Five Eyes spy agencies warn AI will outpace cybersecurity defences within months
The intelligence alliance linking the US, UK, Australia, Canada and New Zealand says AI-powered attacks are arriving faster than most organisations can adapt, and breaches are now a question of when, not if.

Key points
- The Five Eyes intelligence alliance issued a joint advisory on Monday warning that AI is accelerating cyber attacks faster than existing defences can keep up.
- The advisory states that "cyber risk assumptions can become outdated in months, not years" as frontier AI, the most capable AI systems currently available, develops rapidly.
- AI startup Anthropic said in April that its Mythos model family showed a remarkable ability to find vulnerabilities, meaning weaknesses, in software automatically.
- Anthropic suspended access to its Mythos 5 and Fable 5 models this month after a US government directive banned foreign nationals from using them.
- Former CISA director Chris Krebs warned of a coming "vulnerability tsunami" driven by AI reaching criminal groups and hostile governments.
For years, cybersecurity ran on a simple assumption: attackers and defenders move at roughly the same pace. That assumption's breaking down.
The Five Eyes alliance, the intelligence partnership spanning the US, UK, Australia, Canada and New Zealand, published a joint advisory this week saying the most capable AI systems are evolving fast enough to make today's security playbooks obsolete. Not in years. In months.
Finding a flaw in software has historically required real expertise and time. AI changes that equation by scanning systems at machine speed and spotting weaknesses a human analyst might miss entirely.
Should ordinary people be worried?
Yes, in a practical sense, though not in a way that requires panic. The advisory targets governments and businesses, because those are the targets. But when companies get hit, customers feel it: stolen account details, disrupted services, leaked personal data.
Chris Krebs, who ran the US Cybersecurity and Infrastructure Security Agency (CISA), the federal body responsible for protecting critical infrastructure like power grids and hospitals, told CBS News the past few months have been "a bit of a whirlwind." He called the advisory a signal that businesses need to take AI falling into the wrong hands very seriously, and described what's coming as a "vulnerability tsunami."
The advisory doesn't pretend breaches can be stopped entirely. "Breaches will occur," it says flatly. The goal is containing damage before it becomes a financial and operational crisis.
Four broad steps are recommended: integrate AI tools into your own security teams, retire legacy systems that can't be patched securely, tightly restrict access to critical systems, and plan for the moment something goes wrong.
What does Anthropic have to do with it?
Anthropicis near the centre of this. Its Mythos model family, released in April 2026, showed an unusual ability to find software vulnerabilities automatically. Just days after publicly launching a restricted version called Fable 5, Anthropic received a government directive banning foreign nationals from accessing both Mythos 5 and Fable 5. We covered the model suspension and its export-control basis on 13 June 2026. The timing matters: this is the same White House that has otherwise pushed to loosen AI oversight, including moves to stop individual US states from writing their own rules.
The real failure mode
Organisational complacency is the thing that'll actually get you. Most companies review their threat models annually. The Five Eyes advisory is saying that cycle's already too slow, a point our 23 June story on the same advisory flagged as the buried lead: the advice isn't late because the agencies said it, it's late because most CSOs haven't acted on it.
If you're a customer of any large organisation, watch for phishing emails, fake messages designed to trick you into surrendering passwords, in the weeks after major AI announcements. Attackers move fast when new tools arrive.
Operational takeaway: Treat your threat model like a live document, not a quarterly filing.



