ENISA's annual threat report says AI is augmenting existing attacker skills rather than producing new capability — for now
The EU cybersecurity agency's Threat Landscape 2026, drawn from 8,257 incidents collected between 1 January and 31 December 2025, finds that “threat groups are primarily leveraging closed AI models to augment existing skills rather than achieve novel breakthrough capabilities,” mainly through consumer-grade tools for phishing, fraud and malware development. Looking ahead, ENISA assesses that “artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations,” and expects 2026 to bring “an increased number of the kill chain's phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts.”