ENISA: AI is expanding the attack surface of European systems
September 23, 2026

ENISA's 2026 threat landscape reviews 2025: 73 percent of targets were entities covered by NIS2. AI assists attackers while creating a new class of vulnerable systems.
What this is about
The EU cybersecurity agency ENISA published its threat landscape for 2025 on September 22, 2026. The assessment combines publicly reported events with anonymized information from member states and the ENISA Cyber Partnership Programme. Its central finding is that familiar attacks still dominate, while dependencies among service providers, supply chains, and AI systems extend their reach.
Seventy-three percent of recorded targets were essential or important entities under the NIS2 Directive. Public administration was the most frequently targeted sector, accounting for 32 percent of incidents. ENISA gives AI a dual role: attackers use it to support operations, while newly integrated AI systems create additional attack surfaces.
What the threat landscape actually shows
ENISA groups events into cybercrime, state-linked activity, foreign information manipulation, hacktivism, and vulnerability exploitation. DDoS attacks represented 51 percent of recorded cases but were mostly low impact. The agency still considers ransomware the most consequential incident type in the short term.
ENISA could identify an initial access vector for only five percent of unauthorized-access cases. Within that small subset, 60 percent involved a vulnerability. More than 48,000 new CVE records were also published in 2025, a 22 percent increase from the previous year. These figures describe different populations and must not be combined into a single success rate.
Why it matters
Many organizations set defensive priorities according to the number of alerts they receive. That can mislead: frequent DDoS attacks are highly visible, while one less common supply-chain compromise can affect many customers at once. ENISA therefore emphasizes dependencies on third parties, shared platforms, and digital infrastructure. The gap between importance and maturity is especially serious: ENISA points to high criticality but below-average security maturity in health, rail, maritime, drinking water, wastewater, and public administration. A failure there does not stay inside a computer; it can affect essential services and daily life.
AI intensifies this situation in two ways. It reduces effort and language barriers for phishing, translation, and synthetic audio or video. At the same time, models, training data, interfaces, and agents become targets themselves. A company must therefore ask not only whether employees use AI safely, but also what permissions an AI system has, which data it processes, and which external services operate behind it.
In plain language
A modern IT system resembles a chain of power strips. Each strip may have passed inspection, but too many connected links make the whole setup fragile. AI is a new appliance that saves effort and performs useful work while adding more cables and sockets. Security therefore depends on the entire chain, not just the appliance.
A practical example
A municipal utility operates 2,000 workstations, uses an external help desk, and introduces an AI assistant for support tickets. A crafted message causes the assistant to send confidential ticket data to an outside endpoint. The immediate incident begins with one account, but shared administrative privileges could spread it across several systems. A sensible response therefore checks not only the model's text filter but also access rights, logs, supplier contracts, and emergency shutdown paths.
Scope and limits
- The data is not a complete EU census: ENISA combines open and voluntarily shared information; many incidents remain unknown.
- Frequency is not the same as harm: A 51 percent DDoS share does not mean DDoS caused the greatest economic losses.
- AI is rarely the sole cause: The report mainly describes AI as an amplifier and an additional attack surface, not as the autonomous origin of every new attack.
The threat landscape is useful for priorities and scenarios, but it is not an exact forecast for any single organization.
SEO & GEO keywords
ENISA Threat Landscape 2026, EU cybersecurity, NIS2, AI security, ransomware, DDoS, supply-chain attack, vulnerabilities, public administration, FIMI, CVE, critical infrastructure
💡 In plain English
ENISA still sees ransomware, DDoS, and exploited vulnerabilities as central EU risks. AI makes familiar attacks easier and adds new targets in models, data, and interfaces.
Key Takeaways
- →Seventy-three percent of recorded targets were essential or important NIS2 entities.
- →Public administration was the largest target sector at 32 percent.
- →DDoS accounted for 51 percent of cases, while ransomware remained the most consequential in the short term.
- →More than 48,000 new CVEs represented a 22 percent increase from 2024.
- →AI supports attacks while also creating additional vulnerable components.
FAQ
What period does the ENISA report cover?
The 2026 report analyzes events observed from January 1 through December 31, 2025.
Is DDoS the most dangerous attack type?
DDoS was most frequent at 51 percent, but usually low impact. ENISA considers ransomware more consequential in the short term.
How is AI used in attacks?
ENISA cites scaled information manipulation, translation, and synthetic media. AI systems themselves are also becoming targets.
What should organizations do?
They should assess dependencies, suppliers, access rights, and shutdown paths together rather than evaluating individual AI models alone.