The leaders of the Five Eyes cyber security agencies issued an urgent joint appeal to corporate and government decision-makers, warning that rapidly advancing artificial intelligence is reshaping the threat landscape and demanding faster, fundamentals-first defenses.
“As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead,” the statement says. Emphasizing that frontier models are accelerating both offense and defense, the agencies add: “The timeline is not years, it is months.”
The Five Eyes alliance—spanning Australia, Canada, New Zealand, the United Kingdom and the United States—framed AI as both a force multiplier for attackers and a potent set of tools for defenders. “AI is not a future consideration – it is already here,” the leaders wrote, urging boards and executives to treat cyber risk as a core business responsibility, not a purely technical issue. “Cyber resilience is not an IT issue – it is central to operational continuity and market trust.”
The statement calls for a whole-of-organization and whole-of-society response, pressing leaders to assess risk and readiness, empower cyber teams with authority and resources, and stay engaged as threats and guidance evolve. “Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy,” it says.
Alongside high-level principles—“Secure-by-design and secure-by-default must become standard practice – not an aspiration” and a reminder that “defence in depth remains essential”—the agencies lay out practical steps they say are now urgent:
– Shrink the attack surface by limiting unnecessary access and exposure, and isolating systems that do not need to be online.
– Speed up patching, noting AI is compressing the time between discovery and exploitation.
– Tackle legacy, unsupported systems that represent strategic liabilities.
– Tighten identity and access controls with strong authentication and regular permission reviews.
– Rehearse incident response, assuming breaches will occur and prioritizing swift containment and recovery.
“Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises,” the statement says.
The agencies also urge organizations to adopt AI within security operations to detect vulnerabilities earlier, improve software quality, spot anomalous behavior, and accelerate response. “Adversaries are already using AI to move faster and more effectively. Defenders must do the same.”
The leaders caution that the pace of frontier AI development is rendering standard risk assumptions obsolete in “months, not years,” and they encourage closer collaboration across industry and vendors under the Five Eyes’ existing threat-sharing partnerships. “We must act now,” they write, adding that leaders who move quickly will bolster resilience and market confidence, while those who delay “will face growing and avoidable risk.”
Signatories listed alongside the statement include Stephanie Crowe (Australian Cyber Security Centre, Australian Signals Directorate), Rajiv Gupta (Canadian Centre for Cyber Security, Communications Security Establishment), Catriona Robinson (National Cyber Security Centre, Government Communications Security Bureau), Richard Horne (National Cyber Security Centre, Government Communications Headquarters), David Imbordino (Cyber Security Directorate, National Security Agency), and Nick Andersen (Acting Director, CISA).






