security
Apr 25, 2026
By Teun
EU Regulators Warn of Escalating AI-Driven Cyber Attacks Across Europe
European regulators warned that AI is enabling faster, more complex cyber attacks, with threat actors using AI to automate reconnaissance, craft social engineering attacks, and find vulnerabilities at machine speed. New regulatory proceedings against X under the Digital Services Act were announced alongside.
European regulators are warning that artificial intelligence is changing the pace and shape of cyber attacks across the continent. The concern is not that AI has created a brand-new class of threat, but that it is helping attackers move faster, scale further, and probe targets with far less manual effort.
According to the warning reported by The News, threat actors are using AI to automate reconnaissance, generate more convincing social engineering messages, and identify weaknesses at machine speed. In practice, that means an attacker can scan large numbers of systems, sift through public information, and adapt phishing lures or other messages much more quickly than a human operator working alone.
Reconnaissance is the early stage of an attack, when a hacker gathers information about a target. Social engineering is the use of deception to get people to reveal credentials, approve access, or take some other unsafe action. When AI is inserted into those steps, the barrier to running large-scale campaigns drops, especially for criminals who already have access to stolen data, leaked credentials, or public records.
The warning comes as European institutions are already under pressure to respond to AI use in both cybercrime and online harms. Regulators have been focused on how large platforms handle illegal content, manipulation, and security risks, and the latest message suggests they now see AI as an amplifier across all of those categories. Faster attack cycles also give defenders less time to notice suspicious activity before damage is done.
A key concern is that AI can help attackers find vulnerabilities more efficiently. That includes parsing code, spotting exposed services, and testing whether a system behaves in a way that could be exploited. Even when the AI does not discover a novel flaw, it can shorten the time between a weakness being exposed and an attacker taking advantage of it.
The report also notes that new regulatory proceedings against X were announced under the Digital Services Act. The DSA is the European Union law that sets rules for large online platforms, including obligations around illegal content, transparency, and risk management. Proceedings under the law can lead to scrutiny of how a platform handles systemic risks, including the spread of harmful content or features that could be abused.
While the AI warning and the X proceedings are separate issues, they point to the same regulatory direction. European authorities are increasingly treating platform governance, information security, and AI abuse as linked problems rather than isolated ones.
That matters because cyber attacks are not only a technical issue, they are also an infrastructure issue. When attackers can automate parts of the kill chain, from information gathering to message generation to vulnerability discovery, the scale of the problem changes. Defenders may still be able to stop individual attempts, but the volume and speed of attempts can make the overall environment harder to manage.
The underlying message from regulators is that AI is now part of the attack tooling being used by criminals and hostile actors, and that Europe’s security and digital policy response will have to account for that shift.