Chronicle/Policy & standards

ENISA Threat Landscape 2026 expects more kill-chain phases enabled by AI in 2026

PolicyGuidanceSignificance assistant-drafted

ENISA's 2026 threat landscape, based on 8,257 incidents in calendar 2025, assesses that AI will highly likely increasingly support malicious operations and that 2026 will likely see more kill-chain phases directly enabled by AI, with possible human-out-of-the-loop proofs of concept. It notes AI applications becoming targets where they hold files, credentials, sessions or development environment access.

Why it matters

It is the EU cybersecurity agency's formal assessment of agentic misuse and of agents as targets.

Key facts

As stated in the sources, with where to find them.

  • Dataset: 8,257 incidents from January 1 to December 31, 2025.Introduction, methodology
  • ENISA assesses 2026 will likely see an increased number of kill-chain phases directly enabled by AI, with possible experimentation with human-out-of-the-loop proofs of concept.Executive summary
  • AI applications and their ecosystems are increasingly targets where they have access to files, credentials, browser sessions or development environments.AI Threat section

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records