Fight fire with fire: how open source AI models can help EU’s cybersecurity
Follow into
Save into

Europeans, much like others across the world, are increasingly desensitized about the reports of cybersecurity incidents, leaks, and hacks affecting private data. As AI capabilities grow, the number of cybersecurity incidents are growing with it, giving new flavour to EU's investment in EU and member state cybersecurity capacities, as well as the tech and tools slated for procurement.
The data from European Union’s Agency for Cybersecurity (ENISA) shows that in the first three quarters of 2025, the total number of cybersecurity incidents in the EU was 1317, whereas in the first two quarters of 2026 alone, the number already reached 1974 incidents. The most affected sector is public administration, with health, digital infrastructure and banking closely following them. These are all areas with sensitive information we should want to keep protected.

CIRAS incident reporting, ENISA, 2025-2026.
Per data of the European Repository of Cyber Incidents, the politically motivated cyberattacks such as data theft, ransomware, doxxing, and disruptions against EU Member States stands at 166 incidents, with France leading the table with 46 incidents and Germany with 40.
Despite the EU investing in its own cybersecurity capacity and enhancing cybersecurity requirements for both public and private sector, the level of cybersecurity awareness in the EU remains low. Per Eurobarometer data from 2024, 76% of employees in cybersecurity-related roles lacked formal qualifications or certified training and 57% of cybersecurity responsibilities are absorbed into existing roles from non-cybersecurity positions. In 2024, slightly more than a third of European private companies - 35,5% had documents on measures, practices and procedures on ICT security, while less than a quarter - 21,82% updated their security documents within the last 12 months.

Eurobarometer on Cyberskills, Eurobarometer, 2024; ICT security in enterprises, Eurobarometer, 2024.
Why the choice of technology is as important as regulatory obligations and financing
Although the political debate surrounding open source in Europe mostly revolves around seeing open source technology as a response to non-EU technological dominance, illustrated by the EU’s Open Source Strategy, the global push for open source models presents a new opportunity. Not only to democratize the use of technology and make it more accessible and affordable, but also to bring tangible benefits for individuals, public and the private sector, also while pushing back against the increased threats of cyberattacks.
The scenario is simple. To prevent cybersecurity incidents, IT administrators in the public and private sectors can maintain and deploy open-weight AI models to focus on specific vulnerabilities. They point AI agents at source code or databases to find security weaknesses and potential threat vectors. These models can be customized and tooled to run on secure, encrypted enclaves to protect consumer and citizen data, and fed with relevant knowledge and information about the systems they're working on.
With frontier closed-source models, much of this work has been rendered more difficult, due to the dual mandate of creating safety guardrails to stop offensive attacks while also empowering those who want to deploy AI agents defensively. Those who want to use frontier models to protect their code and infrastructure are often "safety-gated," proactively stopped by various models in order to reduce risk. This is where small and large companies must then resort to other means to install better security measures.
Surprisingly, the ideas of those who advocate for open source within Europe, and the ideas of American technology companies seem to be aligning. In late July, a number of American tech companies - including Google, Meta, Microsoft, Open AI, Palantir, NVIDIA, Linux, along European Mistral AI, Hugging Face - signed a letter in support of open source models and a more open ecosystem for artificial intelligence. The only company that has not yet signed the letter until now is Anthropic.
If Europe reframes its open-source stance from inward-oriented to outward and benefit-oriented support for open-source models, whether European or American, it might trigger the legendary Brussels effect that the EU institutions are fond of.