Five Eyes to CSOs: AI Has Already Changed Your Threat Model — Act Now
A joint advisory from CISA and four allied agencies demands strategic action on AI-amplified threats. Experts say the advice is late, vague, and misses the real risk sitting inside your own network.

Key points
- Five Eyes agencies issued a joint statement Monday demanding CSOs overhaul cyber risk strategies in response to AI-accelerated threats.
- The advisory sets out three principles and five practical actions, four of which predate the AI era.
- Experts say the guidance is overdue and omits AI-specific risks including social engineering transformation and generative AI data leakage.
- Corporate leadership deploying AI without informing the CSO is, by one expert's reckoning, a bigger threat than any external adversary.
- CISA's AI guidance portal contains more granular detail than the statement itself.
What did Five Eyes actually say?
The US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cyber Security Centre, the Canadian Centre for Cyber Security, the Australian Cyber Security Centre, and New Zealand's Cyber Security Directorate warned Monday that frontier AI models will "fundamentally transform" offensive and defensive capabilities. The timeline, they wrote, is months, not years. Cyber resilience is a board-level business continuity issue, not a technical one. Three core principles follow: treat secure-by-design and secure-by-default as standard practice rather than aspiration, implement defense in depth, and prepare for novel zero-day vulnerabilities. Five practical actions accompany them, covering attack surface reduction, patching velocity, legacy systems, identity and access controls, and incident response testing.
The Canadian Centre for Cyber Security told reporters the timing reflects "real, recent shifts" in AI tooling, specifically accelerated vulnerability discovery and exploitation. "Waiting will only narrow the window to respond," the agency said.
Should you worry about the gaps?
Experts aren't impressed. Joseph Steinberg, a cybersecurity and AI advisor to governments and enterprises, called the statement "generic" and said it "does not provide meaningful guidance about addressing AI risks." His specific objection: four of the five practical actions predate the AI era entirely. Missing from the advisory are AI's transformation of social engineering, expanded reconnaissance capability, generative AI data leakage risks, and the hard-to-reverse problem of poisoned training data.
Ilia Kolochenko, CEO of ImmuniWeb and adjunct professor at Capitol Technology University, argued the statement should have arrived in late 2023. He put the sharpest point on the insider problem: corporate leadership routinely deploys AI systems without informing the CSO, let alone running a risk assessment. That rush introduces attack surface faster than any external adversary. "No zero-days or faster exploitation cycles with AI are needed anymore," Kolochenko said. Most large organizations already carry enough misconfigured assets that an attacker can exfiltrate critical data without a single exploit.
Rob Enderle of the Enderle Group called the guidance "incredibly late" but acknowledged it delivers a necessary baseline for organizations still catching up. Cyber risk strategy, he said, needs to run from the CEO down, not from the SOC up.
CISA, responding to criticism that the statement is too generic, pointed to its AI guidance resources portal for more granular detail on AI data security and secure-by-design principles.
This isn't the first time a Five Eyes advisory has leaned on operator hygiene over novel prescription. Our June report on CISA's ATG warning reached the same conclusion: the fix is usually basics, done properly.
The advisory's own admission is telling: "These actions are not new, but are now urgent." Whether that framing is honest or damning depends entirely on how long your patch backlog already is.



