Geopolitics

Policy Paper

Strengthening Transatlantic AI Governance and Cybersecurity Coordination to Counter Strategic Competition

Strengthening Transatlantic AI Governance and Cybersecurity Coordination to Counter Strategic Competition

The United States and European Union are uniquely positioned to lead the global governance of artificial intelligence (AI) and cybersecurity.

The United States and European Union are uniquely positioned to lead the global governance of artificial intelligence (AI) and cybersecurity.

New York City, USA / Washington, DC, USA

Alexa Dominique
Pascual
  • Geopolitics

    Policy Paper

Strengthening Transatlantic AI Governance and Cybersecurity Coordination to Counter Strategic Competition

The United States and European Union are uniquely positioned to lead the global governance of artificial intelligence (AI) and cybersecurity. They collectively form the world's largest democratic technology market, house leading research institutions, and include many of the companies innovating in the AI industry. However, transatlantic divergence on issues of AI regulation, cybersecurity, and data governance have undermined the United States and European Union's ability to promote global norms and collaboratively respond to new threats.

China has also advanced its role as a technology standard-setter with ambitions like the Digital Silk Road initiative and Next Generation Artificial Intelligence Development Plan. Through these projects, China invests in 5G telecommunications infrastructure, cloud computing, AI development, and technology standards abroad. Experts such as Adam Segal and Elsa Kania have written that China seeks to expand its vision of cyber sovereignty, which increases state control over cyber governance and expands Beijing's influence over all parts of the technology ecosystem. The United States and European Union can provide an alternative vision grounded in technological innovation, open markets, private-sector leadership, and individual rights.

The Strategic Challenge

The United States and European Union need a standing transatlantic consultative mechanism on AI governance and cybersecurity via the U.S.–EU Trade and Technology Council (TTC). EU regulations, such as the EU AI Act and GDPR, are grounded in rights-based governance, whereas the United States historically emphasizes innovation and regulatory flexibility. Current uncertainty about how technology companies will be regulated hinders fast, effective responses to cyberattacks. Neither the US nor the EU is likely to adopt the other’s regulatory model in its entirety. Instead, in order for this policy to work, both sides should pursue a pragmatic compromise that combines the EU’s emphasis on accountability and safeguards for high-risk AI systems with the US’s focus on innovation and regulatory flexibility. The EU should, however, maintain stronger oversight of high-risk applications while allowing flexibility for low-risk technologies; the US, by contrast, should adopt and implement more consistent accountability measures for AI systems that pose significant security, privacy, or societal risks. If these approaches are implemented, this will allow both partners to preserve their core regulatory principles while developing interoperable standards to address shared security challenges. 

The need for such a compromise is becoming increasingly urgent as the scale and sophistication of cyber threats continue to escalate.  Cybersecurity Ventures estimates that the cost of cybercrime will surpass $10.5 trillion yearly. Threat actors are also weaponizing AI to create more sophisticated attacks. AI technologies enable everything from phishing and ransomware to deepfakes and autonomous cyberattacks. In the absence of a transatlantic response, China’s continued investments in AI and digital infrastructure will continue to expand its capacity to shape tech norms and governance models around the world.

The SolarWinds hack, discovered in 2020, was a significant cyber espionage campaign that compromised thousands of organizations, including US government agencies and private companies. Attackers infiltrated SolarWinds and inserted malicious code into updates for its Orion network management software. As a result, about 18,000 customers unknowingly installed the compromised update, granting attackers access to their systems. This supply chain attack exploited trust in a third-party vendor rather than targeting victims directly. U.S. officials attributed the breach to Russia’s foreign intelligence service, the SVR, and determined the primary goal was intelligence gathering. The incident affected several federal agencies, including the Departments of Homeland Security, the Treasury, Commerce, and Energy, as well as major technology firms. The incident revealed critical weaknesses in Western digital infrastructure and demonstrated the capacity of state-sponsored actors to exploit software supply chains to access sensitive networks. Such vulnerabilities may also be targeted by other strategic competitors, such as China, given its close ties and its intelligence-sharing operations with Russia. The risk of competing state actors conducting cyber operations against the transatlantic alliance, businesses, and critical infrastructure may pose a great risk to international security. For the EU, the SolarWinds incident underscored the risks of shared digital dependencies with the US and emphasized the necessity for enhanced transatlantic cooperation in cybersecurity, intelligence sharing, and supply chain security. 

The SolarWinds attack exposed critical vulnerabilities in software supply chains and demonstrated how fragmented cybersecurity systems leave governments and businesses vulnerable to cyber threats. In response, the US and the EU should adopt a tiered regulatory framework that imposes strict safeguards on high-risk AI applications while maintaining flexibility for lower-risk technologies that support innovation and economic growth. Misinformation and disinformation are ranked among the top five global risks in terms of likelihood over the next decade, according to the World Economic Forum. Advances in generative AI have made it easier than ever for state and non-state actors to create deepfakes, synthetic media, and influence operations that can target democratic elections, undermine public confidence in democratic institutions, and weaken democracy itself. Without transatlantic coordination, adversaries will continue to use cyber operations to target U.S. and European interests with relative impunity.

Data Governance and Secure Information Sharing

Data governance is a critical issue for transatlantic cooperation. The Schrems II decision effectively overturned the EU–U.S. Privacy Shield framework and exposed continuing rifts over privacy, surveillance, and data transfers. In the absence of interoperable standards, democratic allies will be hamstrung in their ability to jointly respond to cyberattacks, AI-enabled disinformation, and foreign influence campaigns.

The United States and European Union should prioritize interoperability over trying to achieve complete alignment of regulations. Bilateral data flows should enable cybersecurity information sharing and AI monitoring efforts that can operate within existing privacy protections. Privacy-enhancing technologies like federated learning, homomorphic encryption, and secure multiparty computation will help companies and organizations cooperate without sharing sensitive data.

The US-EU Trade and Technology Council  should lead an effort with government, academia, tech companies, NGOs, and cybersecurity experts to research trusted standards for secure cross-border collaboration. Common protocols would ensure all parties know what types of data can be shared during ransomware attacks, AI-enabled disinformation operations, and other cyber incidents. This would improve resilience while upholding current privacy standards.

Joint Public–Private Cyber Defence System

Governments cannot defend cyberspace on their own. Most of the hardware and software that powers today’s economy—including cloud platforms, telecom networks, generative AI, and social media—is owned by private companies. Cybersecurity is only as strong as the willingness of these firms to detect threats and work with governments to address them.

The United States and European Union should work together to create a Joint Public–Private Cyber Defence Compact. This initiative would formalize channels for collaboration between governments; technology companies; nongovernmental organizations (NGOs); universities; and independent academics and cybersecurity researchers.

Technology companies can detect malicious behavior before governments because they maintain many of the systems and networks that adversaries target. NGOs and academic institutions offer independent legal analysis, open-source research, and policy experience that can improve attribution while limiting politicization.

There are already many positive examples of this kind of partnership. Microsoft’s Threat Intelligence Center maps state-sponsored cyber threats and assists governments in responding to attacks. Meta’s Threat Disruption unit helps take down influence operations that target democracies. Anthropic is also pursuing AI safety and risk-mitigation research. Each of these efforts could be amplified by a formal public-private cybersecurity compact.

This agreement should include legal liability protections for companies that share cyber threat data. It should standardize reporting requirements for AI-enabled incidents, and it should increase the scope and scale of joint cyber defense exercises. Special emphasis should be paid to ransomware attacks, election security, and supply-chain vulnerabilities.

Sustained Coordination and Strategic Competition

Institutionalized cooperation will be needed to ensure long-term success. The U.S. and E.U. should create a standing Transatlantic AI and Cybersecurity Task Force to provide annual risk assessments, track emerging technology trends, identify regulatory gaps, and synchronize responses to shifts in malicious threat activity. This task force should consult with NATO, the OECD, and the United Nations to better align security priorities with economic and governance initiatives.

Increased coordination would benefit democratic resilience and improve all allies’ ability to compete in this space. Malicious cyber activity is often a costly endeavor for perpetrators when democratic nations utilize shared reporting standards, coordinated attribution strategies, and public-private partnerships.

Policy Recommendation: Transatlantic AI Response Mechanism

The United States and EU should establish a Transatlantic AI Response Mechanism (or use an existing framework) to coordinate the detection, analysis, attribution, and response to AI-enabled cyber attacks. The goal would be to connect governments with cyber agencies, tech companies, NGOs, and think tanks to provide technical analysis and unbiased threat intelligence.

The group could agree to unified reporting standards, track attacks against critical infrastructure, and collaborate on responses to deepfake propaganda, cybersecurity breaches, and foreign interference. Once agreed-upon standards for attribution have been reached, member nations can respond collectively with everything from diplomatic efforts, sanctions, platform-level enforcement, and defensive cyber operations.

Future Outlook

The future of transatlantic AI governance depends on both government coordination and the active involvement of the private sector and civil society stakeholders. The US-EU Trade and Technology Council (TTC) should move beyond a government-only forum and formally include technology companies, NGOs, universities, and independent researchers in its negotiations and designate them as “negotiators” to this committee. Since private firms primarily develop and deploy AI, industry engineers and technical experts often have deeper insight into emerging capabilities, vulnerabilities, and implementation challenges than policymakers. NGOs and academic institutions also provide independent research, human rights expertise, and evidence-based policy analysis that can strengthen decision-making. Formally including these stakeholders in TTC working groups would make negotiations more informed, practical, and adaptable to technological change. Public-private partnerships should help shape policy development from the beginning, not just during implementation. Integrating technical expertise with policy and regulatory discussions will enable the TTC to develop more effective and widely accepted AI governance frameworks. This multi-stakeholder approach will strengthen democratic technology governance, improve regulatory alignment, and enhance the transatlantic alliance’s ability to compete with governance models promoted by authoritarian states. 

Conclusion

The lack of cohesion in AI regulation and cybersecurity poses a growing strategic weakness for both the U.S. and EU. Rising cybersecurity threats in the form of cyberattacks, disinformation, and foreign interference demand closer transatlantic collaboration. Through increased regulatory interoperability, secure data-sharing practices, public-private partnerships, and the creation of a Transatlantic AI Response Mechanism, the United States and EU can build resilience and encourage innovation. Working together to develop a democratic model of AI security and governance will help prevent future threats and present a strong alternative to autocratic systems.

Written by
Alexa Dominique
Pascual

International affairs professional advancing youth inclusion, AI governance, and sustainable development through diplomacy and global cooperation.

Written by
Alexa Dominique
Pascual

International affairs professional advancing youth inclusion, AI governance, and sustainable development through diplomacy and global cooperation.

Follow me

FIND MORE

Other works by

Other works by

Alexa Dominique