Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules
Machine-learning-driven flood attacks are reshaping volumetric thresholds faster than current incident-reporting frameworks anticipated.

Distributed denial-of-service traffic generated by machine-learning tooling is now adapting to mitigation rules mid-attack, according to network operators briefing regulators this autumn, and the shift is forcing a reassessment of how volumetric incidents are classified under existing critical-infrastructure reporting regimes.
The technical change is narrow but consequential. Rather than firing a fixed pattern of UDP or HTTP/2 requests, AI-assisted botnets are observing scrubbing-centre responses in near real time and rotating source IPs, request headers, and TLS fingerprints to defeat signature-based filters. Cloudflare reported mitigating a 7.3 Tbps attack in May 2025, and operators at Akamai and Google have published comparable figures earlier in the year.
The regulatory question is whether such events qualify as "substantial cyber incidents" under the Cybersecurity and Infrastructure Security Agency (CISA) reporting rule. Under §226.1 of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) proposed rule, covered entities must report within 72 hours any incident that leads to "a serious impact on the safety and resiliency of operational systems and processes." A sustained adaptive DDoS that degrades, but does not fully disable, a regulated service sits awkwardly inside that definition.
"The rule was drafted with a clearer line between availability incidents and confidentiality incidents," said Lauren Boas Hayes, senior advisor for technology and innovation at CISA, during an industry roundtable in September. "We are looking carefully at the comments on §226.1(a)(4) that address prolonged availability degradation."
The comment record matters here. CISA received more than 1,400 submissions on the proposed rule, with the Information Technology Sector Coordinating Council and several telecommunications carriers asking the agency to clarify whether AI-augmented DDoS campaigns trigger the 72-hour clock at the first observable impact or only once mitigation fails.
European regulators are moving on a parallel track. Under Article 23 of the Network and Information Security Directive 2 (NIS2), essential entities in the twenty-seven member states must submit an early warning within 24 hours of becoming aware of a significant incident. The European Union Agency for Cybersecurity (ENISA) published technical guidance in October indicating that adaptive volumetric attacks meeting the directive's threshold of "severe operational disruption" should be reported even where service is preserved through overprovisioning.
And the gap between the two frameworks is widening. A multinational financial institution facing the same attack could owe ENISA a notification within a day and CISA a report within three, with different evidentiary standards for each.
Vendors are responding on their own timeline. Cloudflare, Akamai, and Imperva have all published behavioural-detection updates this quarter.
The CIRCIA final rule is expected in 2025. The public comment window on ENISA's draft technical guidance for NIS2 incident classification closes on 14 December, with the finalised text scheduled for publication in the first quarter of next year.



