ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

Wait 5 sec.

Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed.Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting it could soon become measured in minutes rather than months.In its July 2026 paper, ENISA’s view on Cybersecurity in the Frontier AI Era, the EU cybersecurity agency argues that advanced AI is compressing parts of the attack chain, from reconnaissance and vulnerability discovery to exploitation, lateral movement and data theft. The problem isn’t simply that AI can find more bugs. It’s that it can connect individual findings into a working attack.That distinction is important. Traditional security operations could often rely on the time required for a human attacker to research a target, understand a vulnerability, develop an exploit and deploy it. ENISA says that “grace period” is disappearing as automated systems take over more of the work.The agency describes a particularly worrying possibility: what it calls “negative time-to-exploit”. In practice, attackers could gain access to usable exploit information before defenders have even received or deployed a fix. ENISA says vulnerability weaponisation may now occur within 15 minutes of disclosure, while research cited in its report puts the median time from initial access to data exfiltration at 72 minutes.That puts traditional patch management under pressure. A company can receive a vulnerability advisory, send it through a change process, test the update, obtain approval and schedule deployment. An attacker does not have to follow any of those steps.ENISA calls this an “Authority Gap”: organisations may simply take longer to approve a defensive action than an AI-assisted attacker needs to exploit the weakness. The uncomfortable question is whether some environments will eventually need autonomous or near-autonomous patching because waiting for human approval could become the greater risk.That doesn’t mean companies should blindly automate every security update. Automated patching can break systems, disrupt critical services or introduce new bugs, and ENISA explicitly identifies verification of AI-generated patches as a new bottleneck. The challenge is therefore not automation versus humans, but deciding which decisions can safely happen at machine speed and which still require human approval.The scale of vulnerability discovery could create another problem. ENISA reports that one organisation went from roughly 80 CVEs in the first quarter of 2025 to almost 500 in the first quarter of 2026, then saw the volume rise to about 500 reports per day when frontier-AI tools were used.At that point, finding vulnerabilities is no longer the main bottleneck. Verification and remediation become the problem.Security teams already know what happens when too many alerts arrive at once. The difference is that AI could produce them at a scale humans cannot review manually. ENISA therefore recommends shifting resources from discovery alone toward faster triage, prioritisation and remediation, using approaches such as EPSS and VEX to focus scarce resources on vulnerabilities that are most likely to matter.There’s another issue that deserves more attention: low-severity vulnerabilities may become more dangerous when AI can chain them together. ENISA notes that frontier models can reason about application logic, credentials, configurations and API access rather than simply identify isolated coding flaws. That can turn several individually modest weaknesses into a practical attack path.This changes how defenders should think about risk. A vulnerability that looks harmless in isolation may become useful when combined with a weak credential, an exposed API or a poorly configured service.The same pressure is already affecting the disclosure process. ENISA says AI-generated vulnerability reports have begun to overwhelm parts of the open-source reporting pipeline, with platforms and maintainers struggling to separate useful findings from repetitive or poorly validated submissions. At the same time, the agency notes that the quality of AI-generated reports has improved, meaning the problem could become both more serious and harder to filter.There is a similar shift on the defensive side. ENISA recommends integrating AI into the software development lifecycle, using continuous threat modelling and automated testing rather than treating security as a review performed at the end of development. It also argues for AI-assisted incident response that can validate telemetry, prioritise events and contain the blast radius while keeping human oversight in place.That last condition matters. The answer to machine-speed attacks cannot simply be giving machines unlimited authority to fight back. Defensive AI needs its own controls, permissions and audit trails, especially when it can make changes to production systems.ENISA also recommends an “assume-breached” approach. Organisations should expect that some attacker will eventually get inside and design segmentation, monitoring and access controls so that one compromised component doesn’t automatically become a route into everything else.The agency sees this as a structural change rather than another temporary threat trend. It recommends machine-speed defence under the broader concept of “Cybersecurity as Code”, covering areas such as vulnerability management, incident response, security architecture and secure software development.Europe also has a policy problem to solve. NIS2, the Cyber Resilience Act and the AI Act already provide parts of the framework, but ENISA argues that Europe should develop common benchmarks for testing advanced AI models in cyber ranges, measuring exploitability and simulating chained attacks.The agency also sees value in European cybersecurity data. Incident reports, malware samples, vulnerability disclosures and threat intelligence could support trusted defensive AI models, provided organisations apply strong safeguards, anonymisation and access controls.For companies, however, the message is much simpler than the policy language suggests. Review your asset inventory, understand which systems are exposed, identify unsupported components and measure whether your detection and response can keep up with an attack that moves in minutes rather than hours. ENISA explicitly recommends near-real-time security operations, with single-digit-minute targets for mean time to detect and respond.The defenders who adapt fastest won’t necessarily be those with the most advanced AI model. They’ll be the ones that have already removed the basic obstacles: fragmented logging, excessive privileges, slow approvals, unknown assets and systems nobody wants to patch because nobody is quite sure what will break.AI is making attacks faster. It doesn’t change the basic rules of cybersecurity.It just makes the cost of ignoring them arrive much sooner.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Frontier AI)