7/28/2026, 1:04:55 PM · defense-government

Five Eyes Alliance Warns Frontier AI Will Transform Cyber Offense in Months, Not Years

The cybersecurity agencies of the U.S., U.K., Canada, Australia, and New Zealand issued a rare joint advisory on June 22, 2026, warning that advanced AI models will fundamentally reshape offensive cyber capabilities on a timeline of months, and urging organizations to harden identity controls and treat cybersecurity as a core business imperative.

The Advisory

<cite index="17-1,17-4">On June 22, 2026, the leaders of the cybersecurity agencies in Australia, Canada, New Zealand, the United Kingdom, and the United States issued a joint statement calling for an "urgent" focus on cyber resilience in anticipation of frontier AI models exceeding current industry expectations and fundamentally transforming both offensive and defensive cyber capabilities within a timeline of "months."</cite>

<cite index="15-10">The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) signed the statement on behalf of the United States, along with the Australian Signals Directorate, Canada's Communications Security Establishment, New Zealand's Government Communications Security Bureau, and the United Kingdom's Government Communications Headquarters.</cite>

<cite index="12-6">The advisory's framing is unusually direct for a Five Eyes statement, noting that agentic AI systems can chain exploits, adapt to defenses in real time, and scale operations beyond what any human team could manage.</cite>

Context: The Anthropic Catalyst

The warning arrived days after a significant catalyzing event. <cite index="29-3,29-4,29-5">A U.S. official told the Associated Press that Anthropic had teamed up with U.S. intelligence agencies to conduct tests using the company's Mythos model, which identified certain vulnerabilities in highly sensitive and secure U.S. government computer systems within hours — though that did not mean the model was able to exploit them within that time.</cite>

<cite index="27-8">Separately, Anthropic stated that its Mythos Preview had already uncovered thousands of vulnerabilities, including a 27-year-old flaw in OpenBSD, one of the most security-hardened operating systems ever developed.</cite>

<cite index="29-10">The Trump administration subsequently issued a directive requiring Anthropic to prevent foreign nationals from using its latest models, known as Fable 5 and Mythos 5.</cite> <cite index="25-11">This marked the first time the United States applied export controls directly to an AI model rather than to the hardware or chips powering it, a landmark regulatory precedent in AI national security governance.</cite>

Five Recommended Controls

Drawing directly from the published CISA and Australian Cyber Security Centre (ACSC) advisory text, the agencies outlined five practical steps for organizations:

<cite index="11-2">The statement recommended reducing the attack surface by limiting unnecessary system access and external connectivity; accelerating patching to mitigate the impact of AI-powered vulnerability discovery and exploitation; addressing legacy systems that are easy targets; and reviewing and strengthening identity and access controls to limit who can access sensitive systems by enforcing strong authentication and regularly reviewing permissions.</cite>

<cite index="13-3,13-4">Organizations were also directed to prepare for incidents before they happen: testing response plans, training teams, and assuming breaches will occur, with a focus on fast containment and recovery.</cite>

AI as Both Threat and Defense

The agencies did not frame AI solely as a threat vector. <cite index="8-7,8-8">Though AI is being used by adversaries to "move faster and more effectively," it is also part of the solution: organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.</cite>

Wider Enterprise Implications

<cite index="6-5">"The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years," the joint statement said.</cite> <cite index="5-15">Cybersecurity, the nations stated, "is a core business risk and leadership responsibility," with governments urging corporate executives and board members to carefully oversee how their IT and security teams manage and protect computer systems.</cite>

<cite index="15-3,15-4">"Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy," the advisory stated. "Those that do not will face growing operational and strategic disadvantage."</cite>

<cite index="23-4,23-5">What is notable is the specificity of the timeline. For most of 2025 and the first half of 2026, intelligence community language on AI risk remained in the "years" bucket — speculative, hedged, and calibrated for political audiences.</cite> The June 22 statement marks a measurable shift in official posture, with implications for enterprise security budgeting, cyber insurance underwriting, and regulatory scrutiny across sectors reliant on digital infrastructure.

Cross-references

Sources

  1. [1]
    Five Eyes cybersecurity agencies warn of new AI models impact on cyber risks | CBC News
  2. [2]
    Five Eyes Intelligence Alliance Warns AI-Driven Cyberattacks - ProgramBusiness | Where insurance industry clicks
  3. [3]
    “Five Eyes” Intelligence Alliance Warns AI Models Pose Huge Cybersecurity Risks | Democracy Now!
  4. [4]
    Intelligence Alliance Warns AI Could Outpace Cyber Defenses Within Months - The National CIO Review
  5. [5]
    Looming AI-fueled threats require urgent cybersecurity improvements, Five Eyes members say | Cybersecurity Dive
  6. [6]
    AI on pace to bypass cybersecurity systems in months, not years, "Five Eyes" spy partners warn - CBS News
  7. [7]
    Five Eyes Security Agencies Issue Urgent Warning On AI | 10 News - YouTube
  8. [8]
    AI could breach government and business defenses in months, US and its intelligence partners warn | CNN
  9. [9]
    [LINK] Cybersecurity Summit
  10. [10]
    Five Eyes warns AI-powered cyber threats may succeed within months
  11. [11]
    Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats - Infosecurity Magazine
  12. [12]
    Five Eyes agencies warn AI-powered cyberattacks are 'months, not years' away — AESOP AI News
  13. [13]
    Five Eyes cyber security agencies statement | Cyber.gov.au
  14. [14]
    Five Eyes Cyber Security Agencies Statement | CISA
  15. [15]
    Five Eyes warn frontier AI accelerating cyber threats, urges ...
  16. [16]
    Five Eyes Cybersecurity Agencies Issue Statement Regarding AI-Related Shifts in Cybersecurity Risks, Urging Organizational Leaders to “Act Now” | Inside Privacy
  17. [17]
    Five Eyes Intelligence Alliance Warns AI-Fueled Cyberattacks Are Just Months Away
  18. [18]
    AI Watermarking 2026: C2PA, Metadata and Fingerprinting
  19. [19]
    What Is AI Watermarking and Why It Matters in 2026? | Resemble AI
  20. [20]
    AI Content Provenance in 2026: C2PA, Watermarking, and EU AI ...
  21. [21]
    Why Five Eyes Spy Agencies Warn AI Cyber Threats Will Hit You This Year
  22. [22]
    release khanna gallagher introduce five ais act advance development ai within
  23. [23]
    Anthropic's Mythos AI Model Reportedly Breached NSA Classified Systems in Hours
  24. [24]
    Anthropic Shuts Down Mythos and Fable AI Models After AI Nearly Breached All NSA Classified Systems in Hours- The Defense News
  25. [25]
    Anthropic's Mythos AI broke into almost all NSA classified systems in hours
  26. [26]
    Anthropic's Mythos AI found flaws in classified US systems within hours, officials say | Euronews
  27. [27]
    Anthropic’s Mythos model found vulnerabilities in classified U.S. government systems, official says: AP
  28. [28]
    Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says - SecurityWeek
  29. [29]
    Anthropic’s Mythos model found vulnerabilities in classified US government systems, official says | Federal News Network
  30. [30]
    Anthropic’s Mythos AI Model Reportedly Breached NSA Classified Systems in
  31. [31]
    www.mexc.com
  32. [32]
    anthropic latest ai model could 182633282
Five Eyes Alliance Warns Frontier AI Will Transform Cyber Offense in Months, Not Years · AIDB