Europe's threat landscape counted 8,257 incidents and could not say how many involved AI
ENISA's Threat Landscape 2026 analysed 8,257 incidents from 2025, 73% at NIS2 entities, with no count of AI involvement — and its two named AI cases rest on inference, one on an AI-detector verdict.
The European Union Agency for Cybersecurity published its Threat Landscape 2026 on September 22, 2026, built on 8,257 incidents from the 2025 calendar year, 73% of them at organisations that NIS2 classifies as essential or important. The report devotes a section to artificial intelligence but gives no number — nowhere does it say how many of those 8,257 incidents involved AI, and in both of its concrete examples of AI used in real attacks the AI involvement is inferred rather than observed, one of them partly from an AI-detector verdict. That matters because the same report forecasts that 2026 will "likely" see kill-chain phases directly enabled by AI, which means Europe's regulated entities are being told to expect a shift they currently have no measured baseline against.
The short version
ENISA's Threat Landscape is the EU's annual stocktake of cyber threats. It is not law, but it is the closest thing Europe has to an official baseline: written by the agency that supports NIS2 implementation, and classifying its victims using NIS2's own categories. Boards and regulators quote it.
The 2026 edition covers 2025. Its headline findings are unsurprising: distributed denial of service accounted for 51.3% of recorded incidents, unauthorised access 39.5%, phishing 77.8% of social-engineering activity, and public administration was the most affected sector at 31.8%. Ideology-driven operations made up 57.3% of activity, financially motivated 29.2%.
On AI, the report's position is measured and, on its own evidence, defensible: attackers are using AI to do existing things faster and at larger scale, not to do new things. ENISA writes that "reporting over 2025 indicates that attackers primarily use consumer-grade AI tools to augment existing skills and adapt attack vectors rather than to achieve breakthrough capabilities."
The gap worth noticing is not between ENISA and reality. It is between what ENISA can measure and what ENISA expects. The measured part has no AI figure in it at all. The expected part, in the same document, includes "possible experimentation of Human-out-of-the loop proof of concepts." Two reports published in the following ten days — Google's threat-intelligence group on September 30, 2026 and Microsoft's Digital Defense Report in the first days of October — describe that compression as already happening.
Timeline
- January 1 – December 31, 2025 — the reporting period for ENISA Threat Landscape 2026. ENISA notes a six-month overlap with the previous edition.
- November 13, 2025 — Anthropic publishes its account of a state-nexus group running an espionage campaign largely through an agentic AI system. ENISA cites this report in its AI section (footnote 57).
- November 28, 2025 — Sysdig's Threat Research Team observes the AWS intrusion that becomes ENISA's "8 minutes" data point; Alessandro Brucato and Michael Clark publish it on February 3, 2026.
- February 10, 2026 — Darktrace publishes its analysis of an AI-generated malware sample exploiting React2Shell, by Nathaniel Bill and Nathaniel Jones — ENISA's example of malware "leveraged in real-world operational contexts."
- September 22, 2026 — ENISA publishes Threat Landscape 2026 (TLP:CLEAR).
- September 30, 2026 — Google Threat Intelligence Group publishes "Vulnerability Discovery and Exploitation Trends in the AI Era."
- October 2, 2026 — the date Microsoft's MDDR landing page gives for the Digital Defense Report 2026; press coverage appeared on October 1.
What we know
The dataset. ENISA states that its "analysts collected and analysed 8 257 incidents, mainly based on information from open sources, as well as anonymised information shared by EU Member States" and the ENISA Cyber Partnership Programme. The report is explicit about what that means: "ENISA appreciates that open sources and information shared voluntarily do not constitute a complete picture of the cyber threat landscape." It lists reporting granularity, temporality and sectoral categorisation as limitations, and notes that cyberespionage campaigns are often documented six months to more than four years after the fact.
The NIS2 framing. ENISA reports that essential and important entities "represent 73% of the total" targeted organisations. This is the sentence that makes the report regulatory furniture rather than a trade publication: it maps the threat picture directly onto the population that NIS2 obliges to manage risk and report incidents.
What ENISA says about AI. The AI section runs across pages 15 to 17. ENISA "continued to observe an increasing use of Artificial Intelligence (AI) by malicious cyber threat groups, including cybercriminals, State-nexus and Information Manipulation Sets (IMS), primarily to facilitate or enhance their activities to optimise the speed and success rates of their operations overall." The named applications are phishing at scale, influence-campaign content, synthetic identities for remote-worker schemes, reconnaissance, script development and post-exploitation, supported by "'turnkey' AI-assisted toolkits resold via underground marketplaces." ENISA also records "more industrialised methods for ensuring reliable, affordable and anonymised access to premium LLM tiers," and that groups "continue to experiment with methods for bypassing closed model safeguards and constraints, including steganography and indirect prompt injection."
AI as target. ENISA states that "the integration of AI systems into enterprise environments creates a new attack surface," that "AI applications and their ecosystems are increasingly becoming targets, particularly where they have access to files, credentials, browser sessions or development environments," and that "AI-linked developer environments and software supply chains are another area of concern."
What is missing. The report gives no count or percentage of incidents involving AI, anywhere. Every other headline figure appears in body text with a denominator. The AI section has no equivalent.
The outlook. ENISA assesses that "artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations," and that "it is also likely 2026 will see an increased number of the kill chain's phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts." It adds that "while outside the reporting period, ENISA cannot overlook the evolution and emergence of advanced AI models in 2026, which have already shaped the threat landscape, notably through Proof of Concept (PoC) research related to AI-powered malware, and the first signs of malware using generative AI at runtime."
Technical analysis
The interesting work in this report is in its footnotes: the two sentences that give ENISA's AI section its concreteness are both single-source.
The AI-generated malware example. ENISA writes that "the reporting period saw further proliferation of likely AI-generated malware leveraged in real-world operational contexts, as seen with an LLM-produced sample reportedly exploiting the React2Shell vulnerability," citing Darktrace. Darktrace's post describes a Python exploitation framework — a scanner and exploitation toolkit that dropped the XMRig cryptocurrency miner — targeting CVE-2025-55182, a remote code execution flaw in Next.js server components.
Three details in Darktrace's own write-up deserve to travel with the claim. First, the sample came from "a recently observed intrusion against Darktrace's Cloudypots environment" — a honeypot, not a victim network. Second, the activity was identified in early 2026, and the post is dated February 10, 2026, which puts it after ENISA's December 31, 2025 cut-off even though ENISA places it in a sentence about "the reporting period." Third, the LLM attribution is heuristic: unusually thorough code commenting, which the researchers contrast with the "overwhelming majority of samples analysed" that "do not feature this level of commentary"; the string "Educational/Research Purpose Only," read as evidence the author jailbroke a model by framing the request as educational; and a GPTZero test indicating the code "was likely generated using an AI model." Darktrace states plainly that its information "should not be taken as confirmed attribution."
Our assessment: ENISA's double hedge — "likely AI-generated," "reportedly exploiting" — is doing real work here, and it is to the agency's credit that the hedge is there. But a reader taking the sentence at face value comes away believing AI-written malware was confirmed in operational use against real European targets during 2025, and none of those four elements is what the source says. Note also that the strongest single indicator is an AI-detector verdict — a contested instrument on prose, and weaker still on code, which is far more stylistically constrained.
The 8-minute example. ENISA writes that "AI-assisted cloud intrusion reportedly achieved administrative access within 8 minutes," citing Sysdig. Here ENISA's rendering is faithful: Sysdig's timeline puts the compromise of the admin user at the 0:08:00 mark, having completed "the entire sequence from credential theft to successful Lambda execution in just eight minutes, including reconnaissance to identify admin users and roles," and elsewhere states the actor "went from initial access to administrative privileges in less than 10 minutes." The full operation ran about two hours and touched 19 AWS principals, abusing Lambda, Bedrock and GPU resources.
The AI involvement, again, is inferred rather than observed. Sysdig's indicators are the injected Lambda function's comprehensive exception handling alongside Serbian-language comments, attempts to assume roles in two fabricated AWS account numbers, and a reference to a GitHub repository that does not exist — patterns the researchers describe as consistent with AI hallucination. They present these as indicators, not proof.
Why this is structurally hard, not sloppy. The honest reading is that nobody can count AI involvement from the outside, and ENISA's methodology makes it harder than most. If attackers are using AI to write phishing copy and enumerate roles faster, the artefact left in a victim's logs is a phishing email and some API calls. There is no field for it. GTIG, working the same problem from the vulnerability side, says so explicitly: public data "significantly undercount vulnerabilities discovered by AI" because "public CVE repositories do not yet feature uniform metadata tags for AI attribution, requiring manual heuristic tracking," and because major cloud and SaaS providers "routinely remediate AI-surfaced vulnerabilities directly in production without requesting formal CVE IDs."
Our assessment: ENISA's "augmentation, not breakthrough" conclusion is the right conclusion from its evidence, and it is a useful corrective to vendor marketing. The problem is that the same evidentiary weakness that keeps the number out of the report also keeps it from being falsifiable. An AI-augmented intrusion and a conventional one leave the same incident report. A methodology that cannot see AI in the data will keep returning "no breakthrough" for as long as the breakthrough is invisible to it — which is precisely the period in which ENISA's own outlook says the shift will begin.
The contrast with the last fortnight. GTIG's September 30, 2026 report, which this site covered on October 1, found that "exactly 50% of all AI-discovered vulnerabilities result in Remote Code Execution (RCE), compared to just 26% across the broader CVE ecosystem," that disclosures rose from 5,045 in January 2026 to 10,740 in August 2026, and that GTIG recorded 141 vulnerabilities disclosed and exploited between January and August 2026, "surpassing the total number of vulnerabilities exploited for the full year of 2025 (127)." Microsoft's Digital Defense Report 2026 states that exposed cloud workloads were attacked after an average of 5.3 hours, and that "AI is compressing attack timelines, lowering the cost of sophisticated capabilities, and enabling attackers to operate with greater speed, scale, and autonomy."
These are not contradictions of ENISA. They are measurements of 2026 set against ENISA's measurement of 2025, by organisations with first-party telemetry ENISA does not have. Our assessment: the divergence is mostly an artefact of vantage point and lag, and the practical consequence is that anyone treating ETL 2026 as a current picture of AI-enabled threat is reading a report about last year.
What remains unclear
- How ENISA would count AI involvement if it wanted to. The report does not describe an inclusion rule for AI-related incidents, so we cannot tell whether the absence of a figure reflects a deliberate judgement that the data will not support one, or simply that the field is not collected.
- Whether the React2Shell sample belongs in the 2025 picture at all. Darktrace identified the activity in early 2026 and published on February 10, 2026. ENISA presents it inside a sentence about the reporting period. We cannot reconcile those from the published text.
- What ENISA's "first signs of malware using generative AI at runtime" refers to. The claim appears in the outlook; the report does not name the sample in the passage we read.
- The status of ENISA's workflow-integration example. ENISA illustrates AI "becoming more directly integrated into attack workflows" with the "AI in the Middle" technique, citing Check Point research into turning web-based AI services into command-and-control proxies, and words it as something that "could potentially be abused." On ENISA's own phrasing this is capability research rather than an observed campaign; we were unable to read the Check Point post directly and are not treating it as an in-the-wild finding.
- How the Anthropic case was weighted. ENISA cites Anthropic's November 13, 2025 report, in which Anthropic assessed with high confidence that a Chinese state-sponsored group ran a campaign against roughly thirty targets with 80–90% of the work done by AI and only 4–6 human decision points, compromising a small number. ENISA gives it one hedged sentence and does not say whether it informed the "no breakthrough capabilities" judgement or sits against it.
Lessons and what to do
For security teams. Do not use ETL 2026 as your AI threat baseline; use it as your compliance-adjacent baseline and build the AI picture from first-party telemetry. Concretely: start recording AI involvement as a field in your own incident records now, with an explicit rule for what counts, so that in a year you have a denominator nobody can give you today. The indicators used in this story are available to you — hallucinated identifiers that do not resolve, references to non-existent repositories or accounts, uniform code commentary in dropped scripts.
For AI builders. ENISA's targeting language is the operative part for you: AI applications become targets "particularly where they have access to files, credentials, browser sessions or development environments." That is a description of every agent deployment with tool access. Treat the agent's credential scope, not the model, as the asset under threat, and assume the developer environment is in scope — an assumption that recent incident-response findings support directly.
For leadership and policy. Two things follow. First, if your organisation is an essential or important entity under NIS2, you are inside ENISA's 73% and a regulator may reasonably expect you to have read this report — but reading it will not tell you your AI exposure, and you should not let a board paper imply otherwise. Second, the missing number is an argument for standardised metadata, which is exactly what GTIG asks for from the vulnerability side. A reporting regime that records whether AI was involved in an incident is cheap compared with the alternative of arguing about it for another three years. Europe already has the reporting channel; what it lacks is the field.
For anyone quoting the report. Carry the hedges. "Likely AI-generated" and "reportedly" are not padding; in this case they are the difference between a honeypot sample flagged by an AI detector and confirmed AI-written malware in European networks. The pattern of a cautious primary hardening into a confident headline is one this site has had cause to note before, most recently with a regulator that had not confirmed the thing being reported.
Sources
Primary
- ENISA, Threat Landscape 2026, published September 22, 2026, TLP:CLEAR — PDF · ENISA Threat Landscape topic page
- Darktrace, Nathaniel Bill and Nathaniel Jones, "AI/LLM-generated malware used to exploit React2Shell," February 10, 2026 — post
- Sysdig Threat Research Team, Alessandro Brucato and Michael Clark, "AI-assisted cloud intrusion achieves admin access in 8 minutes," February 3, 2026 — post
- Anthropic, "Disrupting AI espionage," November 13, 2025 — report
- Google Threat Intelligence Group, "Vulnerability Discovery and Exploitation Trends in the AI Era," September 30, 2026 — report
- Microsoft, Digital Defense Report 2026 — microsoft.com/mddr
- Check Point Research, "AI in the Middle: turning web-based AI services into C2 proxies" — post (cited by ENISA at footnote 63; not independently read for this analysis)
Coverage: