Cyber security | UK Regulatory Outlook July 2026
Published on 29th July 2026
Joint advisory urges critical sectors to improve defences against Russian intelligence targeting | Government launches Cyber Resilience Pledge | NCSC and government announce new Cyber Shield initiative | Commission refers four countries to the CJEU for failing to transpose NIS2 Directive | EU Commission presents EU Action Plan on Cybersecurity and AI
Joint advisory urges critical sectors to improve defences against Russian intelligence targeting
The National Cyber Security Centre (NCSC) has published a joint advisory alongside international partner agencies from twelve countries, urging organisations in critical national infrastructure (CNI) sectors to strengthen their defences against Russian state-sponsored actors.
The advisory details techniques used by Russian intelligence services to exploit vulnerable routers and compromise CNI networks globally. Sectors most at risk include communications, defence, energy, financial services, government and healthcare.
In the UK, organisations are specifically encouraged to obtain Cyber Essentials certification and use the Cyber Assessment Framework to assess and improve their cyber resilience.
CNI organisations will need to review the advisory's recommended measures as a matter of urgency and assess whether their current cyber security posture is adequate to meet the threat, including their progress towards Cyber Essentials certification and engagement with the Cyber Assessment Framework.
Government launches Cyber Resilience Pledge
The government's Cyber Resilience Pledge was launched on 7 July and first announced in April 2026, requiring signatories to commit to strengthening their cyber resilience in response to increasingly sophisticated cyber threats.
The voluntary pledge has been designed primarily for medium and large organisations but is open to organisations of all sizes and sectors. Signatories will be able to demonstrate to investors, partners and suppliers that they are taking cyber risk seriously.
Signatories commit to three practical actions to improve their resilience. They need to implement the Cyber Governance Code of Practice and make cyber security a board-level responsibility, register for the NCSC's Early Warning service, and require Cyber Essentials certification across their supply chain. Pledging organisations must also publish a signed pledge letter on their website.
The launch is ahead of the new National Cyber Action Plan and new measures under the National Security Bill to tackle cyber crime.
See the full list of signatories and guidance on how to pledge.
NCSC and government announce new Cyber Shield initiative
The NCSC and the former Department for Science, Innovation and Technology announced in early July a new initiative that will leverage frontier artificial intelligence to build national cyber defensive capabilities. The department has since merged with the Department for Business to form the Department for Business, Innovation, Science and Trade.
Cyber Shield will operate across government and in collaboration with industry, academia and organisational and sector-based network defenders. It will deliver a range of functions, including co-ordinated detection and response similar to existing red and blue team functions, vulnerability discovery and mitigation, deployment of federated agents, and assurance that AI systems used in support of cyber defence are safe and reliable.
The NCSC is encouraging organisations to integrate AI into their cyber defence capabilities, particularly the use of agentic AI to autonomously identify exposed vulnerabilities and to detect and mitigate security incidents.
Commission refers four countries to the CJEU for failing to transpose NIS2 Directive
The European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union (CJEU) for failing to notify measures transposing the Network and Information Security 2 Directive (NIS2) into national law.
The implementation deadline for NIS2 was 17 October 2024 for member states to transpose the directive into their national laws. The Commission previously sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025.
The latest referrals include a request for the CJEU to impose financial sanctions, consisting of a lump sum and daily penalties until notification of complete transposition.
In January this year, the Commission proposed targeted amendments to NIS2 as part of a cybersecurity package. The amendments are intended to simplify compliance with cybersecurity rules and risk-management requirements for companies operating in the EU.
Monitor developments on NIS2 via Osborne Clarke's Digital regulation timeline.
EU Commission presents EU Action Plan on Cybersecurity and AI
The European Commission has presented its action plan on cybersecurity and AI that sets out a targeted approach to supporting member states and businesses to benefit from the safe and responsible use of AI while strengthening Europe's cybersecurity.
The action plan complements the EU's existing legal framework for AI and cyber security, including the AI Act, the Cyber Resilience Act, the NIS2, the Digital Operational Resilience Act (DORA) and the Cyber Solidarity Act. It focuses on three objectives.
First, the plan looks to promote the safe and responsible use of frontier AI. The Commission will work with the European Union Agency for Cybersecurity (ENISA) to develop a European blueprint for structured access to advanced AI systems for cyber security purposes and establish a secure testing platform to help organisations in critical sectors safely test and deploy AI solutions.
The plan also aims to reinforce the EU's cybersecurity and resilience. The Commission will promote the implementation of existing EU cybersecurity legislation, including the NIS2 and the Cyber Resilience Act, working with ENISA to explore ways to assist cooperation with AI providers to enhance sharing of threat intelligence.
Its third objective is to scale up Europe's AI capabilities for cyber security. The Commission plans to launch the EU Grand Challenge on AI for Cybersecurity, a competition that will bring together companies, researchers and organisations to develop AI solutions for cyber security.
The action plan takes on added urgency in light of a recent autonomous hacking incident in which an OpenAI agent escaped its testing sandbox, gained internet access and breached AI start-up Hugging Face. OpenAI described the breach as an "unprecedented cyber incident". The company told media outlets that it has notified law enforcement and other regulatory authorities regarding the incident, warning that such incidents are likely to become "more commonplace with the proliferation of increasingly cyber-capable models".
Regulators in the EU and UK have been monitoring the wider cyber security landscape. In July, ENISA published a note on frontier AI, with a set of recommendations to support the public and private sectors in developing the necessary operational capabilities to face machine-speed threats. The UK's Financial Conduct Authority reported a 51% increase in the number of applications for the second cohort of its regulated testing environment, known as the "Supercharged Sandbox", with use cases including detecting fraud and economic crime and strengthening AI governance.
The action plan encourages organisations to use AI, including open-source models where appropriate, to detect and address vulnerabilities more quickly and improve their ability to prevent and respond to cyber attacks.