EU cyber and science agencies acknowledge testing Chinese AI models
ENISA and the Joint Research Centre confirm for the first time that they are stress-testing open-source models from China.
By Katarzyna Wisniewska · Filed Friday, 9 October 2026 · Last updated 07:40 CET
What happened
The European Union's dedicated cybersecurity agency, ENISA, alongside the European Commission's in-house scientific service, the Joint Research Centre, have confirmed for the first time that they are actively testing Chinese open-source artificial intelligence models. The acknowledgement marks an official recognition that European public researchers are examining software architectures developed in China to evaluate their performance, safety, and potential technical risks. While open-source artificial intelligence allows developers and researchers globally to inspect, modify, and run software code freely, its deployment across critical sectors requires stress-testing. ENISA—the body charged with keeping the bloc's digital infrastructure resilient—and the Joint Research Centre—the Commission's primary research arm tasked with providing scientific advice to policymakers—are evaluating these systems to understand their technical capabilities.
Why it matters
For European citizens and businesses, the security of artificial intelligence models embedded in everyday digital services or adopted by local tech firms is a growing concern. If open-source models originating from China gain widespread traction among European developers, regulators and cybersecurity authorities need to know whether those systems contain software vulnerabilities, hidden flaws, or unexpected data-handling behaviours. Understanding how these tools behave allows European authorities to establish informed security baselines and protect digital infrastructure. It ensures that as open-source code flows across borders, European users do not unknowingly inherit unseen cybersecurity risks or technological dependencies built into foreign software.
The Brussels angle
Inside the EU bubble, the revelation touches on the balance between political rhetoric and technical reality. Brussels frequently preaches the virtues of European digital sovereignty and warns against over-reliance on third countries. Yet in cybersecurity and scientific research, authorities cannot assess or regulate software they refuse to touch. The situation illustrates the institutional pragmatism required of EU bodies: before officials can draft security guidelines or evaluate digital risks, technical experts must actually run the code. By acknowledging that their main cyber and scientific arms are examining Chinese models, European institutions demonstrate that understanding potential risks takes precedence over institutional hesitation.
What happens next
The technical assessments carried out by ENISA and the Joint Research Centre will help inform future evaluations across the European Commission. As EU institutions work to implement broader digital rules and security frameworks, findings from these tests are expected to feed into technical guidance for member states and industry actors. Future outputs from both agencies will likely focus on benchmark results and technical risk profiles for open-source systems operating within European digital networks.
Written from these sources
Facts are extracted from primary institutional material and written independently by The Gazette desk.
Correspondent, The Brussels Bubble · Bubble politics and manoeuvring
Katarzyna WisniewskaKatarzyna Wisniewska writes The Brussels Bubble: the rivalries, leaks, coalitions and diplomacy practised off the record in and around the institutions.
More from Katarzyna Wisniewska →The Brief
Brussels, decoded, every morning. What happened, what it means, one good dry joke.