By |Last Updated: September 23rd, 2026|3 min read|Categories: Concepts|

Governments are beginning to set clearer expectations around how AI can be developed and used securely, although the rules differ significantly between jurisdictions.

Two approaches are particularly relevant to AI in cybersecurity: the EU AI Act and the US National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF).

The biggest difference is that the EU AI Act creates binding legal obligations, while the NIST frameworks are voluntary guidance.

The EU Approach To AI And Cybersecurity

The EU AI Act establishes a risk-based regulatory framework for AI systems operating in the European Union. Its requirements are being introduced in stages, with governance and enforcement responsibilities applying from August 2026 and further provisions continuing to take effect thereafter.

In July 2026, the European Commission added a more cybersecurity-specific layer with its Action Plan on Cybersecurity and Artificial Intelligence. The plan addresses both using AI to strengthen cyber defenses and managing the new vulnerabilities created by advanced AI models.

Importantly, the Action Plan is not a standalone binding regulation. Instead, it builds on the EU’s existing legal framework, including the AI Act, Cyber Resilience Act and NIS2 Directive. Among its priorities are improving the evaluation of advanced AI models, strengthening cybersecurity capabilities and helping organizations prepare for AI-enabled threats.

For businesses operating in the EU, this means AI cybersecurity cannot be treated purely as a matter of internal best practice. Depending on how an AI system is developed or used, organizations may have regulatory obligations to consider.

The US Takes A Voluntary Approach

The US approach is currently less prescriptive. NIST’s AI RMF provides a voluntary structure for identifying and managing risks associated with designing, developing, deploying and using AI. Its core functions – Govern, Map, Measure and Manage – are intended to help organizations build trustworthy AI risk management into their processes.

NIST has also developed a preliminary draft Cybersecurity Framework Profile for Artificial Intelligence, or Cyber AI Profile. This focuses more directly on the intersection between AI and cybersecurity, including securing AI systems, using AI to support cybersecurity and defending against AI-enabled attacks.

Unlike the EU AI Act, these NIST frameworks are voluntary. They provide organizations with a practical model for managing AI-related cyber risk rather than creating new legal requirements.

What Does This Mean For Security Teams?

While the regulatory practice is still developing, these changes highlight why security teams need to understand not only how AI can improve detection and response, but also how its use is governed, monitored and secured.

For organizations operating internationally, that may mean complying with binding requirements in one jurisdiction while using voluntary frameworks elsewhere to establish consistent internal controls.

Share This Story, Choose Your Platform!

Related Posts