Sign in Check my fit
EN
Home / Horizon Europe / HORIZON-CL3-2026-02-CS-ECCC-02

Enhancing the Security, Privacy and Robustness of AI Models and Systems (SecureAI)

Open now · HORIZON Innovation Actions · HORIZON-CL3-2026-02-CS-ECCC-02

Next cut-off
15 Sept '26
in 9 days
Per grant
€4.2M
the call's own average
Grants expected
5
projects that will be funded
Funding rate
70%
the rest is your own money

In context of Horizon Europe

This grant€4.2M
The track runs to the largest grant in Horizon Europe (€171M). The median across the 482 calls we publish is €5.3M, this one is below it.

What this call funds

Expected Outcome:

Proposals are expected to contribute to one or more of the following:

  • Robust AI models and systems capable of resisting different classes of adversarial manipulation;
  • Innovative defence mechanisms for AI models and systems against new attack families;
  • Methodologies for detecting and mitigating attacks, such as data poisoning, backdoor exploitation and misclassification;
  • AI systems leveraging privacy-enhancing technologies that maintain data confidentiality and regulatory compliance, enabling trusted in-house AI deployments (e.g., for governments and enterprises).

Scope:

The increasing reliance on AI in cybersecurity, critical infrastructure, and decision-making processes raises concerns about the security and robustness of AI systems. As AI systems become more prevalent, they are increasingly targeted by adversarial attacks that manipulate inputs, compromise training data, or introduce hidden vulnerabilities. This topic aims to strengthen the resilience of AI systems and algorithms against various threats and attacks, such as enhancing their resilience against adversarial attacks, backdoor injections, and data poisoning. Proposals should develop real-time anomaly detection, mitigation techniques to defend against adversarial attacks and robust federated learning techniques, in synergies with leading efforts on AI transparency, and in compliance with the AI Act. The topic is expected to:

  • Develop robust AI models resistant to adversarial attacks. Exploring techniques to harden AI models and systems against adversarial perturbations, such as adversarial training, robust optimisation, and defence mechanisms that enhance the trustworthiness of AI.

Trimmed here, the full scope, expected outcomes and award criteria are on the official topic page ↗.

What applying costs you

ItemEstimateNote
Drafting effort6–8 weekssingle submission
Partner search4–8 weeksruns in parallel, and it is the part that slips
Your own money€1.8M30% of project cost, over the project's life
Time to first payment6–9 monthscut-off → evaluation → grant agreement

These are Bemzu's estimates from the call's structure (the number of stages and whether a consortium is required) not figures published by the Commission. Only the co-financing share is read from the call itself.

Where these conditions come from

Two kinds of row. Most are the sentence we read the condition from, quoted out of the call itself. Some say plainly that they are not a quotation but the programme's own rule for this type of action, the EU portal publishes a table of contents where the conditions should be, so for a Research and Innovation Action the rate comes from the rulebook rather than from the fiche.

ConditionQuoted from the call, or the rule behind it
Consortium sizeNot quoted from this call — Innovation Actions under the Horizon Europe rules are at least three independent legal entities from three different Member States or Associated Countries, at least one established in a Member State.
Funding rateNot quoted from this call — Innovation Actions under the Horizon Europe rules are funded at 70% of eligible costs for profit-making organisations, and 100% for non-profit legal entities — the rate shown here is the one that applies to a company.

Also open in HE

Become the beneficiary.

Eight questions, no account, nothing sent anywhere. You will know which of the 1526 open calls you can actually enter before you finish your coffee.

Check my fit