Five Eyes spy chiefs warn AI is shrinking the window to stop cyberattacks — and boards need to act now

The heads of five Western cybersecurity agencies say artificial intelligence is already changing how fast criminals can strike, and the warning is aimed squarely at company boards, not IT teams.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: Aerial editorial photograph
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • On a Monday in June 2026, cybersecurity agency heads from Australia, the United States, Britain, Canada, and New Zealand issued a rare joint statement on AI-driven cyber risk.
  • Britain's AI Security Institute found one Anthropic AI model could break into computer systems approximately 73% of the time in testing.
  • On 13 June 2026, Anthropic suspended worldwide access to its two most powerful AI models, Fable 5 and Mythos 5, following a US export control directive.
  • The five agencies said the time between a software flaw being discovered and criminals exploiting it is shrinking, making slow patching more dangerous than ever.
  • Stephanie Crowe, head of the Australian Cyber Security Centre, signed the statement and said organisations that take the threat seriously are "in a really good place".

The heads of the Five Eyes cybersecurity agencies, Australia, the United States, Britain, Canada, and New Zealand, published a joint statement this week warning that artificial intelligence is reshaping cyber risk faster than most organisations have planned for. This is the third Five Eyes AI advisory we have covered since June, and the language is getting harder to dismiss each time.

"The urgency is clear. AI is not a future consideration, it is already here," the statement says. "It lowers barriers for malicious actors and increases the speed and complexity of attacks."

Cyber risk, the chiefs say, is no longer a technology problem. It's a leadership problem. Boards need to be confident their defences would survive a real attack, not just that boxes have been ticked on a compliance form.

How close is this threat, really?

Close enough that one AI model is already breaking into systems nearly three-quarters of the time in controlled tests. Britain's AI Security Institute tested an Anthropic model and found it succeeded in around 73% of intrusion attempts, which Queen Mary University of London academic Gina Neff described, in comments to SMH Technology, as "a step change in capability."

On 13 June 2026, a US export control directive prompted Anthropic to suspend worldwide access to Fable 5 and Mythos 5. Australian users lost access without warning. That episode showed how quickly access to powerful AI tools can vanish, with no grace period for organisations that had built processes around them.

The agencies' core concern is timing. Patching, applying official fixes to known software flaws, has always lagged behind discovery. AI shortens that gap further. Criminals can now scan for and exploit unpatched flaws faster than many organisations update their systems, particularly older operational systems built on long update cycles.

The practical steps the agencies set out are unsexy but specific: reduce the number of systems exposed to the open internet, patch known flaws faster, retire software that manufacturers no longer support, and tighten controls over who can reach critical networks.

Should you worry about AI on your own side?

The agencies pressed organisations to use AI defensively. Built into security operations, it can spot unusual behaviour earlier and contain incidents before they become financial crises. The statement is clear that buying more tools is not the point. Getting the basics right, fast, is.

Crowe's broader remark to SMH Technology is worth taking seriously: "Our adversaries are using them and we all need to use them to defend our networks." The statement also warns that cyber risk assumptions can become outdated in months, not years, which makes this a board agenda item rather than an annual IT review.

Stephanie Crowe struck a measured note. "I'm actually really positive that we have the tools and we have the capabilities," she said. "If we all take action ... Then we're in a really good place."

What affected organisations should do now

Review which systems are visible to the open internet and close off anything that doesn't need to be there. Apply outstanding security patches, especially on operational or industrial systems. Test your incident response plan before you need it. Treat cyber risk as a standing item in board meetings, not a quarterly IT update.

© 2026 Threat Vectr