- The Five Eyes cybersecurity chiefs — from Australia, the US, UK, Canada, and New Zealand — have issued a rare joint statement warning that AI is reshaping cyber threats faster than most organisations can respond.
- AI is compressing the time between vulnerability discovery and exploitation, making outdated cyber risk assumptions genuinely dangerous.
- Stephanie Crowe, head of the Australian Cyber Security Centre, says defenders must use AI themselves — not just defend against it.
- The Anthropic model suspension on June 13 exposed just how quickly frontier AI capabilities are advancing and intersecting with national security concerns.
- Leaders who treat this as an IT problem rather than a core business risk are already behind — keep reading to understand what the agencies are actually telling you to do.
The world’s most powerful cybersecurity agencies just said the same thing at the same time, and that almost never happens.
On June 22, 2026, the Five Eyes intelligence alliance — comprising Australia, the United States, the United Kingdom, Canada, and New Zealand — released a joint statement unlike anything seen before in its scope and urgency. The statement warns that artificial intelligence is not a future threat. It is an active, accelerating one. For organisations still treating cyber risk as a background concern, this warning is a hard reset.
Key Takeaways: Five Eyes Agencies Sound the Alarm on AI Cyber Threats
The core message from the Five Eyes statement is direct: frontier AI models are expected to exceed industry expectations and will fundamentally transform both how attacks are carried out and how defences must be structured. The window to act is narrowing, not widening.
AI Is Already Reshaping Cyber Attacks Right Now
Most organisations still think of AI-enabled cyber threats as something to prepare for in the coming years. The Five Eyes agencies are saying that timeline is wrong. AI is already being used by state-backed actors and criminal groups to increase the scale, speed, and sophistication of attacks happening right now.
Why the Five Eyes Statement Is Historically Significant
Joint statements from all Five Eyes cybersecurity agencies are rare. When they do occur, they signal a threat level that individual agencies consider too serious to address alone. The fact that the heads of these agencies — not just staff-level representatives — co-signed this statement makes it one of the most significant coordinated cybersecurity warnings in recent history. For further understanding of cybersecurity threats, explore different cybersecurity testing methods.
“Leaders must act now by strengthening foundational security practices, reducing exposure and embedding cyber risk into organisational strategy. These actions will help organisations withstand and recover from increasingly sophisticated, AI-enabled cyber incidents.”
— Five Eyes Cybersecurity Agencies Joint Statement, June 22, 2026
The statement is not theoretical. It reflects what these agencies are actively observing in their respective threat environments — attacks that are faster, more adaptive, and harder to detect than what traditional security tools were built to handle.
What “Compressing the Timeline” Actually Means for Organisations
One of the most critical warnings in the statement is about time. AI is shortening the gap between when a vulnerability is discovered and when it is exploited. In practical terms, this means a flaw found on a Monday could be weaponised by Wednesday. Security teams that previously had days or weeks to patch critical systems now have hours.
This is especially dangerous for operational environments with long update cycles — think critical infrastructure, healthcare systems, and industrial control environments. These are exactly the systems that attackers are prioritising, and the compressed exploitation window makes delays in patching genuinely life-threatening in some contexts, not just operationally disruptive.
What the Australian Signals Directorate Chief Actually Said
Stephanie Crowe, head of the Australian Cyber Security Centre at the Australian Signals Directorate (ASD), was among the signatories of the joint statement. Her comments add important context to what the agencies are collectively warning about.
Stephanie Crowe’s Warning on AI-Enabled Attacks
Crowe did not soften the message. She acknowledged that adversaries — both state-backed groups and criminal organisations — are already integrating AI into their attack methods. The implication is clear: if defenders are not using the same tools, they are operating at a structural disadvantage that will only widen over time.
Her statement cuts through the noise that often surrounds AI discussions in cybersecurity. This is not about hypothetical scenarios or long-range forecasting. It is about what is happening in the threat landscape right now, and what organisations must do immediately to avoid becoming the next headline.
Why Crowe Is Still Optimistic Despite the Threat
Despite the severity of the warning, Crowe expressed confidence that Australia is well placed — but only if organisations take the threat seriously. That conditional is doing a lot of work. The resilience she is describing is not passive. It requires active decisions at the leadership level to invest in defences, update practices, and embed cyber risk into how the business is run.
Defenders Must Use AI Too, Not Just Worry About It
Crowe was explicit: “Our adversaries are using them and we all need to use them to defend our networks.” This is arguably the most actionable takeaway from her public comments. Organisations that deploy AI in their security operations can detect vulnerabilities earlier, identify unusual behaviour in real time, and respond to incidents faster than teams relying solely on traditional tools.
The Anthropic Model Suspension That Rattled Security Experts
Just nine days before the Five Eyes statement was published, something happened that underscored exactly why these agencies are sounding the alarm. On June 13, 2026, Anthropic suspended worldwide access to its two most powerful AI models — Fable 5 and Mythos 5 — following a US export control directive tied to national security concerns.
Why Australian Users Lost Access Without Warning on June 13
The suspension was abrupt and without advance notice to users. Australian organisations that had integrated Fable 5 and Mythos 5 into their security operations, research workflows, or business processes found themselves locked out overnight. The incident was a sharp reminder that frontier AI tools — no matter how embedded they become — can be switched off for geopolitical reasons entirely outside any organisation’s control. Dependency on a single AI provider is now a cyber risk in itself.
The 73% System Breach Rate That Changed the Conversation
Context: The Five Eyes joint statement referenced findings showing that AI-enabled attack tools achieved a 73% system breach rate in controlled testing environments. This figure has become a reference point in the conversation about how quickly AI is shifting the advantage toward attackers.
A 73% breach rate is not a marginal improvement over traditional attack methods. It represents a structural shift in what attackers can accomplish without needing deep technical expertise. AI is effectively democratising advanced attack capabilities — tools that once required nation-state resources are now accessible to criminal groups operating at scale.
What makes this figure particularly alarming is the context in which it was observed. These were not attacks against poorly defended targets. They were controlled tests, which means real-world results against underprepared organisations could be significantly worse. The gap between what attackers can do and what most organisations are prepared to handle is widening faster than most security teams realise. For a deeper understanding of these vulnerabilities, you can explore various cybersecurity testing methods that highlight the importance of being prepared.
For boards and executives, this number reframes the conversation entirely. Cyber risk can no longer be managed through compliance checklists and annual penetration tests. The threat environment is moving in real time, and the defences must move with it, as highlighted by various cybersecurity testing methods.
Cyber Risk Is Now a Board-Level Problem, Not an IT Problem
The Five Eyes statement is addressed directly to leaders — not IT departments, not security teams, but the people making strategic decisions about where organisations invest and how they operate. This framing is deliberate. The agencies are signalling that the decisions required to manage AI-enabled cyber risk cannot be delegated down the organisational chart.
Boards that have treated cybersecurity as a technical function handled somewhere below the C-suite are now operating with a blind spot that adversaries are actively exploiting. The statement makes clear that embedding cyber risk into organisational strategy is not optional infrastructure work. It is a leadership responsibility with direct consequences for operational continuity, financial stability, and in some sectors, public safety.
What “Core Business Risk” Means in Practice
When the Five Eyes agencies say cyber risk must be treated as a core business risk, they mean it should sit alongside financial risk, regulatory risk, and reputational risk in how leaders make decisions. That means cyber considerations belong in budget discussions, merger and acquisition due diligence, vendor selection, and product development — not just in the security team’s quarterly report.
In practical terms, this looks like a CEO who understands the organisation’s most critical digital dependencies and knows what happens if they fail. It looks like a board that receives regular, plain-language briefings on threat exposure — not just compliance status. And it looks like a CFO who has modelled the financial impact of a significant breach, not just the cost of security tools.
The Difference Between Having Controls and Actually Being Resilient
- Having controls means your organisation has installed security tools, written policies, and ticked the boxes required by your compliance framework.
- Being resilient means your organisation can absorb a sophisticated AI-enabled attack, detect it quickly, contain the damage, and recover operations without catastrophic disruption.
- Controls without resilience is the most common gap the Five Eyes agencies are seeing — organisations that look secure on paper but have never stress-tested what happens when something actually breaks.
- Resilience requires practice — tabletop exercises, incident response drills, and honest assessments of where your recovery capabilities actually fall short.
- AI changes the resilience equation because attacks can move faster than human response teams, meaning automated detection and response capabilities are no longer a luxury but a baseline requirement.
The distinction matters because compliance frameworks were not designed for the current AI threat environment. Many were built around threat models that are already outdated. Organisations that mistake compliance for security are leaving themselves exposed in ways their audit reports will not reveal until something goes wrong.
Resilience also requires knowing your dependencies. If a critical vendor goes down — as Anthropic’s users discovered on June 13 — do you have a continuity plan? If a key system is breached, how long does it take to detect, isolate, and recover? These are the questions resilience planning forces organisations to answer before an attacker forces them to find out the hard way.
Practical Steps the Five Eyes Agencies Are Telling Leaders to Take Now
The joint statement does not just describe the problem — it provides direction. These are not vague aspirational goals. They are specific operational actions that the agencies are telling leaders to prioritise immediately. The urgency is real: every week of delay is a week in which the exploitation window for known vulnerabilities stays open.
1. Cut the Number of Systems Exposed to the Internet
Every internet-facing system is a potential entry point for attackers. AI tools can now scan for and identify exposed systems at a scale and speed that makes broad internet exposure extremely dangerous. The agencies are recommending that organisations conduct an honest audit of what is exposed and aggressively reduce that attack surface — disconnecting anything that does not need to be publicly accessible.
2. Patch Known Vulnerabilities Faster
With AI compressing the exploitation timeline, the agencies are explicit: slow patching is no longer an acceptable operational trade-off. Known vulnerabilities must be prioritised and patched as fast as operationally possible. For systems that cannot be patched immediately — particularly legacy operational technology — compensating controls must be implemented in the interim to reduce exposure. For instance, the August Patch Tuesday highlights the urgency of addressing vulnerabilities promptly.
3. Retire Unsupported Legacy Systems
Legacy systems running unsupported software are among the highest-risk assets any organisation can hold. They cannot receive security patches, they often have hard-coded credentials, and they were designed in an era when AI-enabled attacks were not a consideration. The agencies are pushing organisations to develop and execute concrete retirement plans for these systems — not indefinite roadmaps, but actual timelines with accountability.
4. Tighten Access Controls to Critical Networks
Access control is one of the most effective defences against AI-enabled attacks, and one of the most commonly neglected. The Five Eyes agencies are recommending that organisations implement strict controls over who can reach critical systems — starting with a zero-trust approach that assumes no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter.
Privileged access — accounts with administrative rights over critical infrastructure — must be treated as high-value targets, because they are. Multi-factor authentication should be mandatory for all privileged accounts without exception. Where possible, just-in-time access models should be implemented, so that elevated permissions are granted only when needed and automatically revoked when the task is complete.
Network segmentation is equally important. If an attacker does breach one part of your environment, segmentation limits how far they can move laterally. The agencies are pushing organisations to treat network architecture as a security control, not just an IT infrastructure decision.
5. Embed Cyber Risk Into Organisational Strategy
This is the overarching action that makes all the others sustainable. Patching faster and reducing internet exposure are tactical wins. Embedding cyber risk into organisational strategy means the decisions that create or reduce cyber risk are made at the right level, with the right information, before problems occur rather than after. That means cyber risk has a seat in the boardroom, a line in the budget, and a voice in strategic planning — not just a report filed quarterly by the IT department.
Leaders Who Delay Face Growing and Avoidable Risk
The Five Eyes joint statement uses the word “now” deliberately. AI is not waiting for organisations to finish their three-year digital transformation roadmap. Attackers are using it today, against systems that were designed with yesterday’s threat assumptions. Every month that passes without meaningful action is a month in which the gap between attacker capability and organisational readiness widens further.
The risk is avoidable — that is the other half of this message. The agencies are not saying the situation is hopeless. They are saying the tools, practices, and guidance exist to significantly reduce exposure, but only for organisations whose leaders choose to act. The ones who wait for a breach to motivate change will find that the cost of recovery far exceeds the cost of prevention, in every sense of the word.
Frequently Asked Questions
Below are answers to the most common questions raised by the Five Eyes AI cyber risk warning. If you are a business leader, security professional, or simply someone trying to understand what this means for the organisations you depend on, these answers cut through the technical language and get to what actually matters.
The warning has generated significant public attention because of who signed it and how direct the language is. Understanding the key terms and context helps make sense of what the agencies are actually asking organisations to do — and why the urgency is real rather than performative. For more on cybersecurity approaches, explore cybersecurity testing methods.
Each question below reflects something leaders across government, industry, and critical infrastructure are actively asking. The answers draw directly from the joint statement and related public commentary from the agencies involved.
What is the Australian Signals Directorate and why does its warning matter?
The Australian Signals Directorate (ASD) is Australia’s national intelligence and cybersecurity agency. It is responsible for offensive cyber operations, signals intelligence, and protecting Australian government and critical infrastructure systems from cyber threats. Its cybersecurity arm, the Australian Cyber Security Centre (ACSC), publishes technical advice, threat alerts, and advisories that set the standard for cyber practice across Australian organisations.
When the ASD speaks on cybersecurity, it is drawing on classified threat intelligence, active incident response experience, and deep technical capability. Stephanie Crowe’s co-signature on the Five Eyes statement carries weight precisely because her agency sees the threat environment in real time — not through vendor reports or academic modelling, but through direct operational observation of what adversaries are actually doing.
What are the Five Eyes agencies and why did they issue a joint statement?
The Five Eyes is an intelligence-sharing alliance between Australia, the United States, the United Kingdom, Canada, and New Zealand. The alliance’s cybersecurity agencies — including the ASD’s ACSC, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), the Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre — issued their joint statement on June 22, 2026, because the AI-driven shift in cyber risk is a threat that crosses national borders and requires a coordinated response. Joint statements of this nature are rare and signal a threat level that individual agencies consider too urgent to address in isolation.
How is AI making cyber attacks more dangerous?
AI is making cyber attacks more dangerous in three compounding ways. First, it is increasing the scale of attacks — AI tools can scan millions of systems for vulnerabilities simultaneously, something that previously required significant human effort. Second, it is increasing the speed — the time between a vulnerability being discovered and being exploited is shrinking from weeks to days or even hours. Third, it is lowering the skill barrier — attack capabilities that once required nation-state resources or highly trained threat actors are now accessible to criminal groups with far less technical sophistication.
The combination of these three factors is what makes the current moment different from previous cybersecurity challenges. It is not just that attacks are more sophisticated — it is that they are more frequent, faster, and coming from a broader range of adversaries than ever before. Defenders who do not integrate AI into their own security operations are increasingly trying to fight a modern threat with outdated tools.
What was the Anthropic model suspension and why is it relevant to cybersecurity?
- Date: June 13, 2026 — nine days before the Five Eyes statement was published.
- What happened: Anthropic suspended worldwide access to its two most powerful AI models, Fable 5 and Mythos 5, following a US export control directive tied to national security concerns.
- Who was affected: Organisations globally — including in Australia — that had integrated these models into security operations, research workflows, or business processes lost access without warning.
- Why it matters for cybersecurity: The incident exposed a new category of cyber risk — AI supply chain dependency. Organisations that rely on a single AI provider for critical functions now face the risk of losing those capabilities overnight for geopolitical reasons entirely outside their control.
The Anthropic suspension is relevant to the Five Eyes warning because it illustrates exactly the kind of rapid, unexpected disruption that the agencies are urging leaders to plan for. An organisation that had embedded Fable 5 into its threat detection workflow and had no backup capability was, from a security operations standpoint, suddenly blind.
This is not an argument against using AI in security operations — the agencies are explicitly encouraging it. It is an argument for building resilience into how AI tools are sourced, deployed, and backed up. Single points of failure in AI infrastructure are a risk category that most organisations have not yet formally assessed. For instance, understanding the importance of network security can be a crucial step in mitigating these risks.
The timing of the suspension — days before a major coordinated cybersecurity warning — also highlights how quickly the AI landscape can shift for reasons that have nothing to do with technical performance. Export controls, regulatory decisions, and geopolitical pressures can all affect access to frontier AI tools in ways that security planning must now account for.
For Australian organisations in particular, the suspension served as a practical stress test. Those with mature AI governance frameworks — including documented dependency maps and continuity plans for critical AI tools — were able to adapt. Those without them faced an unplanned operational gap at exactly the moment the threat environment was being described as more dangerous than ever.
What should businesses do right now in response to this AI cyber risk warning?
Start with exposure reduction. Conduct an audit of every internet-facing system your organisation operates and ask honestly whether each one needs to be publicly accessible. Every unnecessary exposure is an open door. At the same time, review your patch management process — specifically, how long it takes from a critical vulnerability being published to it being patched across your environment. If the answer is weeks, that timeline needs to be shortened immediately.
Then move to governance. Cyber risk needs to be on the agenda at the board and executive level — not as a compliance update but as a strategic risk discussion. That means understanding your most critical digital dependencies, knowing what your recovery capability looks like if a key system is breached, and making sure the people responsible for cybersecurity compliance have the authority and budget to act without waiting for a crisis to justify the investment.
Finally, take the AI dimension seriously on both sides. Assess whether your adversaries could be using AI to attack your systems faster than your team can currently detect and respond. Then evaluate whether AI tools could be integrated into your own security operations to close that gap. The Five Eyes agencies are not suggesting AI is a silver bullet — but they are saying clearly that defenders who refuse to use it are choosing to operate at a disadvantage that is only going to grow.
If you are looking for expert guidance on navigating the evolving AI cyber risk landscape, the Australian Cyber Security Centre at the Australian Signals Directorate publishes technical advisories, alerts, and practical frameworks at cyber.gov.au to help organisations of all sizes strengthen their defences.

