The Five Eyes cybersecurity agencies have issued a direct warning to government, business and critical infrastructure leaders: artificial intelligence is no longer an emerging cyber risk - it is already changing the speed and shape of attacks.
In a joint statement released on June 22, 2026, cyber leaders from Australia, Canada, New Zealand, the United Kingdom and the United States said AI was transforming both offensive and defensive cyber capability.
Their central message was that organisations can no longer plan on traditional cyber risk timelines. The agencies warned that frontier AI models could reshape cyber operations within months rather than years.
AI is changing both attack and defence
The warning does not frame AI solely as a hostile tool. The same technologies can help defenders find vulnerabilities earlier, improve software quality, detect abnormal behaviour and respond faster to incidents.
However, the agencies said the immediate risk is that malicious actors are also using AI to move faster, automate more steps in the attack chain and reduce the skill needed to conduct sophisticated activity.
Shrinking time to respond
A key concern is the narrowing gap between vulnerability discovery and exploitation. In practical terms, organisations may have less time to patch systems, review exposure or contain a breach before attackers act.
This is especially significant for critical infrastructure, operational technology environments and organisations running legacy systems that are difficult or slow to update.
Boards urged to treat cyber as business risk
The Five Eyes statement places responsibility squarely with boards and executives. Cyber risk, the agencies said, should be treated as a core business risk linked to operational continuity, market trust, financial exposure and regulatory liability.
The warning is therefore not just aimed at security teams. It is directed at leadership groups that decide budgets, risk appetite, technology strategy and incident readiness.
Basic cyber controls become more important
The agencies’ recommended response is deliberately practical. Organisations are being urged to reduce their attack surface by limiting unnecessary internet exposure and access pathways; accelerate patching processes; deal with unsupported legacy systems; strengthen identity and access controls; and rehearse incident response before an attack occurs.
The underlying message is that basic controls matter more, not less, in an AI-enabled threat environment.
Agentic AI brings new risk
The warning also connects with separate Five Eyes guidance on agentic AI — systems that can reason, plan and take actions through tools, data sources and software integrations.
These systems offer automation benefits, but they also introduce new security problems because they can act with delegated privileges across connected environments.
Prompt injection and privilege risk
The agentic AI guidance highlights several risks. Agents may inherit weaknesses from large language models, including prompt injection. They may increase the attack surface by connecting to external tools, memory stores, APIs and data sources.
They may also create privilege risks if given broad access to systems, files, email, financial records or operational workflows. In a poorly designed environment, a compromised tool or manipulated instruction could cause an AI agent to take actions that appear legitimate in audit logs but are harmful in practice.
Guardrails for AI deployment
For organisations considering agentic AI, the guidance is clear: do not grant broad or unrestricted access, especially to sensitive data or critical systems.
AI agents should be scoped to low-risk tasks first, governed through existing cyber security frameworks and controlled with least privilege, strong authentication, monitoring, segmentation and clear accountability.
Cyber resilience needs to evolve
The broader implication is that AI is forcing a rethink of cyber resilience. Static risk assessments, annual control reviews and slow patching cycles are increasingly mismatched to the pace of AI-enabled threat activity.
Leaders need assurance that security controls will work during a real incident, not just that they exist on paper.
Strategic adoption, not hesitation
The Five Eyes warning is not a call to halt AI adoption. It is a call to adopt it deliberately.
Organisations that use AI defensively while strengthening foundational controls may improve resilience. Those that deploy AI tools without governance or delay basic cyber hygiene, face greater exposure as attackers become faster and more automated.
For technology leaders, the priority is now twofold: secure the organisation against AI-enabled attacks, and secure the AI systems being introduced into the organisation. Both tasks depend on the same foundations — visibility, identity control, secure design, defence in depth, tested incident response and executive accountability.
The message from the Five Eyes agencies is that the window to prepare is narrowing. AI has already entered the cyber threat landscape, and the organisations best placed to withstand it will be those that treat cyber resilience as a strategic function rather than a technical afterthought.