Five Eyes Issue Rare Joint Cyber Warning
The cybersecurity agencies of the United States, United Kingdom, Canada, Australia, and New Zealand issued a rare joint advisory on Monday, June 22, warning business and government leaders that artificial intelligence is on the verge of enabling cyberattacks far beyond anything currently seen and that the window to prepare is closing.
"Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months," the joint statement said.
The statement was signed by the heads of the US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency, the UK's Government Communications Headquarters (GCHQ), the Canadian Centre for Cyber Security, the Australian Signals Directorate, and New Zealand's Government Communications Security Bureau.
What the Alliance Is Warning About
The advisory focuses on the emergence of what the intelligence agencies describe as "agentic AI" autonomous AI systems capable of conducting multi-step operations without human oversight. These systems can carry out rapid automated network discovery, chain together vulnerability exploits, adapt to defensive countermeasures in real time, and scale attack campaigns far beyond the capacity of any human team.
The Canadian Centre for Cyber Security said the statement was issued now "because we are seeing real, recent shifts in how AI tools are being used, including to speed up the discovery and exploitation of vulnerabilities. As these capabilities become more accessible, the risk is no longer theoretical."
The advisory explicitly acknowledged that breaches will occur, framing resilience not just prevention as the core imperative for organisations.
Who Is at Risk
While the advisory was addressed broadly to governments and businesses, independent cybersecurity experts noted that smaller and medium-sized organisations are likely to be the most exposed. "Sophisticated businesses, usually your large corporations, they already invest in cybersecurity, and they'll be better prepared," said one AI and national security expert cited by CNN. "The ones who are more exposed will be those small and medium-sized businesses who maybe have under-invested so far."
Critical infrastructure sectors energy, water, telecommunications, financial systems are identified as particularly high-value targets for nation-state actors using AI-enabled tools.
What Organisations Are Being Told to Do
The Five Eyes advisory urged leaders across four areas: understanding and assessing AI-driven cyber risk; prioritising foundational security practices such as patching, access controls, and software quality management; empowering cybersecurity leaders with authority and resources; and maintaining active, ongoing engagement as the threat landscape evolves.
"Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents," the alliance said, noting that AI is simultaneously part of the problem and part of the solution.
What to Watch
The June 22 advisory builds on guidance the Five Eyes issued in May 2026 cataloguing more than 23 risk categories tied to autonomous AI systems. Cybersecurity insurers are expected to begin repricing premiums in response to the elevated risk assessment. Regulators in several jurisdictions are reviewing whether existing critical infrastructure protection frameworks adequately address AI-accelerated attack vectors. The next major test will be whether any high-profile breach in the coming months can be attributed to AI-enabled offensive tools a development that would likely trigger a significant escalation in international policy response.
Comments (0)
Please log in to post a comment.
No comments yet. Be the first!