Summary
- TNO, Nederlandse Spoorwegen, government cyber bodies, and private security companies are collaborating through the Prometheus initiative.
- The programme is testing AI capabilities including automated discovery and validation of software vulnerabilities.
- Its model combines shared technical development with questions about model security, supplier dependence, portability, and deployment inside critical infrastructure.
TNO, Nederlandse Spoorwegen, Dutch government cyber bodies, and private-sector security companies are building a shared programme to test how artificial intelligence can be used defensively as vulnerability discovery and attack automation become faster.
The Prometheus initiative brings together organisations including the Dutch National Cyber Security Centre, the National Coordinator for Security and Counterterrorism, the Dutch Institute for Vulnerability Disclosure, Vrije Universiteit Amsterdam, ESET, Northwave, Schuberg Philis, Software Improvement Group, and Dutch railway operator NS. Digital Holland coordinates the programme, while TNO is leading work on a proof of concept for using AI to detect weaknesses before attackers exploit them.
Rather than developing a single proprietary security product, the group is testing shared, market-neutral capabilities that participating organisations can evaluate and adapt. One use case involves AI systems automatically identifying and validating software vulnerabilities, while TNO is separately examining which models are safe enough for security work and which Dutch infrastructure providers could host them reliably.
The approach follows warnings from Dutch security organisations that AI can reduce the time and expertise required to carry out parts of an attack, while many defensive processes still depend on slower manual investigation, triage, patching, and approval. Techopia examined that threat assessment earlier this month when Dutch agencies warned that AI was accelerating offensive cyber capability.
Defence moves towards automation
Prometheus takes the next step by asking whether defenders can use similar automation without introducing another source of operational risk. Vulnerability scanning is an obvious candidate because security teams already work with large volumes of alerts, software inventories, and patch information, while the gap between disclosure and exploitation can be very short.
AI systems can potentially analyse code, correlate information across different tools, and investigate weaknesses more quickly than a human team could do alone. Yet placing a model inside a defensive workflow also gives that model access to sensitive technical information about the organisation it is supposed to protect, including software architecture, vulnerabilities, and systems that may form part of critical infrastructure.
TNO is therefore treating the safety of the models themselves as part of the project rather than assuming that an AI security tool is inherently secure. Its work includes AI security assessments, risk management, red-team testing, and techniques for adapting models so they can be deployed more safely inside controlled infrastructure.
That distinction is important because a useful cybersecurity model may need unusually deep visibility into an organisation’s technical environment. A system asked to identify exploitable paths through software has to understand much of the same information an attacker would want, turning model access, hosting, logging, prompt security, and data retention into security controls rather than ordinary procurement details.
Shared capability meets supplier dependence
The programme is also examining where defensive models should run and how easily organisations can change suppliers. Many capable general-purpose models are provided by companies outside Europe, while critical-infrastructure organisations often face tighter requirements around operational control, data handling, and continuity.
TNO’s stated concern is not that a foreign model is automatically unsuitable, but whether an organisation can move to another system within an acceptable period and at an acceptable cost. That makes model portability a resilience issue: a cyber-defence process built too tightly around one proprietary service may become difficult to maintain if commercial terms, regulation, technology, or security requirements change.
Prometheus is attempting to reduce another form of duplication as well. Large organisations can each build their own evaluation environments, red-team processes, and vulnerability-scanning experiments, but doing so independently repeats expensive technical work while producing results that may be difficult to compare.
A shared test environment can create common evidence about what particular models can do, where they fail, and what infrastructure is required to use them safely. Commercial security suppliers remain involved, so the programme is not intended to replace the market; instead, the public-private structure gives participating organisations a place to test capabilities before every member develops its own procurement and governance framework from scratch.
For critical sectors, that shared approach also reflects the interconnected nature of operational risk. Railways, energy systems, healthcare, logistics, water, and government services increasingly depend on overlapping digital infrastructure, so a vulnerability in one supplier or widely used software component can propagate across organisations that otherwise operate separately.
NIS2 has already pushed many European organisations towards more formal cyber-risk management, incident handling, and supply chain controls. AI adds another technology layer because defensive tools themselves can become part of the software and model supply chain that organisations have to assess.
The Dutch project is therefore less a contest over whether AI can outperform individual security analysts than an attempt to redesign the machinery around vulnerability management. Automation can shorten investigation and response times, although organisations still have to decide what a model is allowed to see, which actions it can take, whose infrastructure it runs on, and how its conclusions are verified.












