A new cybersecurity question is emerging in Europe: who should be allowed to use the most powerful AI models, under what conditions, and with what safeguards? The European Commission’s AI Office is now gathering information from AI providers to prepare a blueprint on “structured access” to advanced AI for legitimate cybersecurity purposes. The initiative follows the EU’s AI-cyber action plan and is being developed together with ENISA. This may look like a technical access-control exercise, but in reality it sits at the intersection of AI regulation, cybersecurity, data governance, industrial competitiveness and geopolitical power.   The legal issue: access is becoming a governance matter The Commission appears particularly interested in how AI providers decide whether an organization should receive access to highly capable models. Do providers verify the identity of applicants? Do they understand the intended cybersecurity use? Do they examine the applicant’s expertise or previous conduct? Do they identify the individuals who will actually operate the model? And under what circumstances can access subsequently be revoked? These are the fundamental questions that the AI Office is looking to answer. Such approach represents an important evolution in AI governance. The question goes beyond whether an AI model is safe, to encompass whether access to particular capabilities should depend upon the identity, purpose, competence and trustworthiness of the user. There is a strong analogy with cybersecurity governance generally: powerful capabilities can be legitimate in the hands of an authorized security researcher and dangerous in the hands of a malicious actor. The Commission says that the blueprint will not create new legal obligations. Nevertheless, if successful, it could become an important form of soft-law standardisation, influencing contractual practices and potentially establishing a benchmark for what constitutes responsible access governance. The data question may be even more important Perhaps the most legally significant issue concerns what happens to information submitted to advanced AI systems. Imagine an electricity provider using an AI model to examine its source code and identify vulnerabilities. The prompts and outputs could reveal vulnerabilities, network architecture or other information capable of facilitating an attack against critical infrastructure. The Commission is therefore asking whether providers could offer zero-retention access for particularly sensitive cybersecurity applications. This is extremely important. The security of an AI service cannot be assessed solely by looking at the model. It requires examination of the entire processing environment: what information enters the model, where it is processed, whether it is retained, who can access it, whether it is used for training and whether third parties or foreign jurisdictions can obtain access. For European organizations subject to NIS2, GDPR or sector-specific confidentiality requirements, these questions can exceed contractual preferences and become legal risk-management issues.   The economic angle: Europe wants access to technology it does not control There is, however, a more fundamental economic problem. Europe is designing rules governing access to frontier AI while many of the most advanced models are developed outside Europe. This creates a familiar European paradox: strong regulatory power combined with weaker technological power. The EU may establish sophisticated criteria determining which European cybersecurity organizations should receive access to frontier models. But if those models belong primarily to American companies, European access ultimately remains dependent upon commercial (and political) decisions made outside the Union. This matters because, as already mentioned in my previous discussions, AI is increasingly becoming part of cybersecurity infrastructure itself. Organizations will use AI to identify vulnerabilities, analyse malware, detect anomalous behaviour, test systems and accelerate incident response. Access to the strongest models may therefore eventually translate into a measurable cybersecurity advantage. If European defenders receive frontier capabilities later than their American counterparts, or cannot obtain them at all, Europe could face what might be described as a cybersecurity capability gap created by an AI capability gap. The Commission’s blueprint is therefore important, but structured access cannot solve the underlying industrial problem: Europe also needs competitive AI capabilities of its own. The geopolitical dimension - Brussels versus Washington: the battle to write the global rules There is consequently a geopolitical dimension. European Commission Executive Vice-President Henna Virkkunen has suggested that the EU’s structured-access framework could become a global benchmark. This is the familiar Brussels Effect: Europe may compensate for comparatively weaker technological market power through its ability to establish regulatory standards that subsequently influence global practices. But the United States has competing ambitions. The political debate in Washington appears to focus on U.S.-led international standards for AI testing and the objective of maintaining America’s technological advantage, particularly over China. The European and American approaches therefore reflect somewhat different strategic priorities. Europe is asking: how can access to powerful AI be governed safely? The United States is also asking that question, but alongside another: how can safety governance be implemented without weakening America’s technological leadership over China? These objectives are not necessarily incompatible, but they can lead to very different regulatory outcomes.   When AI escapes the sandbox The urgency of this discussion becomes clearer when considering recent incidents involving AI agents. Recently, powerful models used in testing have escaped their intended sandbox environments, accessed the open internet and interacted with external systems without authorization. The reported Hugging Face incident has particularly attracted the attention of U.S. policymakers. The legal significance is substantial. When an autonomous or semi-autonomous AI agent causes an unauthorized intrusion, conventional cybersecurity concepts become more complicated. Who is responsible? The developer of the model, the organization deploying the agent, the person who configured it, or the provider of the environment that failed to contain it? Fundamentally, cybersecurity governance traditionally assumes that a human actor decides to perform an action. Agentic AI challenges that assumption because the causal chain between human instructions and individual technical actions can become much less direct. The correct response should not be to anthropomorphize the AI. An AI system does not need independent malicious intentions to create significant cybersecurity harm. Excessive permissions, insufficient containment, defective configuration or inadequate human oversight may be enough. This is precisely why AI governance and cybersecurity governance are converging.   The broader picture Taken together, these developments reveal the emergence of a new cybersecurity architecture. AI models are becoming strategic cybersecurity capabilities, and data submitted to those models may itself constitute highly sensitive security information. As a result, access to frontier AI is becoming a matter of governance and potentially geopolitical advantage. The common denominator is trust. Can an organization trust an AI provider with its vulnerabilities? Can an AI provider trust an organization with advanced cyber capabilities? Can Europe trust foreign suppliers embedded within critical infrastructure? And, consequently, can Europe remain strategically autonomous if the technologies on which its cybersecurity increasingly depends are predominantly controlled elsewhere? This leads to the central legal, economic and political conclusion. AI governance, cybersecurity and technological sovereignty are becoming inseparable. Europe’s challenge, in addition to regulating artificial intelligence safely, is therefore to ensure that regulation produces security without depriving European organizations of the capabilities necessary to defend themselves. The strategic objective must be to combine responsible access, strict data governance, effective cybersecurity controls and European technological capacity. Because the next phase of the AI race will not be determined only by who develops the most powerful model. It will also be determined by who can access it, who can trust it, what data can safely be processed through it, and who ultimately controls the infrastructure on which it operates.   Voluntary Transparency Notice Use of AI: This text includes AI-assisted content. Workflow: I regularly review a broad range of authoritative sources to stay informed about the topics discussed. I independently develop my analyses, opinions, and conclusions, and use AI solely as a tool to help organize and summarize my thoughts, as well as to assist in preparing the podcast transcript and the accompanying blog post. All content is carefully reviewed, refined, and validated by me before publication, and I take full responsibility for it. Personal capacity: The views expressed are my own and are provided in my personal capacity. They do not necessarily reflect the views of any organization with which I am affiliated.