An autonomous agent moves in hours. It does not stop at national borders, and it does not stay in one sector. Europe has four crisis response mechanisms for what follows, each built for a different kind of event — and no rule saying which of them leads. The EU has already written that rule three times, for three other problems.
In July, an AI agent broke out of its test environment, exploited a zero-day to reach the open internet, and compromised another company’s production systems. It was running an internal capability evaluation at the time. Nobody had pointed it at that target.
Both sides noticed independently. A week passed before they spoke to one another.
That was the easy case.
One affected company. One sector. A counterpart that cooperated, because it had never had criminal intent. No time pressure, no supervisor waiting on a filing, no public demanding an explanation. Conditions do not get more favourable than they were for OpenAI and Hugging Face in July, and it still took a week for two organisations to work out what had passed between them.
Now change the parameters. Several hundred affected firms instead of one. Insurers, banks and energy utilities instead of a single sector. Five member states instead of two head offices. And behind it, an agent under hostile direction rather than one that wandered off a benchmark — nobody to call, and no interest in being found.
Who leads?
The German insurance association put a version of that question to the Commission’s Cybersecurity and AI action plan and left it open. It deserves a better answer than it usually gets, because the obvious one is wrong.
Not a vacancy
The instinctive reading is that nobody is in charge. That is not the situation. For a cross-border cyber crisis, the European Union has at least four mechanisms, and in the scenario above several of them would engage at once.
EU-CyCLONe is the network of national cyber crisis management authorities, anchored in NIS2 and supported by a secretariat at ENISA. It launched in 2020, was formalised in January 2023, and its chair rotates with the Council presidency. It sits between the technical layer and the political one: the CSIRTs Network advises it on whether an incident qualifies as large-scale, the NIS2 threshold being disruption that exceeds a member state’s capacity to respond, or significant impact on at least two member states.
The Cyber Blueprint is the Council Recommendation adopted on 6 June 2025 and published in the Official Journal on 20 June, replacing Commission Recommendation (EU) 2017/1584. It sets out the actors and mechanisms of EU cyber crisis management across the full lifecycle — preparation, detection, response, recovery, secure communication, coordination with military actors — and explains what a cyber crisis is and what triggers a crisis mechanism at Union level. It is explicitly a non-binding instrument.
EU-SCICF, the systemic cyber incident coordination framework, rests on Article 49(1) DORA and on a 2021 recommendation of the European Systemic Risk Board, which had identified a gap in existing crisis frameworks that could leave the financial sector uncoordinated in a major cross-border ICT incident. It is run jointly by EBA, EIOPA and ESMA, operates in a non-crisis and a crisis mode, and its terms of reference took effect in January 2025. Its scope is the financial sector.
The AI Office joins the list on 2 August 2026, when the Commission begins exercising supervisory powers over general-purpose AI models with systemic risk — the same date that carries the AI Act’s transparency obligations into force. Article 55 of the AI Act already obliges those providers to report serious incidents to the AI Office and national authorities without undue delay, and to maintain adequate cybersecurity for model weights and training infrastructure.
Four mechanisms, four legal bases, four triggers, four different answers to what kind of event this even is. Each of them defensible on its own terms. None of them ranked against the others.
This is not an outside criticism. The bodies concerned say as much themselves. The ESRB identified the coordination gap that produced EU-SCICF. When the ESAs announced the framework, they noted that they would report the legal and operational obstacles encountered in setting it up to the Commission, and that its further development would depend on the resources available. The Blueprint describes itself as non-binding. Read together, that is an architecture conceding its own fragility.
In German I sometimes call this verteilte Verantwortungslosigkeit — distributed unaccountability, though the German carries a sharper edge, since it turns “responsibility” into its own negation. Responsibility spread across enough desks arrives at none of them.
Why not simply appoint someone
The reflex is to propose a body. A European coordination centre for AI-driven cyber crises, with a mandate and a budget.
That fails on its own logic. A problem constituted by four parallel structures is not solved by a fifth. It also fails politically, which matters more: creating an institution that outranks existing ones means reallocating authority between Directorates-General, the European Supervisory Authorities and member states. That is precisely why the Blueprint describes rather than decides, and why it is non-binding.
What is missing is smaller and duller than an institution. It is a rule.
A pattern EU law already knows
European law has met this exact configuration before — several authorities legitimately competent over the same subject at the same time — and it has solved it the same way three times.
Under the GDPR, Article 56 designates a lead supervisory authority for cross-border processing, determined by the controller’s main establishment under Article 4(16). The other concerned authorities do not lose competence; they participate through the cooperation procedure in Article 60. This is the one-stop shop, and its defining feature is that the criterion is fixed in advance, before any particular case arises.
Under DORA, Articles 31 to 44 establish oversight of critical ICT third-party providers. One of the three ESAs is appointed Lead Overseer for each designated provider, with powers to request information, conduct off-site investigations and on-site inspections, issue recommendations and impose penalties. Again: several authorities with a legitimate interest, one designated to lead, the rest contributing through the Oversight Forum.
Under Solvency II, Article 247 opens with the principle in a single sentence — a single supervisor responsible for the coordination and exercise of group supervision shall be designated from among the supervisory authorities of the member states concerned — and then sets out the tie-breaking criteria. Article 248 assigns that group supervisor the coordination of information gathering and dissemination, and the planning and coordination of supervisory activity, expressly including emergency situations.
Three instruments, three sectors, one device. Several competent authorities, a criterion agreed in advance, one lead, the others contributing rather than acting in parallel. Nobody surrenders a mandate. The mandates are ordered.
For an insurance supervisor, the third of these is not an abstraction. European insurance law already knows how to designate who coordinates a group emergency. It simply does not do so when the emergency crosses sectors instead of subsidiaries.
What the rule would have to add
Two things, neither of which the three precedents needed.
The first is tempo. Reuters’ reconstruction of the July incident puts the first breakout attempts around 9 July, access to Hugging Face systems from the 11th, continuing to the 13th; OpenAI connected the activity to its own agent over the weekend of the 18th and 19th; the companies spoke around the 20th. Bloomberg reports the agent needed hours for access that would have taken a human attacker weeks. More than seventeen thousand actions were logged over a single weekend.
Machine-speed attack, institutional-speed response. A lead authority that convenes has already lost. The rule therefore cannot only designate who leads; it has to pre-authorise what the lead may do, so that the response does not wait on coordination. Decisions taken in advance are the only kind available at the speed the thing actually moves.
The second is exercise with private parties. Existing EU cyber exercises are exercises between authorities. A collision rule tested only among supervisors will not survive its first real encounter with an operator, a provider and three regulators in the same room. The financial sector should find this unremarkable: DORA already accepts that testing is a regulatory obligation through threat-led penetration testing. Raising that one floor, from systems to coordination, is a small step.
One objection deserves a short answer, because it comes up immediately: bring the model providers into the crisis structures. It helps less than it sounds. Provider integration is worth doing for accidents and negligence, where a cooperative provider with an API and logs can actually intervene. Against a hostile actor running open weights on infrastructure they control, there is no provider to call, nothing to suspend and no telemetry to share. That is a separate argument, and a longer one.
Why an insurer cares
None of this is administrative housekeeping, at least not from where I sit.
Insurers occupy this scenario twice over: as DORA-regulated undertakings with our own resilience obligations, and as the carriers of the cyber risk of everybody else. A simultaneous, AI-driven attack across countries and sectors is the textbook definition of an accumulation event.
And how quickly and how cleanly the response runs is not a matter of administrative tidiness. It is a determinant of how large the loss becomes. Coordination delay is a severity driver, severity drives insurability, and insurability is where an unresolved question in Brussels turns into a number in a model.
Which is why the answer to the association’s question should not be another appeal for closer cooperation. It should be a rule — the same rule European law already wrote three times, applied where it is currently absent.
Sources & further reading
- Directive (EU) 2022/2555 (NIS2) — EU-CyCLONe (Art. 16), the CSIRTs Network (Art. 15) and the definition of a large-scale cybersecurity incident (Art. 6(7)): disruption exceeding a member state’s response capacity, or significant impact in at least two member states.
- Council Recommendation on an EU Blueprint for cybersecurity crisis management (“Cyber Blueprint”), adopted 6 June 2025, published in the Official Journal on 20 June 2025 — replacing Commission Recommendation (EU) 2017/1584 on coordinated response to large-scale cybersecurity incidents and crises. Non-binding.
- Regulation (EU) 2022/2554 (DORA) — Art. 49(1) (EU-level crisis coordination for systemic cyber incidents), Arts. 31–44 (oversight of critical ICT third-party providers; designation and powers of the Lead Overseer; Oversight Forum), Arts. 26–27 (threat-led penetration testing).
- ESRB Recommendation of 2 December 2021 on a pan-European systemic cyber incident coordination framework (ESRB/2021/17). EU-SCICF terms of reference in force since January 2025; the framework is operated jointly by EBA, EIOPA and ESMA, with the ESAs noting that further development depends on available resources and that legal and operational obstacles would be reported to the Commission.
- Regulation (EU) 2024/1689 (AI Act) — Art. 55 (obligations of providers of general-purpose AI models with systemic risk: serious-incident reporting without undue delay, adequate cybersecurity for model weights and physical infrastructure); Commission supervisory and enforcement powers over such models applying from 2 August 2026.
- Regulation (EU) 2016/679 (GDPR) — Art. 4(16) (main establishment), Art. 56 (lead supervisory authority), Art. 60 (cooperation between the lead and the other concerned authorities).
- Directive 2009/138/EC (Solvency II) — Art. 247 (designation of a single group supervisor and the tie-breaking criteria), Art. 248 (its coordination tasks, expressly including emergency situations).
- Reporting on the July 2026 agent incident: Reuters (timeline — first breakout attempts around 9 July, access to Hugging Face systems 11–13 July, attribution over the weekend of 18–19 July, contact between the companies around 20 July) and Bloomberg (hours rather than weeks to obtain access; more than 17,000 logged actions over a single weekend).
- Gesamtverband der Deutschen Versicherungswirtschaft (GDV), position on the European Commission’s Cybersecurity and AI action plan.