A quick read on why four unrelated cyber filings from four different governments all say the same thing.
By Vladimir Tsakanyan, PhD · Center for Cyber Diplomacy and International Security · cybercenter.space
If you only skimmed the cyber policy headlines this week, you’d have seen four stories that look like they belong in four different newsletters. The EU is suing four of its own member states. The EU is also launching a new AI cybersecurity plan. The UK’s long-running cyber bill is back in front of the House of Lords. And a Canadian province just quietly brought two new regulations into force.
Put them side by side, though, and they’re the same story told four times: writing the law was the easy part. Making it actually govern anything is where every one of these jurisdictions is currently stuck.
Exhibit A: Brussels sues its own members
On July 8, the European Commission referred Ireland, Spain, France, and the Netherlands to the EU’s top court. The charge: failing to transpose NIS2, the directive that sets minimum cybersecurity standards for hospitals, power grids, transport networks, and public administrations across 18 critical sectors. The deadline for this was October 2024. These four countries are still more than 20 months late.
Here’s the part that should give you pause: as of January 2025, only six of the EU’s 27 member states had actually transposed NIS2 on time. This isn’t four bad apples — it’s a bloc-wide pattern that Brussels is now, for the first time, escalating all the way to litigation.
Will the fines actually get paid? Probably not in full — that’s not usually how these cases end. Member states tend to pass the required law once the lawsuit is underway, at which point Brussels drops the case. The Netherlands is doing exactly that right now: its Senate approved its NIS2 transposition law on July 7, one day before the Commission filed against it.
The real cost isn’t the fine. It’s that NIS2 is the foundation other EU cyber law is built on top of — including the Cyber Resilience Act’s incident-reporting rules, which start applying in 2027. Where transposition hasn’t happened, the cross-border incident-response plumbing that NIS2 was supposed to create simply isn’t there yet, even if the country’s cyber agency is technically up and running.
Exhibit B: Brussels also stops writing new rules
The same week, the Commission dropped its AI Cybersecurity Action Plan — and the headline is what’s not in it. No new obligations. Instead: a proposed European AI evaluation capability aiming to be operational by 2027, a secure testing environment for AI systems run with ENISA, and a plan to let vetted organizations securely access frontier AI models for defensive cyber work.
“AI is transforming the meaning of cybersecurity,” said EU tech chief Henna Virkkunen. Translation: Brussels thinks it has enough law already — the AI Act, the Cyber Resilience Act, NIS2, DORA. What it doesn’t have yet is the machinery to actually run any of it at AI speed.
Which makes the timing almost darkly funny. The Commission is building an AI-testing framework that assumes every member state’s cyber response team has full legal standing under NIS2 — in the same week it’s suing four countries for not giving their teams exactly that standing.
Exhibit C: London’s bill outlives its prime ministers
Meanwhile in Westminster, the Cyber Security and Resilience Bill — introduced back in November 2025 to modernize UK critical-infrastructure rules — hit the House of Lords for its second reading on July 14. It’s roughly halfway through Parliament. If it survives, it comes into force in 2027–28.
“There’s still some really good stuff in that bill, but there’s some challenges coming along the line,” is how one former MP put it — which is about as close to full-throated confidence as UK cyber policy gets these days. And there’s a reason for the hedging: the UK is expected to get its sixth prime minister in ten years by September, likely Labour’s Andy Burnham, who’s already promising a “more resilient Britain” in the wake of last year’s $2.5 billion Jaguar Land Rover hack.
Worth noting: the bill is deliberately less expansive than the EU’s NIS2 — and that’s a direct legacy of Brexit. Post-Brexit, nobody in Brussels can sue London for falling behind EU cyber standards the way it’s suing Dublin, Madrid, Paris, and The Hague. Whatever gap opens between UK and EU rules is one only Westminster can choose to close — or not.
Exhibit D: a Canadian province builds the same thing anyway
The quietest story of the four: on July 1, Ontario brought two regulations into force under its Enhancing Digital Security and Trust Act. One requires hospitals, school boards, and children’s aid societies to name a cybersecurity point of contact, run a maturity assessment every two years, and report serious incidents to the province. The other governs how school boards notify parents before handing kids’ digital data to outside apps.
Nobody made Ontario do this. No treaty, no directive, no court threat. A Canadian province simply looked at the same problem the EU and UK are wrestling with and built the same basic toolkit — designated contacts, periodic assessments, mandatory reporting — entirely on its own initiative.
The takeaway
Four governments, four totally different legal systems, and the same underlying story: the legislating part of cyber policy is mostly done. The next two years of Western cybersecurity governance won’t be decided by which bill gets introduced or which directive gets adopted — it’ll be decided by whether the countries that already passed these laws can actually staff, fund, and survive long enough to run them.


Leave a comment