic risks to assess and mitigate loss of control risks, and to conduct its own loss of control model evaluations (or contract them to a third party). Key example mitigations could be preserving chain-of-thought monitorability, having in place scalable and comprehensive monitoring of internally deployed agents, and ensuring that reward learning techniques used do not result in misalignment. Additionally, it could lay out a plan to improve emergency preparedness by bolstering Europe’s detection, containment, response, and resilience capabilities²³ and ensuring sufficient funding is mobilised to improve them. For example, this could be achieved by monitoring for unauthorised autonomous AI agents across EU-regulated critical and government infrastructure, implementing sandbox and isolation standards for AI evaluations conducted in the EU, ensuring sufficient human expert reserve capacity for dealing with crises, and establishing trusted back-up models and non-AI fallbacks for essential functions across government and critical infrastructure. Finally, the Action Plan could catalyse initiatives to build understanding of loss of control risks and the technologies needed to enable oversight and governance, this could include (a) building EU loss of control evaluation and incident investigation capacity, (b) making concerted efforts to build assurance technologies (Immediate Objective 5) to also help with international coordination, (c) building structured access and secure evaluation infrastructure, (d) advancing standards and technology for agent identification, logging, and attribution. The Action Plan should consider how such innovations and capacity building could best be incentivised.
Implementation
Potential instruments:
Executive support in the form of funding and operational guidance to ENISA, Member States, and other relevant Union entities for effectively implementing the Action Plan on Cybersecurity and AI.
Implementing parts of these Action Plans will require diplomatic negotiation, for example to secure access to frontier-level systems, as is likely to be set out in the European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes, commissioned in the Action Plan on Cybersecurity and AI.
Executive action to publish Action Plans on (1) CBRN-security and Artificial Intelligence, (2) AI Loss of Control, inspired by the existing Action Plan on Cybersecurity and AI.
Potential first steps (next 12 months):
Q4 2026: Drafting begins on the Action Plans on CBRN-security and AI and AI Loss of Control.
By Q1 2027: Action Plan on CBRN-security and AI published. The European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes begins to be implemented.
By Q3 2027: Action Plan on AI Loss of Control published. Action Plan on CBRN-security and AI implemented.
By Q1 2028: Action Plan on AI Loss of Control implemented.
Success indicators: Publication of the European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes. Publication of an Action Plan on CBRN-security and AI.
Implementation
Potential instruments:
Executive support in the form of funding and operational guidance to ENISA, Member States, and other relevant Union entities for effectively implementing the Action Plan on Cybersecurity and AI.
Implementing parts of these Action Plans will require diplomatic negotiation, for example to secure access to frontier-level systems, as is likely to be set out in the European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes, commissioned in the Action Plan on Cybersecurity and AI.
Executive action to publish Action Plans on (1) CBRN-security and Artificial Intelligence, (2) AI Loss of Control, inspired by the existing Action Plan on Cybersecurity and AI.
Potential first steps (next 12 months):
Q4 2026: Drafting begins on the Action Plans on CBRN-security and AI and AI Loss of Control.
By Q1 2027: Action Plan on CBRN-security and AI published. The European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes begins to be implemented.
By Q3 2027: Action Plan on AI Loss of Control published. Action Plan on CBRN-security and AI implemented.
By Q1 2028: Action Plan on AI Loss of Control implemented.
Success indicators: Publication of the European Blueprint for structured access to advanced AI capabilities for cybersecurity purposes. Publication of an Action Plan on CBRN-security and AI.
Considerations
A model may be created with biological design capabilities that prompt a tightly restricted release, of the kind observed for Anthropic’s Mythos with respect to offensive cyber capabilities. Europe should implement personal protective equipment stockpiling, screening infrastructure, and response plans for advanced biocapabilities in advance of such a model.
The implementation timeline above shows publication of the loss of control action plan after the action plan on CBRN and AI, due to additional research required to determine the contents of the plan and the fact that the first incidents that may qualify as loss of control have only recently been reported. This means that experts’ understanding of both the risk and how to mitigate it are still evolving. However, if loss of control risks increase more rapidly, the timeline would have to be accelerated to avoid potentially catastrophic outcomes.
Considerations
A model may be created with biological design capabilities that prompt a tightly restricted release, of the kind observed for Anthropic’s Mythos with respect to offensive cyber capabilities. Europe should implement personal protective equipment stockpiling, screening infrastructure, and response plans for advanced biocapabilities in advance of such a model.
The implementation timeline above shows publication of the loss of control action plan after the action plan on CBRN and AI, due to additional research required to determine the contents of the plan and the fact that the first incidents that may qualify as loss of control have only recently been reported. This means that experts’ understanding of both the risk and how to mitigate it are still evolving. However, if loss of control risks increase more rapidly, the timeline would have to be accelerated to avoid potentially catastrophic outcomes.
02
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents
02
Establish a channel for providers and affected parties to voluntarily notify the AI Office of AI incidents
Action
The Commission should establish a channel through which a team within the AI Office can be notified of relevant occurrences that do not qualify as ‘serious incidents’ under Article 3(49) of the AI Act. The channel should be made available through an online tool accessible to the public so that notifications can be made by affected parties (including both individuals and businesses) and providers. Given the potential for multiple interpretations of ‘serious incident’ as used in Article 55(1)(c) of the AI Act, the Commission should clarify that this channel may be used for notifying the AI Office of incidents that the notifier may nonetheless believe do not meet the legal definition of ‘serious incident’ in the AI Act. Where deemed instructive, the AI Office may conduct more thorough assessments of the incidents to which they are notified, as a way of informing the Commission's broader strategy for responding to AI incidents and improving the AI Office’s regulatory expertise. The assessments and any potential follow-up actions would be conducted by the AI Office pursuant to its general monitoring and supervision powers under the AI Act and would not necessarily amount to a formal investigation.
Action
The Commission should establish a channel through which a team within the AI Office can be notified of relevant occurrences that do not qualify as ‘serious incidents’ under Article 3(49) of the AI Act. The channel should be made available through an online tool accessible to the public so that notifications can be made by affected parties (including both individuals and businesses) and providers. Given the potential for multiple interpretations of ‘serious incident’ as used in Article 55(1)(c) of the AI Act, the Commission should clarify that this channel may be used for notifying the AI Office of incidents that the notifier may nonetheless believe do not meet the legal definition of ‘serious incident’ in the AI Act. Where deemed instructive, the AI Office may conduct more thorough assessments of the incidents to which they are notified, as a way of informing the Commission's broader strategy for responding to AI incidents and improving the AI Office’s regulatory expertise. The assessments and any potential follow-up actions would be conducted by the AI Office pursuant to its general monitoring and supervision powers under the AI Act and would not necessarily amount to a formal investigation.
Implementation
Potential instruments:
No legal instruments are required to establish and announce a voluntary notification channel.
The Commission could issue guidance clarifying that incidents do not need to meet the AI Act’s definition of ‘serious incident’ (Article 3(49)) to be eligible for notification.
Potential first steps (next 12 months):
Q4 2026: Notification channel announced and published on Commission website alongside communications clarifying the purpose and legal scope.
Q1 2027: AI Office notified of first incidents through the channel. First assessments begin.
Success indicators: Number of substantive notifications, previously unknown to the AI Office. Outcomes and recommendations from subsequent assessments.
Implementation
Potential instruments:
No legal instruments are required to establish and announce a voluntary notification channel.
The Commission could issue guidance clarifying that incidents do not need to meet the AI Act’s definition of ‘serious incident’ (Article 3(49)) to be eligible for notification.
Potential first steps (next 12 months):
Q4 2026: Notification channel announced and published on Commission website alongside communications clarifying the purpose and legal scope.
Q1 2027: AI Office notified of first incidents through the channel. First assessments begin.
Success indicators: Number of substantive notifications, previously unknown to the AI Office. Outcomes and recommendations from subsequent assessments.
Considerations
The AI Office should stress that notification of an AI incident will in no way be treated as an admission of wrongdoing, in line with Recital (j) of the Safety and Security Chapter of the General-Purpose AI (GPAI) Code of Practice. Proactive notifications from providers should be seen in a positive light, and be taken into account by the AI Office when dealing with providers, in line with Articles 99(7)(h) and 101 of the AI Act.
The AI Office should have a standing team for triaging and assessing notifications of incidents received through this voluntary channel so as not to reduce the AI Office’s capacity in other areas.
Considerations
The AI Office should stress that notification of an AI incident will in no way be treated as an admission of wrongdoing, in line with Recital (j) of the Safety and Security Chapter of the General-Purpose AI (GPAI) Code of Practice. Proactive notifications from providers should be seen in a positive light, and be taken into account by the AI Office when dealing with providers, in line with Articles 99(7)(h) and 101 of the AI Act.
The AI Office should have a standing team for triaging and assessing notifications of incidents received through this voluntary channel so as not to reduce the AI Office’s capacity in other areas.
03
Strengthen cooperation between AI expertise and national security and intelligence authorities.
03
Strengthen cooperation between AI expertise and national security and intelligence authorities.
Action
The Commission should establish standing working channels between the EU AI Office, Member State AISIs (see Immediate Objective 2), and security and intelligence services, since each will hold information and expertise that the others need but lack. These collaborations should be governed by an agreed protocol for handling classified and commercially sensitive material. This collaboration should work to produce joint threat assessments of AI-enabled threats covering offensive cyber, CBRN, harmful manipulation, and loss of control. This ensures that Europe’s intelligence communities have access to subject-matter AI expertise when analysing potential national security threats.
Action
The Commission should establish standing working channels between the EU AI Office, Member State AISIs (see Immediate Objective 2), and security and intelligence services, since each will hold information and expertise that the others need but lack. These collaborations should be governed by an agreed protocol for handling classified and commercially sensitive material. This collaboration should work to produce joint threat assessments of AI-enabled threats covering offensive cyber, CBRN, harmful manipulation, and loss of control. This ensures that Europe’s intelligence communities have access to subject-matter AI expertise when analysing potential national security threats.
Implementation
Potential instruments:
Include provisions for information exchange and joint threat modelling and assessment exercises between the EU AI Office and Europol in the proposed Regulation on Europol COM(2026) 580.
The Cybersecurity Act II (COM(2026) 11) proposes closer Europol–ENISA cooperation on ransomware preparedness and response, providing a precedent to build on.
Collaborations with individual Member States’ intelligence organisations should be negotiated individually based on a shared template.
Potential first steps (next 12 months):
Q4 2026: The EU AI Office and DG HOME agree on mutual points of contact. Amendments to the proposed Regulation on Europol (COM(2026) 580) are proposed by parliament.
Q1 2027: The AI Office, DG HOME, and national intelligence agencies draft a protocol for handling classified and commercially sensitive material, drawing on existing Commission security rules.
Q3 2027: The first joint threat assessment is drawn up by the EU AI Office and at least one national security service.
Success indicators: A signed handling protocol exists by Q2 2027. At least two joint exercises, such as threat assessments or gap analyses, are completed by the end of 2027.
Implementation
Potential instruments:
Include provisions for information exchange and joint threat modelling and assessment exercises between the EU AI Office and Europol in the proposed Regulation on Europol COM(2026) 580.
The Cybersecurity Act II (COM(2026) 11) proposes closer Europol–ENISA cooperation on ransomware preparedness and response, providing a precedent to build on.
Collaborations with individual Member States’ intelligence organisations should be negotiated individually based on a shared template.
Potential first steps (next 12 months):
Q4 2026: The EU AI Office and DG HOME agree on mutual points of contact. Amendments to the proposed Regulation on Europol (COM(2026) 580) are proposed by parliament.
Q1 2027: The AI Office, DG HOME, and national intelligence agencies draft a protocol for handling classified and commercially sensitive material, drawing on existing Commission security rules.
Q3 2027: The first joint threat assessment is drawn up by the EU AI Office and at least one national security service.
Success indicators: A signed handling protocol exists by Q2 2027. At least two joint exercises, such as threat assessments or gap analyses, are completed by the end of 2027.
Considerations
Since national security is the exclusive responsibility of each Member State under the EU treaties, many elements of collaboration will be voluntary. This includes the shared channels, agreed protocols, and joint assessments.
Appropriate confidentiality must be maintained on both sides of collaborations. Security services will not share intelligence that could reach commercial parties, and AI providers will be hesitant to share model details with the AI Office if they believe there is a chance that they will be accessible to parties other than the AI Office. Confidentiality agreements should remain in line with Article 78 of the AI Act.
Considerations
Since national security is the exclusive responsibility of each Member State under the EU treaties, many elements of collaboration will be voluntary. This includes the shared channels, agreed protocols, and joint assessments.
Appropriate confidentiality must be maintained on both sides of collaborations. Security services will not share intelligence that could reach commercial parties, and AI providers will be hesitant to share model details with the AI Office if they believe there is a chance that they will be accessible to parties other than the AI Office. Confidentiality agreements should remain in line with Article 78 of the AI Act.
04
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures
04
Establish a cross-programme European AI preparedness and resilience package in the 2028–2034 Multiannual Financial Framework and allow existing funds to be used for AI resilience measures
Action
To ensure AI preparedness and resilience across the European bloc, the Commission should propose a cross-programme package totalling €10 billion within the 2028–2034 Multiannual Financial Framework (MFF) spending plan for AI-specific preparedness and resilience. The proposal for the 2028–2034 MFF includes multiple funding sources for preparedness and resilience. This includes the proposed COM(2025) 565, which reserves a quarter of Member States’ contributions to the budget for responding to crises; the proposed COM(2025) 548, which would establish a Crisis Coordination Hub; and the European Competitiveness Fund (COM(2025) 555), a €234 billion fund within the MFF to support strategic technologies, innovation, and industrial capacity. Member States should be able to draw on this package to implement measures addressing systemic AI risks including CBRN (Chemical, Biological, Radiological, and Nuclear) threats, cyber offence, loss of control, and harmful manipulation. Ahead of the next MFF's entry into force in 2028, the Commission should clarify that existing funding programmes can be used to fund AI-specific resilience measures. For example, Digital Europe could be used to fund AI-enabled cyberdefence for essential entities, rescEU could fund Personal Protective Equipment (PPE) stockpiling, and EU4Health could fund expanded wastewater monitoring.
Action
To ensure AI preparedness and resilience across the European bloc, the Commission should propose a cross-programme package totalling €10 billion within the 2028–2034 Multiannual Financial Framework (MFF) spending plan for AI-specific preparedness and resilience. The proposal for the 2028–2034 MFF includes multiple funding sources for preparedness and resilience. This includes the proposed COM(2025) 565, which reserves a quarter of Member States’ contributions to the budget for responding to crises; the proposed COM(2025) 548, which would establish a Crisis Coordination Hub; and the European Competitiveness Fund (COM(2025) 555), a €234 billion fund within the MFF to support strategic technologies, innovation, and industrial capacity. Member States should be able to draw on this package to implement measures addressing systemic AI risks including CBRN (Chemical, Biological, Radiological, and Nuclear) threats, cyber offence, loss of control, and harmful manipulation. Ahead of the next MFF's entry into force in 2028, the Commission should clarify that existing funding programmes can be used to fund AI-specific resilience measures. For example, Digital Europe could be used to fund AI-enabled cyberdefence for essential entities, rescEU could fund Personal Protective Equipment (PPE) stockpiling, and EU4Health could fund expanded wastewater monitoring.
Implementation
Potential instruments:
The Commission should publish coordinated guidance identifying for Member States which AI-preparedness measures are eligible for reimbursement under Digital Europe, EU4Health, and the Union Civil Protection Mechanism. Funds from the EU Cybersecurity Reserve should be used to respond to qualifying AI-enabled cyber incidents. Non-cyber AI incidents should be addressed through the Union Civil Protection Mechanism and the EU's HERA.
The Commission should amend COM(2025) 548 to require Member States to address AI-enabled and AI-amplified incidents in national risk assessments and planning. It should also address Union-level risk reporting, scenarios, and capacity-gap analysis under Articles 14–16.
The Commission should amend COM(2025) 565 to add AI-enabled incident preparedness as an eligible investment for Member States. It should also establish a spending floor for AI-preparedness initiatives. It should make reserved funds from the unprogrammed share available at the 2031 mid-term review for AI risks that materialise faster than planned.
The European Competitiveness Fund's Resilience and Security window, its Health, Biotechnology, Agriculture, and Bioeconomy window, and its Digital Leadership window should explicitly cover industrial capacities related to synthesis screening, DNA sequencing, and AI-based cyberdefence tools.
Potential first steps (next 12 months):
Q4 2026: The Commission tables the €10 billion package as its position in the MFF and programme negotiations; Parliament and Council positions reflect it by mid‑2027. The Commission clarifies the eligibility of existing funds and instruments for financing national AI-specific resilience before the 2028–2034 MFF takes effect.
Q2 2027: During final negotiations, the Commission defines a clear division of scope between the European Competitiveness Fund, COM(2025) 548, and COM(2025) 565.
Q4 2027: The Commission’s rules, work programmes, and eligibility guidance are finalised ahead of January 2028.
Success indicators: Guidance published by Q1 2027, with at least 15 Member States drawing on civil preparedness money for AI-related resilience work by the end of 2027. The Competitiveness Fund's Resilience and Security window dedicates a minimum share for civil preparedness capacities within the binding text. COM(2025) 548 and COM(2025) 565, as adopted, name AI-enabled incidents among the hazards in scope, specify a spending floor for AI-threat preparedness, and allocate dedicated funds for novel threats.
Implementation
Potential instruments:
The Commission should publish coordinated guidance identifying for Member States which AI-preparedness measures are eligible for reimbursement under Digital Europe, EU4Health, and the Union Civil Protection Mechanism. Funds from the EU Cybersecurity Reserve should be used to respond to qualifying AI-enabled cyber incidents. Non-cyber AI incidents should be addressed through the Union Civil Protection Mechanism and the EU's HERA.
The Commission should amend COM(2025) 548 to require Member States to address AI-enabled and AI-amplified incidents in national risk assessments and planning. It should also address Union-level risk reporting, scenarios, and capacity-gap analysis under Articles 14–16.
The Commission should amend COM(2025) 565 to add AI-enabled incident preparedness as an eligible investment for Member States. It should also establish a spending floor for AI-preparedness initiatives. It should make reserved funds from the unprogrammed share available at the 2031 mid-term review for AI risks that materialise faster than planned.
The European Competitiveness Fund's Resilience and Security window, its Health, Biotechnology, Agriculture, and Bioeconomy window, and its Digital Leadership window should explicitly cover industrial capacities related to synthesis screening, DNA sequencing, and AI-based cyberdefence tools.
Potential first steps (next 12 months):
Q4 2026: The Commission tables the €10 billion package as its position in the MFF and programme negotiations; Parliament and Council positions reflect it by mid‑2027. The Commission clarifies the eligibility of existing funds and instruments for financing national AI-specific resilience before the 2028–2034 MFF takes effect.
Q2 2027: During final negotiations, the Commission defines a clear division of scope between the European Competitiveness Fund, COM(2025) 548, and COM(2025) 565.
Q4 2027: The Commission’s rules, work programmes, and eligibility guidance are finalised ahead of January 2028.
Success indicators: Guidance published by Q1 2027, with at least 15 Member States drawing on civil preparedness money for AI-related resilience work by the end of 2027. The Competitiveness Fund's Resilience and Security window dedicates a minimum share for civil preparedness capacities within the binding text. COM(2025) 548 and COM(2025) 565, as adopted, name AI-enabled incidents among the hazards in scope, specify a spending floor for AI-threat preparedness, and allocate dedicated funds for novel threats.
Considerations
Civil resilience should be funded separately from defence. The European Competitiveness Fund also includes €131 billion proposed for defence and space. Without a guaranteed minimum written into the law, civil preparedness would be at risk of deprioritisation relative to other funding targets.
At least 60% of the €10 billion allocation should flow through national and regional partnership plans: This funding should be allocated by a published formula to ensure it reaches Member States equitably rather than through a competitive bidding process.
Collective AI-specific resilience funding is split across three instruments due to sector-specific scopes. The European Competitiveness Fund focuses on technology and industrial capacity, COM(2025) 548 focuses on operational preparedness, and COM(2025) 565 is for national resilience investments.
Considerations
Civil resilience should be funded separately from defence. The European Competitiveness Fund also includes €131 billion proposed for defence and space. Without a guaranteed minimum written into the law, civil preparedness would be at risk of deprioritisation relative to other funding targets.
At least 60% of the €10 billion allocation should flow through national and regional partnership plans: This funding should be allocated by a published formula to ensure it reaches Member States equitably rather than through a competitive bidding process.
Collective AI-specific resilience funding is split across three instruments due to sector-specific scopes. The European Competitiveness Fund focuses on technology and industrial capacity, COM(2025) 548 focuses on operational preparedness, and COM(2025) 565 is for national resilience investments.
Recommendations at the national level
Recommendations at the national level
01
Strengthen the biosecurity provisions in the EU Biotech Act
High
01
Strengthen the biosecurity provisions in the EU Biotech Act
High
02
Build up reserves of resources and equipment necessary for responding to crises
Very high
02
Build up reserves of resources and equipment necessary for responding to crises
Very high
03
Strengthen critical national infrastructure against AI-enabled cyberattacks
Very high
03
Strengthen critical national infrastructure against AI-enabled cyberattacks
Very high
04
Include AI-enabled incidents in national and sector-specific emergency response plans
High
04
Include AI-enabled incidents in national and sector-specific emergency response plans
High
01
Strengthen the biosecurity provisions in the EU Biotech Act.
01
Strengthen the biosecurity provisions in the EU Biotech Act.
Action
Member States should push for more ambitious biosecurity provisions to be included in the EU Biotech Act during trilogue negotiations. Proposed amendments should include provisions for increasing security and resilience against AI-mediated biological risks, for example, by ensuring that the list of products in scope of KYC provisions can be updated rapidly in the case of a novel AI-generated pathogen being detected. More general strengthening provisions could include providing legal safe-harbour for trusted third parties to test for weaknesses in synthesis screening measures (for example, under Article 50, concerning audits of screening mechanisms). Article 53, concerning biological systemic risk from AI models, could be developed, for example to specify potential ‘appropriate measures to ensure a proper control of risks’ that can be taken by the Commission and Member States.
Action
Member States should push for more ambitious biosecurity provisions to be included in the EU Biotech Act during trilogue negotiations. Proposed amendments should include provisions for increasing security and resilience against AI-mediated biological risks, for example, by ensuring that the list of products in scope of KYC provisions can be updated rapidly in the case of a novel AI-generated pathogen being detected. More general strengthening provisions could include providing legal safe-harbour for trusted third parties to test for weaknesses in synthesis screening measures (for example, under Article 50, concerning audits of screening mechanisms). Article 53, concerning biological systemic risk from AI models, could be developed, for example to specify potential ‘appropriate measures to ensure a proper control of risks’ that can be taken by the Commission and Member States.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
Support robust measures in the EU Biotech Act chapter on biosecurity. Table amendments that strengthen the Act’s biosecurity chapter, such as processes for rapidly adding to the list of products of concern, so that screening can keep pace with rapidly emerging AI-designed sequences.
Convene key industry players and collaborate (e.g. through MoUs) to voluntarily implement synthesis screening and KYC controls on dangerous viruses, based on the proposed contents of the Biotech Act.
Designate, resource, and fund National Competent Authorities (NCAs) through national implementing acts.
Potential first steps (next 12 months):
Q4 2026: Table amendments to uphold strong biosecurity provisions during the trilogue.
Q1 2027: Consult with national industry and academia on potential voluntary implementation of synthesis screening and support its uptake ahead of the Biotech Act’s expected passing.
Success indicators: Biotech Act passed with strong biosecurity provisions in place.
Implementation
Potential instruments:
Support robust measures in the EU Biotech Act chapter on biosecurity. Table amendments that strengthen the Act’s biosecurity chapter, such as processes for rapidly adding to the list of products of concern, so that screening can keep pace with rapidly emerging AI-designed sequences.
Convene key industry players and collaborate (e.g. through MoUs) to voluntarily implement synthesis screening and KYC controls on dangerous viruses, based on the proposed contents of the Biotech Act.
Designate, resource, and fund National Competent Authorities (NCAs) through national implementing acts.
Potential first steps (next 12 months):
Q4 2026: Table amendments to uphold strong biosecurity provisions during the trilogue.
Q1 2027: Consult with national industry and academia on potential voluntary implementation of synthesis screening and support its uptake ahead of the Biotech Act’s expected passing.
Success indicators: Biotech Act passed with strong biosecurity provisions in place.
Considerations
For biosecurity provisions to be effective, they must be adequately enforced by national competent authorities. NCAs should thus be adequately resourced to ensure effective enforcement.
The bio-relevant capabilities of frontier AI systems are advancing rapidly, and it may be many years before the EU Biotech Act is implemented. Member States should therefore aim to bridge this gap by introducing harmonised frameworks that can be built on after the Act’s passing.
Synthesis screening must be robustly implemented in all Member States to be effective. Weak implementation in one jurisdiction significantly impacts the regime as a whole.
Considerations
For biosecurity provisions to be effective, they must be adequately enforced by national competent authorities. NCAs should thus be adequately resourced to ensure effective enforcement.
The bio-relevant capabilities of frontier AI systems are advancing rapidly, and it may be many years before the EU Biotech Act is implemented. Member States should therefore aim to bridge this gap by introducing harmonised frameworks that can be built on after the Act’s passing.
Synthesis screening must be robustly implemented in all Member States to be effective. Weak implementation in one jurisdiction significantly impacts the regime as a whole.
02
Build up reserves of resources and equipment necessary for responding to crises.
02
Build up reserves of resources and equipment necessary for responding to crises.
Action
Member States should identify and procure physical resources that would be scarce, slow to replace, or geographically concentrated in times of crisis. For example, Member States should establish protective equipment stockpiles sufficient for handling pandemics at least as significant as COVID-19. Member States should conduct supply chain criticality assessments and tabletop exercises to identify vulnerabilities in the supply chains for equipment that is critical for telecommunications, energy grids and emergency response; and proactively build stockpiles in case those supply chains are disrupted.
Action
Member States should identify and procure physical resources that would be scarce, slow to replace, or geographically concentrated in times of crisis. For example, Member States should establish protective equipment stockpiles sufficient for handling pandemics at least as significant as COVID-19. Member States should conduct supply chain criticality assessments and tabletop exercises to identify vulnerabilities in the supply chains for equipment that is critical for telecommunications, energy grids and emergency response; and proactively build stockpiles in case those supply chains are disrupted.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
A multiannual national budget line for the recurring cost of rotating stockpiles of consumables (PPE, pharmaceuticals, fuel).
A procurement framework including rotation clauses.
Implement a minimum-spares obligation on designated critical entities through national Critical Entities Resilience (CER) Directive transposition.
Potential first steps (next 12 months):
Q4 2026: Designate a centralised national stockpiling authority and register with the EU stockpiling network. Conduct a review of current stockpiles.
Q1 2027: Conduct supply-chain criticality assessments for entities identified under the CER directive. Sign PPE framework contracts, including health-service rotation clauses.
Success indicators:
Population coverage x days of supply for PPE.
Net annual cost as a share of stockpile value.
Implementation
Potential instruments:
A multiannual national budget line for the recurring cost of rotating stockpiles of consumables (PPE, pharmaceuticals, fuel).
A procurement framework including rotation clauses.
Implement a minimum-spares obligation on designated critical entities through national Critical Entities Resilience (CER) Directive transposition.
Potential first steps (next 12 months):
Q4 2026: Designate a centralised national stockpiling authority and register with the EU stockpiling network. Conduct a review of current stockpiles.
Q1 2027: Conduct supply-chain criticality assessments for entities identified under the CER directive. Sign PPE framework contracts, including health-service rotation clauses.
Success indicators:
Population coverage x days of supply for PPE.
Net annual cost as a share of stockpile value.
Considerations
Stockpiles could operate as rotating inventories, with stock approaching expiry transferred into routine use (e.g. PPE use in hospitals), so that the continuing cost to the state remains below the headline value of the stockpile.
Considerations
Stockpiles could operate as rotating inventories, with stock approaching expiry transferred into routine use (e.g. PPE use in hospitals), so that the continuing cost to the state remains below the headline value of the stockpile.
03
Strengthen critical national infrastructure against AI-enabled cyberattacks.
03
Strengthen critical national infrastructure against AI-enabled cyberattacks.
Action
Member States are already required to ensure that essential and important entities (previously called operators of essential services in NIS1) manage cyber risk via the NIS2 Directive. To catalyse implementation, Member States should go further by establishing programmes through which essential and important entities (including water-treatment facilities, electricity grids, banks and payment systems, telecommunications, and transport) can access cybersecurity expertise and resources to proactively harden their digital infrastructure against AI-enabled cyberattacks. Combine expertise in internal bodies and contracted private-sector entities, and supply them with highly capable AI models for identifying and patching critical vulnerabilities. After high-priority infrastructure has been hardened, SMEs should also be eligible for the participation in the programme.
Action
Member States are already required to ensure that essential and important entities (previously called operators of essential services in NIS1) manage cyber risk via the NIS2 Directive. To catalyse implementation, Member States should go further by establishing programmes through which essential and important entities (including water-treatment facilities, electricity grids, banks and payment systems, telecommunications, and transport) can access cybersecurity expertise and resources to proactively harden their digital infrastructure against AI-enabled cyberattacks. Combine expertise in internal bodies and contracted private-sector entities, and supply them with highly capable AI models for identifying and patching critical vulnerabilities. After high-priority infrastructure has been hardened, SMEs should also be eligible for the participation in the programme.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
The Action Plan on Cybersecurity and Artificial Intelligence specifies a ‘pilot of a Critical Open Source Resilience Campaign to accelerate patching including by leveraging AI’, which could provide a suitable vehicle for funds.
The NIS2 Directive required Member States to identify and designate essential and important entities. This designation could serve as a list of entities to prioritise for funding allocation.
Regulation (EU) 2021/887 required Member States to establish a National Coordination Centre (NCC). NCCs are able to provide grants and technical assistance to national industry for bolstering cyberdefence.
Highly capable AI for cyberdefence could be acquired and coordinated by the European Cybersecurity Competence Centre (ECCC) or ENISA.
Potential first steps (next 12 months):
Q4 2026: Designate priority entities at particular risk to cyberattacks, due to prominence, criticality, or other factors.
Next budget cycle: Establish a pooled fund for cyberdefence support for entities on the priority list.
Q4 2027: Expand the programme to lower-priority entities, raising the floor of cyberdefence.
Success indicators: Programme launched. 80% of identified priority entities participating in the programme.
Implementation
Potential instruments:
The Action Plan on Cybersecurity and Artificial Intelligence specifies a ‘pilot of a Critical Open Source Resilience Campaign to accelerate patching including by leveraging AI’, which could provide a suitable vehicle for funds.
The NIS2 Directive required Member States to identify and designate essential and important entities. This designation could serve as a list of entities to prioritise for funding allocation.
Regulation (EU) 2021/887 required Member States to establish a National Coordination Centre (NCC). NCCs are able to provide grants and technical assistance to national industry for bolstering cyberdefence.
Highly capable AI for cyberdefence could be acquired and coordinated by the European Cybersecurity Competence Centre (ECCC) or ENISA.
Potential first steps (next 12 months):
Q4 2026: Designate priority entities at particular risk to cyberattacks, due to prominence, criticality, or other factors.
Next budget cycle: Establish a pooled fund for cyberdefence support for entities on the priority list.
Q4 2027: Expand the programme to lower-priority entities, raising the floor of cyberdefence.
Success indicators: Programme launched. 80% of identified priority entities participating in the programme.
Considerations
Discovered exploits should be patched as soon as possible. If this is not possible, unpatched exploits should be catalogued securely due to their sensitivity.
Considerations
Discovered exploits should be patched as soon as possible. If this is not possible, unpatched exploits should be catalogued securely due to their sensitivity.
04
Include AI-enabled incidents in national and sector-specific emergency response plans.
04
Include AI-enabled incidents in national and sector-specific emergency response plans.
Action
Member States should revise national emergency preparedness and civil protection plans to include named AI-enabled incidents. Where sector-specific plans already exist, these should be reconciled and expanded to account for cross-cutting AI-enabled incidents that may go beyond those previously imagined in scope or magnitude of harm. All plans should specify a clear chain of command, the legal basis for emergency measures, and named contacts within relevant Union-level structures. They should also be tested through periodic exercises conducted jointly with the Commission and neighbouring Member States, and revised in response to any lessons identified.
Action
Member States should revise national emergency preparedness and civil protection plans to include named AI-enabled incidents. Where sector-specific plans already exist, these should be reconciled and expanded to account for cross-cutting AI-enabled incidents that may go beyond those previously imagined in scope or magnitude of harm. All plans should specify a clear chain of command, the legal basis for emergency measures, and named contacts within relevant Union-level structures. They should also be tested through periodic exercises conducted jointly with the Commission and neighbouring Member States, and revised in response to any lessons identified.
Member State mode
All Member States.
Member State mode
All Member States.
Implementation
Potential instruments:
Amendments to national civil-protection legislation and the national emergency plans made under it.
National risk assessments and disaster risk management planning.
Large-scale cybersecurity incident and crisis response plans, as required by NIS2 Article 9.
Preparedness and response plans under Union Regulation 2022/2371 on serious cross-border threats to health (Article 6).
Articles 36 and 48 of the DSA.
Cyber Europe and EU-CyCLONe provide vehicles for preparedness exercises for AI-enabled crises.
Potential first steps (next 12 months):
Q4 2026: Map responsible national bodies under existing crisis plans, and flag potential areas of conflict or overlap. Add named AI-enabled emergencies and incidents to national risk assessments and/or registers.
By Q1 2027: Identify emergency preparedness plans with designated ownership and chains of command specified for each class of incident.
By Q4 2027: Conduct the first emergency exercises in collaboration with relevant Union entities and neighbouring Member States.
Success indicators: Percentage of national emergency-response plans updated to account for transformative AI.
Implementation
Potential instruments:
Amendments to national civil-protection legislation and the national emergency plans made under it.
National risk assessments and disaster risk management planning.
Large-scale cybersecurity incident and crisis response plans, as required by NIS2 Article 9.
Preparedness and response plans under Union Regulation 2022/2371 on serious cross-border threats to health (Article 6).
Articles 36 and 48 of the DSA.
Cyber Europe and EU-CyCLONe provide vehicles for preparedness exercises for AI-enabled crises.
Potential first steps (next 12 months):
Q4 2026: Map responsible national bodies under existing crisis plans, and flag potential areas of conflict or overlap. Add named AI-enabled emergencies and incidents to national risk assessments and/or registers.
By Q1 2027: Identify emergency preparedness plans with designated ownership and chains of command specified for each class of incident.
By Q4 2027: Conduct the first emergency exercises in collaboration with relevant Union entities and neighbouring Member States.
Success indicators: Percentage of national emergency-response plans updated to account for transformative AI.
Considerations
AI-enabled incidents unfold quickly and require quick decisions. Plans should state in advance which decisions can be pre-authorised and which cannot.
National AI Security Institutes, and at the Union level, the EU AI Office, should be consulted on threat models for AI-enabled incidents, to ensure the relevance of emergency-response plans.
Civil protection and disaster response remain primarily the responsibility of Member States. This means that the operational response to critical AI incidents will remain largely national.
Considerations
AI-enabled incidents unfold quickly and require quick decisions. Plans should state in advance which decisions can be pre-authorised and which cannot.
National AI Security Institutes, and at the Union level, the EU AI Office, should be consulted on threat models for AI-enabled incidents, to ensure the relevance of emergency-response plans.
Civil protection and disaster response remain primarily the responsibility of Member States. This means that the operational response to critical AI incidents will remain largely national.
IO-5
Make Europe the global leader in AI assurance technology
IO-5
Make Europe the global leader in AI assurance technology
Why it matters
In a world with transformative AI it will be increasingly important to be able to ensure security of the most capable AI models and compute, whilst allowing third parties to verify where and how they are being used. For example, public-sector use of AI, secure importing of restricted models, and methods for verifiably ‘pacing the frontier’ of AI development may all depend on security and/or verifiability. Europe has the opportunity to become a world leader in developing such assurance technology while also benefitting from their application.
Why it matters
In a world with transformative AI it will be increasingly important to be able to ensure security of the most capable AI models and compute, whilst allowing third parties to verify where and how they are being used. For example, public-sector use of AI, secure importing of restricted models, and methods for verifiably ‘pacing the frontier’ of AI development may all depend on security and/or verifiability. Europe has the opportunity to become a world leader in developing such assurance technology while also benefitting from their application.
Recommendations at the Union level
Recommendations at the Union level
01
Define Union-wide security and verifiability tiers for AI infrastructure
High
01
Define Union-wide security and verifiability tiers for AI infrastructure
High
02
Fund and support fundamental research into assurance technologies
Very high
02
Fund and support fundamental research into assurance technologies
Very high
03
Scale proofs of concept into real-world pilots
High
03
Scale proofs of concept into real-world pilots
High
04
Internationalise assurance technology
High
04
Internationalise assurance technology
High
01
Define Union-wide security and verifiability tiers for AI infrastructure.
01
Define Union-wide security and verifiability tiers for AI infrastructure.
Action
Define Union-wide technical assurance levels for AI-specific compute, with two dimensions: one for security and the other for verifiability. Require every publicly (co-)funded compute facility intended for sensitive workloads to be certified to a defined tier. For all other publicly (co-)funded capacity, require that the facility's design record the tier it is built to, without a certification obligation. This framework could serve as the basis for frontier model access negotiations (see Objective 1.1). This scheme should also aim to harmonise with national compute assurance levels. For workloads within scope of the framework, certification should satisfy all compute-specific security and verifiability requirements of the specified tier, without the need for additional national requirements. This means that a data centre certified at a given tier can serve any Member State's workloads at that level without meeting additional national conditions.
Action
Define Union-wide technical assurance levels for AI-specific compute, with two dimensions: one for security and the other for verifiability. Require every publicly (co-)funded compute facility intended for sensitive workloads to be certified to a defined tier. For all other publicly (co-)funded capacity, require that the facility's design record the tier it is built to, without a certification obligation. This framework could serve as the basis for frontier model access negotiations (see Objective 1.1). This scheme should also aim to harmonise with national compute assurance levels. For workloads within scope of the framework, certification should satisfy all compute-specific security and verifiability requirements of the specified tier, without the need for additional national requirements. This means that a data centre certified at a given tier can serve any Member State's workloads at that level without meeting additional national conditions.
Implementation
Potential instruments:
Draft tiering published by ENISA/JRC.
Amend CADA to establish a distinct AI-compute assurance framework that covers relevant hardware, firmware, and software. Criteria should be updatable through delegated acts.
AI Gigafactory agreements could specify target assurance levels.
Potential first steps (next 12 months):
Q4 2026: Task ENISA/JRC with drafting and publishing an assurance level framework that considers both security and verifiability of compute.
Q1–Q2 2027: ENISA/JRC assurance level framework published. First wave of announced AI Gigafactories refer to target assurance levels.
Q3–Q4 2027: ENISA/JRC assurance level framework tabled into the Council and Parliament negotiations of CADA.
Success indicators: ENISA/JRC framework published with defined security and verifiability tiers. AI Gigafactories built to specified assurance tiers.
Implementation
Potential instruments:
Draft tiering published by ENISA/JRC.
Amend CADA to establish a distinct AI-compute assurance framework that covers relevant hardware, firmware, and software. Criteria should be updatable through delegated acts.
AI Gigafactory agreements could specify target assurance levels.
Potential first steps (next 12 months):
Q4 2026: Task ENISA/JRC with drafting and publishing an assurance level framework that considers both security and verifiability of compute.
Q1–Q2 2027: ENISA/JRC assurance level framework published. First wave of announced AI Gigafactories refer to target assurance levels.
Q3–Q4 2027: ENISA/JRC assurance level framework tabled into the Council and Parliament negotiations of CADA.
Success indicators: ENISA/JRC framework published with defined security and verifiability tiers. AI Gigafactories built to specified assurance tiers.
Considerations
The security tiers may be benchmarked against the RAND security levels for AI model weights.
Voluntary certification with the scheme should be open to all providers regardless of nationality, and its visibility with the US government and frontier developers should be actively cultivated, so that it grounds the access negotiations of Objective 1.1 below.
The current US administration may publish a replacement to the rescinded AI Diffusion Framework that laid out security requirements for export of model weights for the largest models to third countries. The assurance tiers should take into account the provisions of such a framework, should one be published.
ENISA already owns the EU Cloud Certification Scheme. This initiative should be handled separately and narrowly scoped to AI-specific compute.
It may be necessary to revise CADA’s exclusion of ‘hardware’ from its sovereignty assurance levels (Annex II) if it is to serve as a basis for providing a framework for certifying security and verifiability of data centres.
Considerations
The security tiers may be benchmarked against the RAND security levels for AI model weights.
Voluntary certification with the scheme should be open to all providers regardless of nationality, and its visibility with the US government and frontier developers should be actively cultivated, so that it grounds the access negotiations of Objective 1.1 below.
The current US administration may publish a replacement to the rescinded AI Diffusion Framework that laid out security requirements for export of model weights for the largest models to third countries. The assurance tiers should take into account the provisions of such a framework, should one be published.
ENISA already owns the EU Cloud Certification Scheme. This initiative should be handled separately and narrowly scoped to AI-specific compute.
It may be necessary to revise CADA’s exclusion of ‘hardware’ from its sovereignty assurance levels (Annex II) if it is to serve as a basis for providing a framework for certifying security and verifiability of data centres.
02
Fund and support fundamental research into assurance technologies.
02
Fund and support fundamental research into assurance technologies.
Action
Stand up an ambitious research programme into compute security and verifiability, with at least €250 million guaranteed over five years. Employ subject-matter experts as project leads, alongside programme managers empowered to decide on specific projects to undertake within security and verification R&D. Specify predetermined kill criteria for underperforming projects, and employ a standing red team that stress-tests mechanisms in realistic settings. The programme should double as the field's talent engine by providing support, for example, through fellowships and doctoral funding
Action
Stand up an ambitious research programme into compute security and verifiability, with at least €250 million guaranteed over five years. Employ subject-matter experts as project leads, alongside programme managers empowered to decide on specific projects to undertake within security and verification R&D. Specify predetermined kill criteria for underperforming projects, and employ a standing red team that stress-tests mechanisms in realistic settings. The programme should double as the field's talent engine by providing support, for example, through fellowships and doctoral funding
Implementation
Potential instruments: The research programme could be housed as part of the European Innovation Council’s (EIC) ‘advanced innovation challenges’ (see Objective 2.1), alongside dedicated funding from Horizon Europe.
Potential first steps (next 12 months):
Q4 2026: Research programme announced, with funding allocated from the EIC’s ongoing ‘advanced innovation challenges’.
Q1 2027: Project leads hired and in place. Longlist of potential research projects published.
Q2 2027: Initial research projects underway.
Success indicators: Programme announced and funding allocated by end of 2026. Project managers announced.
Implementation
Potential instruments: The research programme could be housed as part of the European Innovation Council’s (EIC) ‘advanced innovation challenges’ (see Objective 2.1), alongside dedicated funding from Horizon Europe.
Potential first steps (next 12 months):
Q4 2026: Research programme announced, with funding allocated from the EIC’s ongoing ‘advanced innovation challenges’.
Q1 2027: Project leads hired and in place. Longlist of potential research projects published.
Q2 2027: Initial research projects underway.
Success indicators: Programme announced and funding allocated by end of 2026. Project managers announced.
Considerations
The subject-matter experts employed as project leads should be provided with full autonomy to decide on which research bets to pursue.
Underperforming research bets should be dropped early, based on prespecified ‘kill criteria’ to minimise sunk costs and ensure effective use of funding.
Considerations
The subject-matter experts employed as project leads should be provided with full autonomy to decide on which research bets to pursue.
Underperforming research bets should be dropped early, based on prespecified ‘kill criteria’ to minimise sunk costs and ensure effective use of funding.
03
Scale proofs of concept into real-world pilots.
03
Scale proofs of concept into real-world pilots.
Action
Collaborate with European industry, academia, and partner states to run large-scale pilots on promising security and verification mechanisms, including any identified through the fundamental research activities of Union-level recommendation 2. The guiding goal should be to identify cutting-edge security and verifiability mechanisms that function at the scales of frontier AI deployment, and to provide clear routes for their implementation. In line with the recommendation made in Objective 2.2, these pilots should culminate in the construction (by 2028) of the world's first AI data centre designed to withstand an SL5 equivalent threat model, as well as a separate maximally verifiable AI data centre.
Action
Collaborate with European industry, academia, and partner states to run large-scale pilots on promising security and verification mechanisms, including any identified through the fundamental research activities of Union-level recommendation 2. The guiding goal should be to identify cutting-edge security and verifiability mechanisms that function at the scales of frontier AI deployment, and to provide clear routes for their implementation. In line with the recommendation made in Objective 2.2, these pilots should culminate in the construction (by 2028) of the world's first AI data centre designed to withstand an SL5 equivalent threat model, as well as a separate maximally verifiable AI data centre.
Implementation
Potential instruments:
Funding could be provided through the InvestAI Initiative.
An ARPA-like vehicle could serve as the central manager for real-world pilot projects, coordinating input from industry, academia, and Member State initiatives (see Objective 2.1).
Potential first steps (next 12 months):
Q4 2026: ARPA vehicle stood up. Initial shortlist of potential first-round pilots announced.
Q1 2027: First round of pilots announced, with initial funding allocations and project leads in place.
Q2 2027: In line with the recommendation in Objective 2.2, specification for the SL5 data centre finalised.
Q3 2027: Shortlist of second-round pilots announced, in part drawing on research projects carried out under the ARPA vehicle.
Success indicators: First round of pilots announced and underway by mid-2027. Independently assessed SL5 data centre operational by 2028.
Implementation
Potential instruments:
Funding could be provided through the InvestAI Initiative.
An ARPA-like vehicle could serve as the central manager for real-world pilot projects, coordinating input from industry, academia, and Member State initiatives (see Objective 2.1).
Potential first steps (next 12 months):
Q4 2026: ARPA vehicle stood up. Initial shortlist of potential first-round pilots announced.
Q1 2027: First round of pilots announced, with initial funding allocations and project leads in place.
Q2 2027: In line with the recommendation in Objective 2.2, specification for the SL5 data centre finalised.
Q3 2027: Shortlist of second-round pilots announced, in part drawing on research projects carried out under the ARPA vehicle.
Success indicators: First round of pilots announced and underway by mid-2027. Independently assessed SL5 data centre operational by 2028.
Considerations
It is currently unclear whether it is possible for a single data centre to attain both resilience to SL5 security threats and high levels of verifiability. Pilots should aim to empirically investigate the tradeoffs between these two properties. The initial target should therefore be to have separate data centres that are (respectively) highly secure and highly verifiable.
The maximally verifiable data centre will likely be built after the maximally secure data centre, as verification mechanisms still pose technical challenges.
Considerations
It is currently unclear whether it is possible for a single data centre to attain both resilience to SL5 security threats and high levels of verifiability. Pilots should aim to empirically investigate the tradeoffs between these two properties. The initial target should therefore be to have separate data centres that are (respectively) highly secure and highly verifiable.
The maximally verifiable data centre will likely be built after the maximally secure data centre, as verification mechanisms still pose technical challenges.
04
Internationalise assurance technology.
04
Internationalise assurance technology.
Action
If the previous recommended actions result in developments in assurance technology, the Commission should act to internationalise these with like-minded partners. This involves collaborative research, development, and testing of the technology itself, as well as open publication of any resulting technological advances. Given assurance technology's likely critical role in an international agreement that provides the option of ‘pacing the frontier’, international collaboration and partnership on its development will be essential since states and companies may not trust unilaterally developed assurance technologies that they have limited visibility into.
Action
If the previous recommended actions result in developments in assurance technology, the Commission should act to internationalise these with like-minded partners. This involves collaborative research, development, and testing of the technology itself, as well as open publication of any resulting technological advances. Given assurance technology's likely critical role in an international agreement that provides the option of ‘pacing the frontier’, international collaboration and partnership on its development will be essential since states and companies may not trust unilaterally developed assurance technologies that they have limited visibility into.
Implementation
Potential instruments:
Bilateral partnerships, for example with international AI safety institutes or industry or academic projects, can be used to run red-teaming and rehearsal exercises for mutually verified compute.
The Pax Silica declaration, signed by the EU in June 2026, could provide a venue for internationalising the EU’s security and verifiability tiers, recommended above.
An open-by-default stance for AI verification technologies would allow all interested parties to inspect proposed verification mechanisms.
Potential first steps (next 12 months):
Q1 2027: First bilateral agreements and partnerships with like-minded allies announced.
Q3 2027: First red-teaming exercise of assurance mechanisms conducted with an international partner, and learnings published openly.
Success indicators: Technical advances stemming from the ARPA research programme published openly. Bilateral agreements and red-teaming exercises conducted through collaboration with international partners.
Implementation
Potential instruments:
Bilateral partnerships, for example with international AI safety institutes or industry or academic projects, can be used to run red-teaming and rehearsal exercises for mutually verified compute.
The Pax Silica declaration, signed by the EU in June 2026, could provide a venue for internationalising the EU’s security and verifiability tiers, recommended above.
An open-by-default stance for AI verification technologies would allow all interested parties to inspect proposed verification mechanisms.
Potential first steps (next 12 months):
Q1 2027: First bilateral agreements and partnerships with like-minded allies announced.
Q3 2027: First red-teaming exercise of assurance mechanisms conducted with an international partner, and learnings published openly.
Success indicators: Technical advances stemming from the ARPA research programme published openly. Bilateral agreements and red-teaming exercises conducted through collaboration with international partners.
Considerations
Verification mechanisms are unlikely to serve as a basis for international agreements absent adequate inspectability and interoperability. This motivates an open-by-default stance for sharing advances in verification technologies.
Considerations
Verification mechanisms are unlikely to serve as a basis for international agreements absent adequate inspectability and interoperability. This motivates an open-by-default stance for sharing advances in verification technologies.
Recommendations at the national level
Recommendations at the national level
01
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers
High
01
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers
High
02
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement
Very high
02
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement
Very high
01
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers.
01
Mutually recognise national secure cloud accreditations by mapping them onto the common EU assurance tiers.
Action
National regimes such as France's SecNumCloud, Germany's C5, and Spain's ENS certify cloud service providers as secure for handling sensitive government data. Member States should provide mappings between their respective certification schemes for AI applications by explicitly referring to the Union-wide tiered framework for security and verifiability recommended above. This mapping between countries should be bi-directional, such that certification to a tier in one Member State is sufficient for recognition at an equivalent tier in the other. This would allow Member States to pool and share secure compute resources, and provide a simplified route for providers to become certified across the Union.
Action
National regimes such as France's SecNumCloud, Germany's C5, and Spain's ENS certify cloud service providers as secure for handling sensitive government data. Member States should provide mappings between their respective certification schemes for AI applications by explicitly referring to the Union-wide tiered framework for security and verifiability recommended above. This mapping between countries should be bi-directional, such that certification to a tier in one Member State is sufficient for recognition at an equivalent tier in the other. This would allow Member States to pool and share secure compute resources, and provide a simplified route for providers to become certified across the Union.
Member State mode
Universal.
Member State mode
Universal.
Implementation
Potential instruments:
Unilateral declarations by Member States that certification via a Union-wide scheme will be treated as equivalent to certification to equivalent tiers in their own certification scheme.
Coordination between Member States via the European Cybersecurity Competence Centre.
Bilateral negotiations between Member States to mutually recognise each others’ certification schemes.
Potential first steps (next 12 months):
Q4 2026: Begin negotiations between Member States to mutually recognise national certification schemes.
Q1–Q2 2027: Commence work mapping national certification schemes to the Union-wide assured compute certification scheme (recommended above) once published.
Success indicators: At least ten published bilateral mappings and mutual recognition agreements.
Implementation
Potential instruments:
Unilateral declarations by Member States that certification via a Union-wide scheme will be treated as equivalent to certification to equivalent tiers in their own certification scheme.
Coordination between Member States via the European Cybersecurity Competence Centre.
Bilateral negotiations between Member States to mutually recognise each others’ certification schemes.
Potential first steps (next 12 months):
Q4 2026: Begin negotiations between Member States to mutually recognise national certification schemes.
Q1–Q2 2027: Commence work mapping national certification schemes to the Union-wide assured compute certification scheme (recommended above) once published.
Success indicators: At least ten published bilateral mappings and mutual recognition agreements.
Considerations
It is important to ensure that mappings between certification tiers are bi-directional. That is, certifications to equivalent tiers in two certification regimes are treated as strictly equivalent, without exceptions. Individual Member States should not place additional requirements for providers on top of certification to equivalent assurance tiers in other States’ regimes.
Considerations
It is important to ensure that mappings between certification tiers are bi-directional. That is, certifications to equivalent tiers in two certification regimes are treated as strictly equivalent, without exceptions. Individual Member States should not place additional requirements for providers on top of certification to equivalent assurance tiers in other States’ regimes.
02
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement.
02
Demonstrate demand for secure and verifiable AI infrastructure through joint innovation procurement.
Action
Member States should provide a clear demand signal for both secure and verifiable AI compute as a way of incentivising further industry R&D on the topics. Member States should aggregate anticipated government demand for attestable AI compute and issue a forward purchasing agreement for this demand. This should be actioned through Pre-Commercial Procurement (PCP) to contract the development of future security and verifiability mechanisms, followed by Public Procurement of Innovative Solutions (PPI) to purchase assured AI compute capacity once mechanisms reach maturity.
Action
Member States should provide a clear demand signal for both secure and verifiable AI compute as a way of incentivising further industry R&D on the topics. Member States should aggregate anticipated government demand for attestable AI compute and issue a forward purchasing agreement for this demand. This should be actioned through Pre-Commercial Procurement (PCP) to contract the development of future security and verifiability mechanisms, followed by Public Procurement of Innovative Solutions (PPI) to purchase assured AI compute capacity once mechanisms reach maturity.
Member State mode
Coalition of 5–10 Member States with significant government demand for sensitive AI workloads.
Member State mode
Coalition of 5–10 Member States with significant government demand for sensitive AI workloads.
Implementation
Potential instruments:
Publication of a joint multiyear forecast for secure and verifiable AI compute, quantified in terms of GPU-hours or reserved cluster capacity.
A joint PCP programme targeting specific assurance capacities that cannot currently be provided at scale.
A PPI for qualifying assurance capacity with a ring-fenced budget and commitments to procure pre-specified compute capacity once solutions satisfying defined assurance tiers are available at scale.
Issuing targeted technology challenges, with rewards of prizes or contract funding for solving specific bottlenecks in the assured AI compute stack.
Potential first steps (next 12 months):
Q4 2026: Convene an initial coalition of Member States, and jointly quantify and forecast expected demand for secure and verifiable AI compute by government bodies over the next four years.
Q1 2027: Identify priority capability gaps preventing commercial infrastructure from reaching assurance tiers.
Q2 2027: Publish the first PCP call.
Q3 2027: First PCP contracts awarded.
Success indicators: Coalition formed and forecasted demand published. PCP contracts awarded. Successful prototypes demonstrated under realistic deployment conditions.
Implementation
Potential instruments:
Publication of a joint multiyear forecast for secure and verifiable AI compute, quantified in terms of GPU-hours or reserved cluster capacity.
A joint PCP programme targeting specific assurance capacities that cannot currently be provided at scale.
A PPI for qualifying assurance capacity with a ring-fenced budget and commitments to procure pre-specified compute capacity once solutions satisfying defined assurance tiers are available at scale.
Issuing targeted technology challenges, with rewards of prizes or contract funding for solving specific bottlenecks in the assured AI compute stack.
Potential first steps (next 12 months):
Q4 2026: Convene an initial coalition of Member States, and jointly quantify and forecast expected demand for secure and verifiable AI compute by government bodies over the next four years.
Q1 2027: Identify priority capability gaps preventing commercial infrastructure from reaching assurance tiers.
Q2 2027: Publish the first PCP call.
Q3 2027: First PCP contracts awarded.
Success indicators: Coalition formed and forecasted demand published. PCP contracts awarded. Successful prototypes demonstrated under realistic deployment conditions.
Considerations
Earlier-stage research and development should take place within the Union-level research programme recommended above. PCP contracts should focus on rapid scaling of technologies with a clear pathway to broad deployment.
Demand should be aggregated across participating Member States and refer to the Union-wide assurance tiers recommended above.
The PCP and PPI stages should remain distinct. PPI should be open to all relevant suppliers, with no preference given to recipients of PCP contracts.
Considerations
Earlier-stage research and development should take place within the Union-level research programme recommended above. PCP contracts should focus on rapid scaling of technologies with a clear pathway to broad deployment.
Demand should be aggregated across participating Member States and refer to the Union-wide assurance tiers recommended above.
The PCP and PPI stages should remain distinct. PPI should be open to all relevant suppliers, with no preference given to recipients of PCP contracts.
Footnotes
This presumption should apply to derogations under Article 4(7) of the Water Framework Directive (WFD) only for data centres using closed-loop or other non-evaporative cooling systems.
This presumption should apply to derogations under Article 4(7) of the Water Framework Directive (WFD) only for data centres using closed-loop or other non-evaporative cooling systems.
In this context, a backstop is a commitment by an investment-grade third party to step in if the data centre’s contracted customer stops paying. This allows lenders to rely on the creditworthiness of the guarantor rather than just the data centre’s main customer, making large AI data centres easier and cheaper to finance. A backstop is normally required when AI companies without investment-grade rating, such as OpenAI or Anthropic, are planning a data centre.
In this context, a backstop is a commitment by an investment-grade third party to step in if the data centre’s contracted customer stops paying. This allows lenders to rely on the creditworthiness of the guarantor rather than just the data centre’s main customer, making large AI data centres easier and cheaper to finance. A backstop is normally required when AI companies without investment-grade rating, such as OpenAI or Anthropic, are planning a data centre.
Examples could include: (a) Detection: Monitoring for rogue autonomous AI agents across EU-regulated critical and government infrastructure; early warning services and threat intelligence sharing of rogue AI agent incidents; logging of AI agent events when used in high-risk systems. (b) Containment: shutdown and rollback capabilities for EU-operated AI systems and EU-based data centres; network segmentation and containment procedures for critical infrastructure, government, and other important attack surfaces; sandbox and isolation standards for AI evaluations conducted in the EU. (c) Resilience and response: trusted back-up models and non-AI fallbacks for essential functions across government and critical infrastructure; compute, tool, and human expert reserves for crises; identifying single points of failure; including loss of control in emergency response plans; conducting loss of control crisis tabletop exercises and simulations; including loss of control crisis coordination in existing structures.
Examples could include: (a) Detection: Monitoring for rogue autonomous AI agents across EU-regulated critical and government infrastructure; early warning services and threat intelligence sharing of rogue AI agent incidents; logging of AI agent events when used in high-risk systems. (b) Containment: shutdown and rollback capabilities for EU-operated AI systems and EU-based data centres; network segmentation and containment procedures for critical infrastructure, government, and other important attack surfaces; sandbox and isolation standards for AI evaluations conducted in the EU. (c) Resilience and response: trusted back-up models and non-AI fallbacks for essential functions across government and critical infrastructure; compute, tool, and human expert reserves for crises; identifying single points of failure; including loss of control in emergency response plans; conducting loss of control crisis tabletop exercises and simulations; including loss of control crisis coordination in existing structures.
Pillar 1
Pillar 2
Pillar 3
Pillar 1
Pillar 2
Pillar 3