ENISA's 2026 threat landscape, based on 8,257 incidents in calendar 2025, assesses that AI will highly likely increasingly support malicious operations and that 2026 will likely see more kill-chain phases directly enabled by AI, with possible human-out-of-the-loop proofs of concept. It notes AI applications becoming targets where they hold files, credentials, sessions or development environment access.
Why it matters
It is the EU cybersecurity agency's formal assessment of agentic misuse and of agents as targets.
Key facts
As stated in the sources, with where to find them.
- Dataset: 8,257 incidents from January 1 to December 31, 2025.Introduction, methodology
- ENISA assesses 2026 will likely see an increased number of kill-chain phases directly enabled by AI, with possible experimentation with human-out-of-the-loop proofs of concept.Executive summary
- AI applications and their ecosystems are increasingly targets where they have access to files, credentials, browser sessions or development environments.AI Threat section
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Sep 16, 2026
May 11, 2026
Sep 25, 2026
Sep 8, 2026
Jun 3, 2026
Nov 13, 2025