ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations

The CYBERAI topic funds secure, trustworthy AI for detection, threat intelligence, response and self-healing in European cyber operations. How it differs from AI4SME, who should be in the consortium and what evaluators expect.

October 01, 2026 14 min read

Systems engineer watching monitors in an office in the evening Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. CYBERAI at a Glance
  4. CYBERAI or AI4SME?
  5. Operational Capability Paths
  6. Secure and Trustworthy AI Is Part of the Deliverable
  7. Data, CTI and Information-Sharing Design
  8. Deployment, Licensing and Strategic Dependencies
  9. Who Can Participate and How to Build the Consortium
  10. Funding and Cost Model
  11. Expected Outcomes and Evidence Model
  12. KPI Contract
  13. A Practical Work-Package Model
  14. How Evaluators Will Read the Proposal
  15. Eligibility, Security and Application Package
  16. Readiness Checklist
  17. Frequently Asked Questions
  18. Conclusion
  19. Guides in the ECCC 2027 Series
  20. Official Sources

Applies to: technology providers, Cyber Hubs, CSIRTs, national and competent authorities, research organizations, NIS 2 entities and partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI.

The CYBERAI topic provides a €15 million envelope to develop and deploy secure, robust and trustworthy AI-powered systems for European cyber operations. The expected EU contribution is €3-5 million per project, the funding rate is 50%, and the indicative duration is 36 months. Proposals are due by 14 January 2027 at 17:00 CET and must include at least one official capability path, such as threat detection, CTI production, automated response, vulnerability management, self-healing, secure information sharing or protection of AI systems. A generic AI prototype without operational users, security controls and validation is not enough (official call document).

In Brief

  • CYBERAI targets operational capacity for National and Cross-Border Cyber Hubs, CSIRTs, national authorities, NIS single points of contact and other relevant stakeholders.
  • The topic covers both AI for cybersecurity and the cybersecurity of AI, including misuse, model risks, supply-chain security, robustness, trust and legal compliance.
  • Activities must include at least one official path and should connect development, testing, validation, deployment and measurable operational use.
  • Resulting systems, tools and services are expected to be available for licensing to Cyber Hubs, CSIRTs and relevant authorities under favorable market conditions.
  • The topic is a Simple Grant with a 50% rate; no SME-specific 75% uplift applies.
  • The two baseline KPIs measure benefiting entities and AI-powered capabilities provided to Cyber Hubs or national authorities.
  • Article 12(5) security restrictions apply, which makes ownership, control, data location and technology dependencies material design issues.

Scope and Source Boundary

This guide explains the topic's operational scope, secure-AI expectations, stakeholder model, funding mechanics and evidence requirements. It does not determine the eligibility of a specific system or consortium and does not replace the official call document, the live Funding & Tenders record or applicable EU legislation.

CYBERAI is one of seven topics under DIGITAL-ECCC-2027-DEPLOY-CYBER-11. Its core purpose is to strengthen central cyber-operational capacity through AI and machine learning, including generative AI, while ensuring that the resulting technology is itself cybersecure and trustworthy (ECCC call overview).

CYBERAI at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI
Topic budget €15 million
Type of action Simple Grant
Funding rate 50%
Expected EU contribution €3-5 million per project
Indicative duration 36 months
Consortium minimum None in the common composition rules
Equipment-cost treatment Depreciation and full cost for listed equipment
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The expected contribution is a planning range, not an automatic award or absolute cap. A different amount can be considered when duly justified, and the final grant may be lower than the amount requested.

CYBERAI or AI4SME?

Both topics concern AI-powered cybersecurity, but their primary outcomes differ.

Decision factor CYBERAI AI4SME
Primary outcome Central and advanced AI-powered cyber-operational capacity Adoption of user-friendly AI cybersecurity by European SMEs
Core users Cyber Hubs, CSIRTs, authorities, NIS stakeholders and cyber operators SMEs and organizations that need accessible risk and incident tools
Typical outputs CTI, anomaly detection, automated response, self-healing, secure AI and authority-ready services SME toolkit, risk assessment, alerts, incident guidance, notification and onboarding
Type and rate Simple Grant, 50% SME Support Action, 50%; 75% for SMEs
Deployment question Can the capability operate securely at ecosystem or authority level? Can SMEs adopt and use the solution effectively?

Choose the topic from the intended operational result, not from the use of AI alone. A project may help SMEs and still fit CYBERAI if its primary deliverable is central operational capacity for Cyber Hubs or authorities; conversely, a user-friendly SME toolkit belongs more naturally under AI4SME.

Operational Capability Paths

The call requires activities to include at least one listed path. A focused proposal may combine several paths when their data, users and validation model form one coherent operating capability.

Capability path Operational result Evidence to define
Threat and anomaly detection Identify emerging patterns, new attack vectors and abnormal behavior across ICT or OT Data sources, detection latency, precision, recall, drift and analyst workflow
Cyber Threat Intelligence Create and process high-quality CTI, including original European feeds or services Provenance, enrichment, confidence, sharing format and consumer validation
Real-time monitoring and response Generate alerts or trigger controlled automated responses Trigger logic, authorization, containment limits, response time and audit trail
Malware analysis Analyze code behavior, network traffic and file characteristics Test corpus, detection performance, explainability and analyst verification
Vulnerability management Combine multiple information sources to identify and prioritize weaknesses Asset context, source quality, prioritization, remediation workflow and closure evidence
Self-healing and recovery Support recovery through automated or semi-automated restoration Safe-state definition, rollback, approval gates, recovery objectives and test results
Automated scanning and testing Identify weaknesses through vulnerability scanning and penetration testing Authorization, scope, safety controls, findings quality and retest evidence
Secure information sharing Share CTI and actionable data without compromising security or privacy Anonymization, access control, purpose limitation, retention and interoperability
AI, IoT and industrial risk reduction Protect crossovers among AI, IoT, smart grids and manufacturing chains System boundary, dependencies, safety impact and sector validation
AI-system protection and certification Secure AI solutions and contribute to standardization or certification Threat model, security controls, conformance evidence and assessment pathway

The topic also supports product security and cybersecurity by design or default in line with Cyber Resilience Act requirements.

Secure and Trustworthy AI Is Part of the Deliverable

The call explicitly requires attention to the security of AI itself, especially during learning, and to malicious use of AI. It also connects deployment to performance, robustness, trustworthiness, social acceptance, the AI Act, intellectual-property rules and the GDPR.

A proposal should address at least four linked layers:

  1. AI asset layer: models, training and inference data, prompts, embeddings, pipelines, model registries and supporting infrastructure.
  2. Threat layer: poisoning, evasion, adversarial input, model theft, data leakage, prompt injection, unsafe tool use, dependency compromise and malicious repurposing where applicable.
  3. Control layer: provenance, access control, isolation, integrity checks, validation, monitoring, confidence thresholds, human authorization, rollback and incident handling.
  4. Assurance layer: test cases, acceptance criteria, independent review, reproducibility, limitations, audit logs and evidence for certification or standardization.

ENISA's Multilayer Framework for Good Cybersecurity Practices for AI and Cybersecurity of AI and Standardisation provide official reference points cited by the call. The project should still adapt controls to its own architecture, operating context and risk appetite.

Data, CTI and Information-Sharing Design

AI cyber operations depend on data from authorities, Cyber Hubs, CSIRTs, NIS entities and technical sensors. Data volume alone does not demonstrate quality or legality.

A defensible data model should define:

  • source, ownership, authorization and permitted purpose for each dataset;
  • classification, sensitivity, personal-data and intellectual-property constraints;
  • normalization, deduplication, labeling, quality and confidence controls;
  • anonymization or pseudonymization before cross-organization sharing;
  • access segregation, geographic location, retention and deletion;
  • feedback from analysts and downstream CTI consumers;
  • handling of false or adversarial intelligence;
  • export formats and interoperability with operational platforms.

For original European CTI feeds, the proposal should explain what makes the intelligence original, who can consume it, how confidence is expressed and how the service remains sustainable after funding.

Deployment, Licensing and Strategic Dependencies

The call expects systems, tools and services to be made available for licensing under favorable market conditions to National or Cross-Border Cyber Hubs, CSIRTs, competent authorities and other relevant authorities. This makes exploitation and licensing architecture part of the project design rather than an end-of-project afterthought.

Define early:

  • foreground and background intellectual property;
  • licensing model, eligible users and support obligations;
  • deployment options for sensitive environments;
  • maintenance, model updates and vulnerability handling;
  • portability and exit arrangements;
  • dependencies on non-eligible suppliers, models, data or cloud infrastructure;
  • controls against foreign influence and indirect control.

The call stresses that Cyber Hubs must be protected from dependencies and vulnerabilities because of their operational role and sensitive information. In well-justified cases, access to EuroHPC high-performance computing infrastructure may be granted; this is a possibility, not an entitlement, so the proposal needs a viable compute plan without assuming approval.

Who Can Participate and How to Build the Consortium

Targeted stakeholders include technology providers, Cyber Hub operators, research and academia, cybersecurity entities, the public sector, NIS 2 entities, private-sector organizations and other actors supporting secure-AI deployment.

The common rules impose no minimum consortium composition for CYBERAI, and a single applicant may submit where all topic and capacity conditions are satisfied. A typical end-to-end partnership may include:

Role Contribution
Operational authority, Cyber Hub or CSIRT Use cases, sensitive operating constraints, data, validation and adoption
Technology or AI provider Models, tooling, infrastructure, secure development and lifecycle support
Cybersecurity specialist Threat models, detection, response, testing and assurance
Research organization Methodology, benchmarking, robustness testing and reproducibility
NIS or sector operator Representative deployment environment and sector-specific validation
Standardization or certification actor Assessment pathway, evidence model and contribution to trust mechanisms

Every partner should own a measurable part of the operational result. A consortium with impressive names but no data rights, deployment environment or adoption commitment will remain weak.

Funding and Cost Model

CYBERAI is a Simple Grant with a 50% funding rate. The expected EU contribution is €3-5 million per project, with an indicative duration of 36 months.

The budget-based grant reimburses eligible actual costs with the unit-cost and flat-rate elements defined in the call. Planning should account for:

  • indirect costs at 7% of applicable eligible direct costs;
  • depreciation and full cost for listed equipment under the topic conditions;
  • the no-profit rule and possible reductions for non-compliance;
  • co-financing, cash flow and financial capacity for each beneficiary;
  • eligible-country restrictions for work, subcontracting and controlled entities.

Compute, data engineering, secure infrastructure and validation can create substantial costs. Each amount should trace to workloads, environments, work packages and measurable outputs. Do not rely on a broad "AI platform" budget line without usage assumptions and cost ownership.

Expected Outcomes and Evidence Model

The expected outcomes include deployed AI capabilities for Cyber Hubs and authorities, validated novel tools, better collaboration, automated CTI processes, original European CTI feeds, advanced secure AI for NIS sectors and contributions to standardization or certification.

Outcome family Evidence of completion
Detection capability Validated performance on representative data, analyst acceptance and operational deployment
CTI production Feed provenance, quality metrics, consumer use and information-sharing controls
Automated response Tested playbooks, authorization gates, containment safety and response-time improvement
Recovery and self-healing Recovery tests, rollback evidence and measured service restoration
Secure AI Threat-model coverage, robustness tests, monitoring, limitations and lifecycle controls
Collaboration Connected authorities or hubs, completed exchanges, common workflows and sustained operating model
Certification contribution Defined scheme or standardization pathway, evidence package and assessor involvement

Validation should cover relevant conditions, not only laboratory accuracy. For an operational tool, evidence may need to include performance under load, adversarial behavior, degraded inputs, model drift, human response and recovery from incorrect automation.

KPI Contract

The topic defines two mandatory indicators:

  1. Number of entities benefiting from development, testing, validation, deployment or uptake of AI-powered cybersecurity technologies, tools and services.
  2. Number of AI-powered cybersecurity technologies and capabilities provided to National or Cross-Border Cyber Hubs and national authorities encompassing Cyber Hubs and CSIRTs.

Optional indicators cover AI services for rapid detection and decision-making, automated threat detection and response, AI-IoT-smart-grid risk-reduction tools, original CTI feeds, cybersecurity-by-design tools and protection of AI solutions.

For each applicable KPI, define baseline, target, unit, data source, collection frequency and responsible partner. If an indicator does not apply because the related activity or outcome is outside the project, state and justify that boundary. Additional KPIs should capture genuine gaps such as detection quality, decision time, deployment availability, analyst workload, robustness or safe-response performance.

A Practical Work-Package Model

This is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Governance, ethics and security Control scope, ownership, security restrictions, risks and decisions Governance model, threat model, data and security plans
WP2 Data and CTI foundation Prepare authorized, high-quality and interoperable operational data Data agreements, pipelines, taxonomies and quality metrics
WP3 AI capability development Build or adapt models, tools and integrations Architecture, releases, controls and technical documentation
WP4 Robustness and assurance Test AI security, performance, trust and compliance Adversarial tests, validation reports, limitations and assurance evidence
WP5 Operational pilots Deploy with hubs, CSIRTs, authorities or sector operators Pilot records, analyst feedback, operational KPIs and acceptance decisions
WP6 Licensing and uptake Make results available and sustainable Licensing model, support plan, deployment packages and exploitation pathway

The common rules also require a dissemination and exploitation deliverable in the first six months and yearly deliverables on relevant KPIs and project outputs.

How Evaluators Will Read the Proposal

Criterion CYBERAI evidence to emphasize Pass threshold
Relevance Official capability path, operational users, EU cyber need, secure AI and supply-chain resilience 3/5
Implementation Mature architecture, data access, consortium capacity, pilots, security and measurable plan 3/5
Impact Deployed capabilities, authority or hub uptake, CTI value, scalability and European autonomy 3/5
Overall Combined score 10/15

For CYBERAI, the award subcriteria on overcoming lack of market finance and on environmental sustainability or European Green Deal effects are explicitly not applicable. The digital technology supply-chain subcriterion remains applicable.

Passing the thresholds does not guarantee funding. Proposals are ranked within the available topic budget, and legal, financial, exclusion and security checks continue during grant preparation.

Eligibility, Security and Application Package

Beneficiaries and affiliated entities must generally be eligible legal entities established in EU Member States or in Norway, Iceland or Liechtenstein. Article 12(5) restrictions apply to participation in every role: entities must be established in and controlled from eligible countries, while project activities and subcontracted work must take place there.

The application consists of online Part A, technical Part B limited to 70 pages, and required ownership and control declarations. Submission is exclusively electronic through the Funding & Tenders Portal.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Confirm that central cyber-operational capacity is the primary result and select the correct topic.
  2. Choose at least one official capability path and map every work package to it.
  3. Secure operating-user commitment, data rights and a representative validation environment.
  4. Define AI assets, threats, controls, assurance evidence and acceptable automation boundaries.
  5. Document GDPR, intellectual-property, AI Act and CRA considerations where applicable.
  6. Plan how results will be licensed to Cyber Hubs, CSIRTs or relevant authorities under favorable conditions.
  7. Address supplier, model, cloud, data and control dependencies under the security restrictions.
  8. Include both mandatory KPIs and justify every optional or non-applicable indicator.
  9. Build a credible 50% co-financing plan and evidence the cost of compute, data, pilots and assurance.
  10. Use the live portal templates, keep Part B within 70 pages and submit before the deadline.

Frequently Asked Questions

Is CYBERAI a research-only topic?

No. The call requires development and deployment, with tools tested and validated in relevant conditions and made available to operational stakeholders. Research may support the method, but operational use is central.

What is the main difference from AI4SME?

CYBERAI focuses on advanced operational capability for Cyber Hubs, CSIRTs, authorities and NIS ecosystems. AI4SME focuses on practical uptake of user-friendly AI cybersecurity tools by SMEs and provides the SME-specific 75% rate.

Must a Cyber Hub join the consortium?

The common rules do not establish a minimum consortium or explicitly require a Cyber Hub beneficiary. The proposal must nevertheless show how its capability reaches the relevant hubs, CSIRTs or authorities and is validated for their operating context.

Can the project use generative AI?

Yes. The objective explicitly includes generative AI, but the proposal must address its operational value, cybersecurity risks, misuse, data controls, robustness and trustworthy deployment.

Is EuroHPC access guaranteed?

No. The call says access requests may be granted in well-justified cases. Applicants need a credible compute model that does not depend on unapproved access.

Does every consortium partner receive more than 50%?

No. CYBERAI is a Simple Grant with a 50% funding rate. There is no topic-specific SME uplift.

Does reaching 10/15 guarantee funding?

No. A proposal must also score at least 3/5 on each criterion, rank within the topic budget and pass subsequent legal, financial and security checks.

Conclusion

CYBERAI is designed for projects that can turn secure AI into validated European cyber-operational capability. A strong proposal joins authoritative users, governed data, proven technology, adversarial testing, measurable operational improvement and a realistic licensing path.

We can help you define security requirements, evidence models, data governance and risk controls through our Virtual CISO service; the Cyber Check-up gives each partner a first documented measure of its posture. Final scope, eligibility, legal, cost and submission decisions must remain anchored to the official call document, applicable legislation and live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 29, 2026

ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers

The AI4SME topic funds AI-enabled cybersecurity tools and services that European SMEs actually adopt. Budget, the 75% SME funding rate, eligible acti…

May 29, 2025

The EU Cyber Solidarity Act: A New Pillar of Collective Resilience

The EU Cyber Solidarity Act introduces coordinated mechanisms and shared capabilities to improve threat detection, incident response, and strategic r…

May 29, 2025

Cybersecurity Update - Week 22 of 2025

Aegister's weekly cybersecurity update for Week 22 of 2025, covering major threats, trends, regulatory changes (NIS 2, DORA), GRC topics, and interna…