ENISA (EU Agency for Cybersecurity)
ENISA Threat Landscape 2025
Corrected · October 2025
What was fabricated
AI-hallucinated source references across TWO ENISA threat reports, published October and November 2025, found by researchers at Westfälische Hochschule and reported via Der Spiegel; many dead source links. ⚠️ IN ONE OF THE TWO REPORTS — WHICH IS NOT IDENTIFIED IN THE PUBLIC REPORTING — 26 of 492 footnotes were incorrect. Which of the two carries that figure is NOT ESTABLISHED, so the count is not asserted of this document. ENISA said AI had been permitted only 'minor editorial revisions'.
What happened as a result
Researchers at Westfälische Hochschule flagged the bad references (reported via Der Spiegel). ENISA admitted 'human errors' and said AI had been permitted only 'minor editorial revisions'. A v1.2 file exists on ENISA's site, but no source establishes it was issued as an announced correction, and neither published version carries a change log or erratum.
Sources
- https://www.heise.de/en/news/EU-cyber-agency-secretly-uses-AI-for-reports-and-gets-caught-11136978.html
- https://cybernews.com/ai-news/enisa-cybersecurity-ai/
Every incident is confirmed against at least one reputable source (mainstream news, legal/official, or the organisation itself). Nothing unverifiable is listed. Accuracy is non-negotiable — Ukweli is a truth product.