Five Eyes warns AI threat to cybersecurity is moving on a ‘months’ timeline

Five Eyes issues urgent AI cyber warning
The intelligence agencies of the U.S., U.K., Canada, Australia and New Zealand issued a joint warning Monday that rapidly evolving AI is becoming an urgent cybersecurity threat, saying business leaders must move now to harden defenses.
Frontier AI models will likely “exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” the Five Eyes announcement said. “The timeline is not years, it is months.”
The agencies said AI is lowering barriers for malicious actors while increasing the speed and complexity of attacks, shrinking the time between finding a vulnerability and exploiting it. At the same time, they said AI can strengthen defense, making immediate action necessary rather than optional.
Boards and executives should ensure cyber resilience “works under pressure,” the announcement said, warning that it is “not enough to have controls.” Leaders were urged to reduce their attack surface by cutting system access and external connectivity wherever possible, pressure-test whether systems need to be exposed, and isolate those that do not.
The guidance also called for faster patching, saying AI is compressing the window between vulnerability discovery and exploitation. Legacy systems, the agencies said, are especially risky because “unsupported systems are easy targets” and should be treated as “strategic liabilities,” not just technical debt.
Pressure on patching, access and resilience
The alert lands amid a broader push by governments to respond to AI-enabled cyber risks. The U.S. Cybersecurity and Infrastructure Security Agency recently said federal agencies will need to use a prioritization triage system to determine whether some vulnerabilities must be patched in less than three days, partly based on whether AI is involved.
The Trump administration also recently blocked Anthropic from selling its Mythos and Fable models abroad over national security concerns, though President Trump later said he no longer viewed the company as a security threat. An Anthropic spokesperson said the two sides were still working on the issue.
Five Eyes said organizations should strengthen access controls, limit the number of people with access to critical systems, and use tough authentication methods. It also urged companies to give internal cyber leaders the money and authority needed to apply foundational security practices and keep pace with changing threats.
Secure-by-design and secure-by-default should become standard, the announcement said, as AI continues to reshape both attack and defense.
Sources: