REGULATORY WATCH BRIEF Moderate 52 🧭 Regulatory Guidance published

ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks

The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.

ImpactModerate 52
Type🧭 Regulatory Guidance
Statuspublished enacted, check the effective date
JurisdictionEU
Effective22 September 2026

What happened

ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted sector and highlights that 73% of incidents affect essential entities under the NIS2 definition.

Why it matters for trust and compliance

  • Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
  • The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.
  • Takes effect September 22, 2026.
  • It relates to NIS2. The regulations library explains what that law requires.

Who is affected

government financial services manufacturing technology ENISA European Banking Authority

Recommended actions

  1. Map the security requirements to existing controls and close gaps.
  2. Identify affected vendors and update due-diligence and contract terms.
  3. Inventory AI or automated decision systems in scope and their assessments.