The Advisory
<cite index="17-1,17-4">On June 22, 2026, the leaders of the cybersecurity agencies in Australia, Canada, New Zealand, the United Kingdom, and the United States issued a joint statement calling for an "urgent" focus on cyber resilience in anticipation of frontier AI models exceeding current industry expectations and fundamentally transforming both offensive and defensive cyber capabilities within a timeline of "months."</cite>
<cite index="15-10">The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) signed the statement on behalf of the United States, along with the Australian Signals Directorate, Canada's Communications Security Establishment, New Zealand's Government Communications Security Bureau, and the United Kingdom's Government Communications Headquarters.</cite>
<cite index="12-6">The advisory's framing is unusually direct for a Five Eyes statement, noting that agentic AI systems can chain exploits, adapt to defenses in real time, and scale operations beyond what any human team could manage.</cite>
Context: The Anthropic Catalyst
The warning arrived days after a significant catalyzing event. <cite index="29-3,29-4,29-5">A U.S. official told the Associated Press that Anthropic had teamed up with U.S. intelligence agencies to conduct tests using the company's Mythos model, which identified certain vulnerabilities in highly sensitive and secure U.S. government computer systems within hours — though that did not mean the model was able to exploit them within that time.</cite>
<cite index="27-8">Separately, Anthropic stated that its Mythos Preview had already uncovered thousands of vulnerabilities, including a 27-year-old flaw in OpenBSD, one of the most security-hardened operating systems ever developed.</cite>
<cite index="29-10">The Trump administration subsequently issued a directive requiring Anthropic to prevent foreign nationals from using its latest models, known as Fable 5 and Mythos 5.</cite> <cite index="25-11">This marked the first time the United States applied export controls directly to an AI model rather than to the hardware or chips powering it, a landmark regulatory precedent in AI national security governance.</cite>
Five Recommended Controls
Drawing directly from the published CISA and Australian Cyber Security Centre (ACSC) advisory text, the agencies outlined five practical steps for organizations:
<cite index="11-2">The statement recommended reducing the attack surface by limiting unnecessary system access and external connectivity; accelerating patching to mitigate the impact of AI-powered vulnerability discovery and exploitation; addressing legacy systems that are easy targets; and reviewing and strengthening identity and access controls to limit who can access sensitive systems by enforcing strong authentication and regularly reviewing permissions.</cite>
<cite index="13-3,13-4">Organizations were also directed to prepare for incidents before they happen: testing response plans, training teams, and assuming breaches will occur, with a focus on fast containment and recovery.</cite>
AI as Both Threat and Defense
The agencies did not frame AI solely as a threat vector. <cite index="8-7,8-8">Though AI is being used by adversaries to "move faster and more effectively," it is also part of the solution: organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.</cite>
Wider Enterprise Implications
<cite index="6-5">"The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years," the joint statement said.</cite> <cite index="5-15">Cybersecurity, the nations stated, "is a core business risk and leadership responsibility," with governments urging corporate executives and board members to carefully oversee how their IT and security teams manage and protect computer systems.</cite>
<cite index="15-3,15-4">"Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy," the advisory stated. "Those that do not will face growing operational and strategic disadvantage."</cite>
<cite index="23-4,23-5">What is notable is the specificity of the timeline. For most of 2025 and the first half of 2026, intelligence community language on AI risk remained in the "years" bucket — speculative, hedged, and calibrated for political audiences.</cite> The June 22 statement marks a measurable shift in official posture, with implications for enterprise security budgeting, cyber insurance underwriting, and regulatory scrutiny across sectors reliant on digital infrastructure.