The European Cybersecurity Competence Centre (ECCC) opened a new call for proposals under the EU's Digital Europe Programme on September 3, 2026, worth up to €96 million, with proposals due by January 14, 2027. AI is the single largest theme in the call: €15 million for AI-based cybersecurity tools and services, generative AI included, plus €20 million specifically to help small and medium enterprises adopt AI cyber solutions — €35 million combined, more than a third of the headline figure.
Where the rest of the €96 million is supposed to go
The remaining line items, as the ECCC itself lists them: €15 million for crisis-preparedness testing in critical sectors, €20 million to help the European ecosystem comply with the recent wave of EU rules — NIS2, the Cyber Resilience Act, DORA, and the AI Act — €5 million for regional hubs focused on undersea cable security, and €10 million for dual-use technology usable in both civilian and military contexts. Add those six figures together — 15, 20, 15, 20, 5, 10 — and the total is €85 million, not €96 million. The ECCC's own materials don't explain the remaining €11 million; it isn't assigned to any of the categories reported.
The market the funding is trying to fix
The call lands against a genuinely lopsided market. Non-European vendors hold an estimated 60–70% of Europe's civil cybersecurity market, according to a BDO report cited alongside the announcement. The European market itself is estimated at €46 billion in 2025 — about a quarter of the global total — split across roughly 7,000 companies, 90% of them SMEs that together generate only a quarter of the sector's revenue. Investment tells the same story at a larger scale: in 2025, the US and Israel reportedly captured 91% of global cybersecurity investment, while Europe outside the UK attracted just $1.3 billion. A €96 million call — or €85 million, depending which number you use — is a rounding error against gaps that size; the ECCC's own framing treats this as seed funding meant to direct where scarce public money goes, not as a fix for the scale problem itself.
Why AI specifically is getting a bigger slice
AI cuts both ways in this market, which is presumably why it draws the largest dedicated allocation: the same models improving detection, analysis, and incident response are also strengthening offensive capability, and the US holds a structural edge on both sides of that ledger — in foundation models, compute infrastructure, and company funding alike. That's the same gap this blog covered from the sovereign-model angle only hours earlier, when France's economy minister argued European AI can't rest on Mistral alone, and the same underlying dependency the AI Act's own compliance timeline has had to bend around as it comes into force. Funding AI-specific cyber tooling and easing AI Act compliance in the same call is Brussels treating the AI Act itself as one more cost European cyber vendors need help absorbing, not just a rule imposed on them.
What to expect next
- Watch whether the ECCC clarifies the missing €11 million. Six published line items summing to €85 million against a headline €96 million figure is either an administrative reserve the announcement didn't spell out, or a rounding gap worth someone asking about directly.
- Watch who actually wins the AI-cyber and SME-adoption lines. With 7,000 companies and 90% of them SMEs generating a quarter of sector revenue, whether this money reaches that fragmented base or concentrates in a handful of larger players is the real test of the program's stated goal.
- Watch the €10 million dual-use line for pushback. Civil-military technology funding inside a nominally civilian cybersecurity program is the kind of detail that tends to draw scrutiny once national delegations start reviewing proposals.
- Watch the gap between this call's January 2027 deadline and actual disbursement. Seed money announced today doesn't reach an SME's balance sheet for a long time yet — the scaling problem Brussels itself names as the real challenge won't be tested until money actually moves.