Skip to main content

The European Union Agency for Cybersecurity (ENISA) has published a position paper on what frontier AI models mean for the way organisations find, triage and fix vulnerabilities, and for the skills their security teams will need. Released on 7 July 2026, the 16-page paper sets out an initial set of recommendations for national authorities, EU policymakers, defenders and service providers.

What the paper argues

ENISA's central point is that AI is compressing the attack lifecycle. The gap between a vulnerability being discovered and being exploited has shrunk from years to months and, in some cases, to minutes. The agency reports that one organisation went from roughly 80 CVEs in the first quarter of 2025 to close to 500 in the same quarter of 2026, and to around 500 per day once frontier AI tools were applied.

The consequences are organisational as much as technical. ENISA describes an "authority gap": human change advisory boards cannot approve a fix in the few minutes now available to counter an autonomous exploit. Elsewhere it notes that in three quarters of breaches the logs that should have flagged anomalous behaviour already existed, but the signals sat unread across separate tools.

The paper also documents pressure on the open-source disclosure pipeline. A major bug bounty platform paused new submissions after a surge of AI-assisted reports of uneven quality, and the curl project closed its coordinated disclosure programme in January 2026 because maintainers could not absorb the volume.

Why it matters for digital skills

ENISA is explicit that security fundamentals have not changed, they are simply being stress-tested at a new speed. The response it proposes rests heavily on people:

  • incident response and threat modelling should use human-gated AI workflows, which requires upskilling and reskilling the existing cybersecurity workforce rather than replacing it;
  • moving from oversight-based security to security embedded in development depends on developers and integrators acquiring secure-by-design practices;
  • the paper's section on talent and human capital argues that awareness, understanding and skills need to rise across all levels of an organisation, and considerably faster than at present, not only in specialist security roles.

For anyone designing cybersecurity training, curricula or workforce strategies, the paper is useful as a statement of where the skills gap is moving.

Who it is for

National competent authorities, CSIRTs, policymakers, security operations teams, product manufacturers subject to the Cyber Resilience Act, and training providers working on advanced cybersecurity skills.

Access

The paper is available in English and can be downloaded free of charge from the ENISA publications page. It is published under a Creative Commons Attribution 4.0 licence.

Digital skills resource details

Target audience
Digital skills for ICT professionals and other digital experts.
Digital technology / specialisation
Digital skill level
Geographic scope - Country
Austria
Belgium
Bulgaria
Cyprus
Industry - field of education and training
Information and Communication Technologies (ICTs) not further defined
Target language
English
Geographical sphere
EU institutional initiative
Methodology

The paper draws on a series of ENISA stakeholder engagements and consultations rather than on primary data collection. Input was received from the EU CSIRTs Network, EU-CyCLONe, the ENISA Advisory Group, the ENISA Cyber Partnership Programme, industry representatives, the open-source community and academia. Successive drafts were circulated to the CSIRTs Network and EU-CyCLONe between May and June 2026 and discussed with the ENISA Management Board before publication.

Skills resource type
Report