lagen.nu
ENISA’s view on Cybersecurity in the Frontier AI Era

ENISA’s view on Cybersecurity in the Frontier AI Era

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2026-07-07
Språk
engelska
Ämnesord
Artificial Intelligence and Next Gen Technologies
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.
TLP: CLEAR

ENISA’s view on Cybersecurity in the Frontier AI Era

JULY 2026

ABOUT ENISA CONTACT AUTHORS ACKNOWLEDGEMENTS LEGAL NOTICE COPYRIGHT NOTICE

Table of contents

EXECUTIVE SUMMARY IMPACT ON VULNERABILITY & PATCH MANAGEMENT 11 SECURITY FUNDAMENTALS MATTER MORE THAN EVER THE WAY AHEAD: BUILDING AI-RESILIENT DEFENCES 13

Executive summary

Frontier AI models are challenging traditional To identify the appropriate response security paradigms by compressing the to the emergence of AI and its impact vulnerability management lifecycle and attack on cybersecurity, ENISA held a series of chain, from discovery to exploitation. The engagements where our stakeholders frontier model landscape is evolving rapidly; raised the following: it is expected that open-weight models may reach a similar level of capability within • there is the likelihood that attackers 9 to 12 months and that existing models will have access to exploits before when coupled with skilled security experts fixes are released (so called 1 2 can yield comparative results . While ENISA negative time-to-exploit ); acknowledges the potential benefits of these • AI amplifies challenges related to technologies to improve security, this note legacy systems and products that will aims to focus on some of the immediate and soon reach or have reached their endmid-term cybersecurity challenges. of-life and end-of-support; This note provides national competent • due to an expected increase in patch authorities in Member States and release frequency, patching may lead EU policymakers, defenders, and to an increase in service disruptions; service providers with an initial set of recommendations to support them in • open-source require a strategy to their respective roles towards developing prevent maintainers to be overloaded the necessary operational capabilities to face machine-speed threats. The with vulnerability reports; recommendations are not an all-inclusive • SMEs, part of the backbone of checklist. ENISA aims to further refine and expand these recommendations in close the EU economy, may require cooperation with Member States and EUIBAs additional support, in particular in and will align these to upcoming European terms of guidance and access to the Commission Action Plan. latest models;

• cybersecurity should be positioned • architectural solutions must use as a strategic use case for European an assume-breached mindset, investment in AI, as a need exists for while acknowledging that zero trust the EU-based organisations to have approaches will require a deep access to and develop their own transformational process; AI models, • Cybersecurity as Code: means • security fundamentals matter more machine-speed threats need to than ever in the age of AI; be addressed with machine-speed defences (Vulnerability Management • resources need to be shifted from as Code, Incident Response as Code, discovery to risk-based prioritisation Security by Design as Code, Security of vulnerabilities through higher-speed Architecture as Code); triage, remediation and risk reduction; • AI-driven defensive capabilities that • defensive AI tooling need to be can detect, correlate and respond to integrated into the software threats at machine speed need to be development lifecycle to support deployed, and secure by design practices; • the Cyber Resilience Act’s Single • human-gated AI workflows need be Reporting Platform must be integrated across incident response leveraged, once it is functional, to and threat modelling, by upskilling and address the challenges posed by reskilling the cybersecurity workforce; new developments.

Impact on Vulnerability & Patch Management

Over the past few years, ENISA has urged Historically, the Window of Exposure (WoE) the cybersecurity community to adapt was a manageable gap; the inherent friction its vulnerability management practices of human-led research and the manual in response to advancing AI capabilities. development of exploits provided defenders We have noted the steadily narrowing with a ‘grace period’. However, data window between vulnerability discovery synthesised by researchers shows that the and exploitation: this period has gone from delta between discovery and weaponisation years, to months, and now (potentially) to is approaching zero . hours or even minutes. Industry research underscores the urgency. Attackers can ENISA’s current capacity, as well as that weaponise new vulnerabilities within 15 of manufacturers, national CSIRTs, and minutes of disclosure, and the median time national coordinated disclosure processes, from initial access to data exfiltration has may need further reinforcement or been compressed to 72 minutes , meaning reconsideration to manage a large wave of that security operation centres (SOCs) must newly discovered vulnerabilities. further adopt automation, and explore new strategies to reduce their Mean Time The NCSC-NL noted that the speed to Detect (MTTD), Mean Time to Respond of autonomous agents eliminates the (MTTR), and Mean Time to Contain (MTTC) defender’s advantage of “private discovery”. to levels commensurate with the evolving Once a vulnerability is found by an AI agent, threat landscape. the transition to a weaponised exploit is no longer a human-led engineering project but a machine-speed computationale task. The message to organisations should be clear:

“Do not treat this as a “next “The EU, as an innovative trend”, but as a structural block with a high density shift in the pace of attack and of SMEs and a deeply defence ”. interconnected supply chain, is particularly sensitive to

Also, as CERT-EU noted :

the disruptions brought by Frontier AI”. “What makes the latest

To navigate these changes, the generation of models cybersecurity community must prepare for

particularly dangerous seven structural challenges derived from

current ENISA’s assessments:

is not just the volume of vulnerabilities they find. It is

• The Velocity Asymmetry and

their ability to chain findings

the Authority Gap. In the new

across multiple steps, reason environment, the primary latency is no

about application logic, and longer technical, but procedural. The

“Authority Gap” refers to the inability

produce exploitation paths

of human Change Advisory Boards

that previously required deep

(CABs) to authorise interventions specialist knowledge. This is in just the few minutes available to

what turns a list of individual counter autonomous exploits. Plainly,

it means organisations are too slow to

flaws into a working attack.”

authorise a meaningful antidote. The necessity of autonomous patching, This capability extends beyond vulnerability where the risk of an automated chaining. Frontier AI models can creatively update breaking a system or causing reason about application logic, credentials, significant downtime is statistically configurations, and API access patterns, weighed against the near-certainty of going beyond static code analysis to an AI-driven breach will be challenging. understand how applications work, and Particularly in the short-term, larger can orchestrate entire autonomous attack organisations will likely be able to campaigns from reconnaissance through establish resilient patching practices lateral movement to exfiltration, not merely quicker, while smaller ones will face discover individual vulnerabilities. challenges due to a lack of resources, security focus, and the necessary As mentioned by NCSC IE: skills.

• Economic Devaluation of Discovery:

“Now is the time to review

Vulnerability discovery is becoming asset inventories, prioritise increasingly industrialised, which

patching discipline, lowers the marginal cost of finding

flaws and raises the volume of

and assess exposure to

disclosures faster than many

unsupported components”.

organisations can remediate them. As an example, an industry Europe’s particular context also needs to be representative shared with ENISA acknowledged as noted by Belgium’s CCB: that their organisation used to receive a few hundred reports of possible vulnerabilities a year, of

which only one hundred would teams now face a challenge of scale, traditionally receive a CVE ID. that is how to audit and validate AI- However, the organisation went generated patches so that they do from about ~80 CVEs in Q1 2025 to not introduce new vulnerabilities close to 500 in Q1 2026, and then into the codebase. An additional the number jumped to about 500 burden for technical teams should be per day when they used Frontier AI- expected, as low-risk vulnerabilities enabled tools. ENISA’s analysis of can no longer be deemed harmless, vulnerability disclosure notes that as they can be chained to create disclosure economics depend on working exploits. incentives, coordination, and the • N-Day Weaponisation. Public costs borne by both researchers and vulnerability disclosure and patch defenders, making rapid triage and releases can still provide attackers remediation a more critical bottleneck with useful information, because than discovery alone. Vulnerability patch diffs and binary changes prioritisation mechanisms like the have historically enabled reverse Exploit Prediction Scoring System engineering and exploit development. (EPSS) developed by FIRST, and the ENISA’s vulnerability management Vulnerability Exploitability eXchange guidance recognises that the (VEX) can directly assist organisations exploitation window can begin before in focusing scare resources. patch deployment and that exposure • Technical Debt as an Existential often persists while organisations test, Risk. Considering legacy systems coordinate, and schedule updates. today, AI-assisted analysis and Such strategies must, however, be reverse engineering can accelerate pursued within the constraints set by code understanding and vulnerability some of the mission critical systems discovery, but this does not make deployed by Operators of Essential these systems automatically Services. In the short term, such ‘undefendable’. Further complexity organisations will need to invest in is added by the already existing proactive security measures in the backlog of vulnerabilities and technical absence of a patch and/or methods debt. System hardening, network for faster patch consumption. segmentation, security monitoring, • The Secure SDLC revolution. There and staged modernisation can is an opportunity to shift the focus still reduce risk. In addition, these from traditional vulnerability and transformational needs may push patch management towards the small and medium organisations stronger enforcement of Secure towards broader cloud adoption Software Development Life Cycle as entities look at whether the (SSDLC) practices, including more risk, operational constraints, and comprehensive assessments of maintenance burden justify continued potential vulnerabilities throughout operation versus retirement or the development process. This needs replacement. to happen across all phases of product • The Verification Bottleneck and development in order to minimise the the ‘Truth’ Crisis. While Advanced introduction of vulnerabilities from the AI models may significantly reduce outset. At the same time, integrators false positives, the sheer volume of and end users should be enabled ‘true’ reports creates a verification to detect vulnerabilities as early as bottleneck. As pointed out in its possible, particularly those arising studies, ENISA notes that the quality from combinations of configurations of vulnerability information is often and system integrations. Regarding insufficient for rapid action. Technical vulnerability detection and

remediation, the objective should be from a discovery channel into a triage to move from a model based primarily bottleneck, where the limiting factor on oversight towards one based on becomes reviewer capacity rather the integration of security directly than the supply of findings. However, into development and operational according to recent ENISA discussions processes at company level. This also with industry, the last few months requires a clear focus on increasing have seen an important increase in the accessibility and adoption of AI report quality, therefore there is a relevant security technologies and large amount of ‘signal’ currently being practices, and the reskilling and reported. upskilling of the existing workforce. • The Risk of ‘Inside-Out’ Attacks: • AI-Generated Vulnerability Distinct from the vulnerability- Reports. By early 2026, AI-generated exploitation paradigm above, vulnerability reports had begun adversaries are increasingly to overwhelm parts of the open- compromising the AI and software source disclosure pipeline.A global supply chain to land inside vulnerability disclosure coordination infrastructure directly, for example and bug bounty platform paused new by arriving through a trusted Internet Bug Bounty submissions software update or a compromised after a surge of mixed-quality AI- open-source dependency. In these assisted reports, while curl shut scenarios, the attacker never needs down its CVD programme in January to breach perimeter defences as they 2026 because maintainers could not are inside the environment and only sustainably absorb the reporting need to move laterally to access and volume and noise. The underlying exfiltrate data. This threat model problem was not just volume, but demands detection and response signal dilution meaning that human strategies that go beyond perimeterreviewers were spending increasing oriented defences and assume that amounts of time separating real adversaries may already be present issues from repetitive, superficial, or within trusted environments. poorly validated submissions. That shift turns vulnerability reporting

Security fundamentals matter more than ever

Security fundamentals will not change, but against live telemetry potentially within new AI models are compressing the entire hours or minutes. Research indicates that attack lifecycle, from reconnaissance to in 75% of breaches, logging existed that lateral movement, in ways that stress-test should have flagged anomalous behaviour these fundamentals, forcing defenders, but signals were fragmented across manufacturers and service providers to different tools and not acted upon. That gap accelerate their cybersecurity initiatives. was manageable when attacks moved at human speed but at AI speed, it will become

1. Vulnerability management untenable.

To defend against lightning-fast automated Service providers, including newly expanded cyberattacks, critical service providers may providers under the scope of NIS2, must be forced to use autonomous patching, harden operations against AI-scale threats as organisational approval is simply too such as adaptive phishing, model poisoning, slow. However, this creates a new risk: and supply-chain pivots. Risk assessments automated updates could accidentally break should blend logging and monitoring systems and cause unwanted downtime. requirements with runtime AI guards, Furthermore, verifying these AI-generated access controls, and threat intelligence patches may become a major bottleneck. sharing, to enable real-time detection System managers may face challenges and response. to build tools that can quickly check and approve these fixes without accidentally ENISA’s Technical Implementation Guidance introducing new bugs into the code. on NIS2 Risk Management reinforces this by operationalising documented risk

2. Incident response frameworks, incident handling policies, supply-chain security, threat hunting For defenders, incident response becomes capabilities, processes now under pressure a race against AI-orchestrated campaigns, by the speed and autonomy of AI. with SOCs needing to validate intrusions

A parallel constraint is the ability of form critical part of the technology stack national authorities to absorb and act on in use. There is also the risk that Union’s incident data at scale. Mandatory incident small manufacturers will not get access reporting, combined with a broader to software/product testing capabilities scope of regulated entities, will sharply enabled by new AI models due to costs. increase reporting volumes, just as AI accelerates vulnerabilities, exploitation, and Manufacturers must adjust their product breaches. This creates a structural risk of lifecycles for compliance with the Cyber simultaneous surges in incidents exceeding Resilience Act (CRA). Developers of AI national capacity. Proactive scanning of models should train their models to be critical infrastructure by National CSIRTs structurally constrained (stronger than a becomes even more relevant. guardrail), and ensure that such models are suggesting code that is secure by In such scenarios, key questions include design/default. ENISA’s proposal for how to prioritise incidents when they machine-processable security attestations all meet regulatory thresholds, which and implementation of SBOM strategies CSIRTs structures can operate without can operationalise the CRA security prioritisation, and how sectoral CSIRTs can requirements; embed threat modelling, be supported when national capacity is least privilege, and lifecycle attestations saturated. Governments should act and from the outset. integrate industry into its crisis planning, establishing surge capacity models, 4. Talent and human capital defining clear prioritisation and escalation frameworks, and stress-testing multi- A cross-cutting challenge will be to ensure incident scenarios. that foreseen solutions will keep the human in the middle. While AI can help build

3. Product Security system fasters, or defend networks better, humans will still need to understand the As the frontier AI capabilities will enable environments they assume responsibility software developers, owners and for. Cybersecurity risks related to AI will manufacturers to secure their code in require raising the level of awareness, the long run, the immediate problem is understanding and skills, across all levels of the security of legacy products and in organisations, substantially faster. particular open-source components which

The way ahead: building AI-resilient defences

Frontier AI models demand a fundamental national authorities and defenders, the shift if defenders are to achieve operational development of new frameworks and the parity with, or stay ahead of attackers reinforcement of existing platforms can through structured frameworks and more function as force multipliers. For example, adaptive practices. The recommendations correlated EUVD data can help identify below set a clear direction for what supply-chain hotspots, systemic weaknesses organisations should aim for through and vulnerability trends accelerated by AI- European coordination, national assisted discovery. CRA-related reporting enforcement and defender operations. may help validate vendor hardening claims They are neither exhaustive nor against real-world exploitability and incident mutually exclusive. patterns. When combined, over time, NIS2 incident reporting and other situational The CRA’s Single Reporting Platform awareness reports, can help close the (SRP) and EU Vulnerability Database (EUVD) gap between vulnerability disclosure to can help support the operationalisation coordinated response. of some of these recommendations. For

Recommendations

• European Level: • National Authorities:

– At the European level, the existing – Run AI-powered threat hunting legal frameworks, including NIS2, operations and publish CRA and the EU AI Act should be anonymised datasets from Frontier leveraged, to ensure that systemic AI simulations. risks stemming from the most – Require critical infrastructure advanced AI models are assessed operators to attest zero-trust and mitigated. To this end, it may be baselines, resilient incident useful to establish EU-wide state-ofresponse capabilities during annual the-art benchmarks for the security audits, and clear escalation paths evaluation of advanced AI models, for AI-accelerated incidents. including standardised testing against cyber ranges, exploitability – Direct government agencies and metrics, and simulations of chained critical infrastructure operators to attacks, to set a consistent bar for reduce ineffective security tooling assessing their capabilities. and complement their cybersecurity stack with AI-enabled platforms – Leverage and build on existing capable of ingesting, correlating, initiatives at European and Member and acting on threat data. State level that consider the use of future AI models for cybersecurity. – Develop common frameworks for the deployment of AI-enabled – European institutions, national security tools that prioritise human authorities, CSIRTs, regulators oversight, auditability, and humanand operators of essential gated triage for decision making. services hold cybersecurity data that could be highly valuable – Develop evaluation capacities for training, evaluating and finefor products including AItuning defensive AI systems. functionalities, in order to ensure This includes incident reports, and validate security levels to face vulnerability disclosures, telemetry, cybersecurity threats malware samples, abuse reports and sectoral threat intelligence. – Proactively scan critical Subject to strong safeguards, infrastructure components that anonymisation, access controls fall under the responsibilities of and clear legal bases, such national authorities. datasets could become a European strategic asset. They could support trusted European cyber-AI models and serve as leverage in procurement negotiations.

– In accordance with the AI Act and the Code of Practice for General Purpose AI, adequate risk mitigations for AI models with advanced cyber capabilities need to be identified.

• Defenders:

– Build more dynamic incident – Treat every environment as response pipelines, using AIpotentially already compromised assisted triage for real-time and extend endpoint protection telemetry validation, prioritisation, across all environments. Every and blast-radius containment, organisation should conduct an while keeping human review firmly analysis of its exposure to frontier in the loop to reliably hit 24-hour AI and deploy real-time, MLnotifications. based prevention and detection

on all on-premises and cloud – Transform security operations into hosts, including securing agentic a near real-time function, targeting endpoints and enterprise browsers, single-digit-minute mean-time-towhich represent critical new attack detect (MTTD) and mean-time-tosurfaces as AI agents increasingly respond (MTTR) metrics. operate autonomously on

endpoints and within browsers. – Accelerate zero-trust segmentation,

behavioural baselining, and more – Embed structured threat modelling evasion-resistant detection layers early and continuously, leveraging that assume attackers will adapt advanced AI models with precise and evolve in near real-time. context to uncover combinations

of weaknesses and run continuous

simulations against live

architectures, effectively turning

AI into an always-on support

capability for red teaming and

defensive validation.

ABOUT ENISA enisa.europa.eu

Fotnoter

  1. European Union Agency for Cybersecurity (ENISA)
  2. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  3. ENISA’s view on Cybersecurity in the Frontier AI Era 1
  4. The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
  5. For contacting the authors please use info@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu.
  6. ENISA would like to acknowledge the valuable insights received from the EU CSIRTs Network, EU-CyCLONe, the ENISA Advisory Group, the ENISA Cyber Partnership Programme, industry representatives, the open-source community and academia.
  7. This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to Regulation (EU) 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and must be accessible free of charge. All references to it or its use as a whole or in part must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication.
  8. © European Union Agency for Cybersecurity (ENISA), 2026 Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided appropriate credit is given and any changes are indicated. Copyright for the image on the cover and on pages 5 - 9 - 11: © Shutterstock For any use or reproduction of elements that are not owned by the European Union Agency for Cybersecurity, permission may need to be sought directly from the respective rightholders.
  9. English PDF Web TP-01-26-015-EN-N 978-92-9204-801-3 2314-9434 10.2824/9549088
  10. European Union Agency for Cybersecurity (ENISA)
  11. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  12. DATE VERSION MODIFICATION
  13. 4 May 2026 0 Internal draft 8 May 2026 1.1 Shared with EU-CyCLONe and CSIRTs Network 29 May 2026 1.2 Feedback integrated from CSIRTs Network and EU-CyCLONe 11 June 2026 1.3 Further integration of comments from EU-CyCLONe 17 June 2026 2 Proofread and graphic design Discussion and feedback from ENISA Management Board 18-19 June 2026 3 Minor edits Shared under embargo with the Management Board, ENISA NLO, AG, CSIRTs Network, EU-CyCLONe and CPP.
  14. ENISA’s view on Cybersecurity in the Frontier AI Era 3
  15. European Union Agency for Cybersecurity (ENISA)
  16. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  17. 1 https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier (accessed 18 June 2026) 2 https://suzulabs.com/suzu-labs-blog/mean-time-to-exploit-has-gone-negative.-security-strategy-has-to-change (accessed 18 June 2026)
  18. ENISA’s view on Cybersecurity in the Frontier AI Era 5
  19. European Union Agency for Cybersecurity (ENISA)
  20. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  21. 3 https://securitybrief.com.au/story/ai-fuelled-cyber-attacks-now-steal-data-in-72-minutes (accessed 18 June 2026) 4 https://zerodayclock.com/ (accessed 18 June 2026) 5 https://www.ncsc.nl/nieuws/anthropics-frontiermodel-mythos-vraagt-om-directe-actie (accessed 18 June 2026)
  22. ENISA’s view on Cybersecurity in the Frontier AI Era 7
  23. 6 Original (NL/machine translated): Behandel dit niet als “volgende trend”, maar als structurele verschuiving in het tempo van aanvallen én verdediging. 7 https://cert.europa.eu/blog/ai-vulnerability-discovery-defenders-must-adapt (accessed 18 June 2026) 8 Centre for Cybersecurity Belgium (CCB) – Food for thought: The Cybersecurity Revolution in the Age of Frontier AI
  24. European Union Agency for Cybersecurity (ENISA)
  25. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  26. 9 ENISA - Economics of vulnerability disclosure (accessed 18 June 2026) 10 Patch Diffing | CVE North Stars (accessed 18 June 2026)
  27. ENISA’s view on Cybersecurity in the Frontier AI Era 9
  28. 11 https://www.darkreading.com/application-security/ai-led-remediation-crisis-prompts-hackerone-pause-bug-bounties (accessed 18 June 2026)
  29. European Union Agency for Cybersecurity (ENISA)
  30. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  31. 12 Palo Alto Networks, 2025 Unit 42 Global Incident Response Report (accessed 18 June 2026) 13 ENISA – Technical Implementation Guidance (accessed 18 June 2026)
  32. ENISA’s view on Cybersecurity in the Frontier AI Era 11
  33. European Union Agency for Cybersecurity (ENISA)
  34. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  35. ENISA’s view on Cybersecurity in the Frontier AI Era 13
  36. 14 Article 55 of the EU AI Act requires providers placing general-purpose AI models with systemic risk on the EU market to assess and mitigate those risks, regardless of where they are based. Through the GPAI Code of Practice, providers commit to identifying systemic risks, including large-scale cyberattack risks, applying safety and cybersecurity measures across the model lifecycle, and reporting relevant information and evaluation results to the European AI Office. These rules have applied since 2 August 2025 and will be enforced from 2 August 2026, with the Office empowered to investigate compliance, require mitigation measures, impose fines of up to 3% of global annual turnover and, in extreme cases, restrict, withdraw, or recall models from the EU market.
  37. European Union Agency for Cybersecurity (ENISA)
  38. Agamemnonos 14 | Chalandri 15231 | Attiki | Greece | info@enisa.europa.eu | www.enisa.europa.eu
  39. ENISA’s view on Cybersecurity in the Frontier AI Era 15
  40. The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
  41. European Union Agency for Cybersecurity
  42. Athens Office ISBN 978-92-9204-801-3 Agamemnonos 14 Chalandri 15231, Attiki, Greece
  43. Brussels Office
  44. Rue de la Loi 107 1049 Brussels, Belgium