THE European Union Agency for Cybersecurity (ENISA) says frontier AI could compress the cyberattack lifecycle from vulnerability discovery and reconnaissance to exploitation, lateral movement and data theft. In its July 2026 paper, *ENISA’s view on Cybersecurity in the Frontier AI Era*, the agency warns that “negative time-to-exploit” could occur when attackers obtain usable exploit information before defenders receive or deploy a fix.
The article says ENISA estimates vulnerabilities may be weaponised within 15 minutes of disclosure, while research cited in the report puts the median time from initial access to data exfiltration at 72 minutes. These figures describe potential attack speeds, not confirmed exploitation of a specific vulnerability.
ENISA also reports that one organisation’s vulnerability volume rose from roughly 80 CVEs in the first quarter of 2025 to almost 500 in the first quarter of 2026, then reached about 500 reports per day when frontier-AI tools were used. The agency says verification, triage and remediation could therefore become greater constraints than discovery, while AI-generated reports are already putting pressure on open-source disclosure processes.
It recommends prioritising vulnerabilities using approaches such as EPSS and VEX, integrating AI-assisted testing and incident response with human oversight, and considering near-real-time operations with single-digit-minute targets for detection and response. ENISA further calls for “Cybersecurity as Code”, assume-breached designs, stronger segmentation and common European benchmarks for testing advanced AI in cyber ranges. It cautions that automated patching requires verification because changes can disrupt systems or introduce new bugs.