Cybersecurity in the Frontier AI Era, the view of ENISA
Yesterday, the European Union Agency for Cybersecurity published its recommendations for developing operational capabilities to deal with machine-speed threats. The publication is meant to support the competent national authorities, EU policymakers, and everyone working in a cyberdefense role.
The recommendations are not an all-inclusive checklist, according to the authors. ENISA aims to refine and expand them in close cooperation with member states and EU institutions, bodies, and agencies (EUIBAs), and will align these to the upcoming European Commission Action Plan.
Frontier AI models are challenging traditional security paradigms by compressing the vulnerability management lifecycle and attack chain, from discovery to exploitation. The frontier model landscape is evolving fast; it is expected that open-weight models may reach a similar level of capability within 9 to 12 months and that existing models, when coupled with skilled security experts, can yield comparative results. While ENISA acknowledges the potential benefits of these technologies to improve security, the publication focuses on some of the immediate and mid-term cybersecurity challenges.
Frontier AI models demand a fundamental change if defenders are to achieve operational parity with, or stay ahead of attackers through structured frameworks and more adaptive practices.
Stakeholders' concerns
To identify the appropriate response to the emergence of AI and its impact on cybersecurity, ENISA held a series of engagements where our stakeholders raised the following:
- There is the likelihood that attackers will have access to exploits before fixes are released (so-called negative time-to-exploit).
- AI amplifies challenges related to legacy systems and products that will soon reach or have reached their end-of-life and end-of-support.
- Due to an expected increase in patch release frequency, patching may lead to an increase in service disruptions.
- Open-source requires a strategy to prevent maintainers from being overloaded with vulnerability reports.
- SMEs, part of the backbone of the EU economy, may require additional support, in particular in terms of guidance and access to the latest models.
- Cybersecurity should be positioned as a strategic use case for European investment in AI, as a need exists for the EU-based organisations to have access to and develop their own AI models.
- Security fundamentals matter more than ever in the age of AI.
- Resources need to be shifted from discovery to risk-based prioritisation of vulnerabilities through higher-speed triage, remediation, and risk reduction.
- Defensive AI tooling needs to be integrated into the software development lifecycle to support secure-by-design practices.
- Human-gated AI workflows need to be integrated across incident response and threat modelling, by upskilling and reskilling the cybersecurity workforce.
- Architectural solutions must use an assume-breached mindset, while acknowledging that zero trust approaches will require a deep transformational process.
- Cybersecurity as Code: means machine-speed threats need to be addressed with machine-speed defences (Vulnerability Management as Code, Incident Response as Code, Security by Design as Code, Security Architecture as Code).
- AI-driven defensive capabilities that can detect, correlate, and respond to threats at machine speed need to be deployed.
- Once functional, the Cyber Resilience Act’s Single Reporting Platform must be leveraged, to address the challenges posed by new developments.

