Guidelines  ·  2026-09-26

ENISA Threat Landscape 2026 (incl. AI-threat analysis)

GuidelinesMedium impactEuropean Union
ENISA published the flagship ENISA Threat Landscape 2026 on 22 September 2026 (Publication date: September 22, 2026; ISBN 978-92-9204-807-5, DOI 10.2824/0806036, TLP:CLEAR). The annual EU-wide threat intelligence report covers incidents from 1 January to 31 December 2025 (8,257 recorded incidents, 51.3% DDoS; ransomware, unpatched flaws and supplier compromise the main damage vectors) and includes an AI-threat chapter tracing the evolution of AI-powered malware Proof-of-Concept research and early signs of runtime/GenAI-assisted malware.
It is the authoritative EU reference framing the cyber threat landscape for NIS2/DORA-regulated entities and national authorities. The AI-threat content and the dependency/supply-chain analysis inform how EU organisations prioritise AI-related cyber risk at a time when agentic AI expands the attack surface.
EU security teams and regulators should incorporate ETL 2026 findings into annual threat modeling, risk registers, and board-level cyber-risk reporting, particularly the AI-threat and digital-dependency sections; use the methodology (updated ENISA CTL methodology, September 2026) for repeatable landscape assessments.
ENISA — ENISA Threat Landscape 2026 (publication page)ENISA — ENISA Threat Landscape 2026 (PDF)ENISA Threat Landscape 2026 press release
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →