Guidelines  ·  2026-06-23

Five Eyes Joint Statement: 'The AI Shift in Cyber Risk — Why Leaders Must Act Now'

GuidelinesHigh impactAustralia
The heads of the Five Eyes cybersecurity agencies (NCSC/UK, CISA/US, ASD/Australia, CSE/Canada, GCSB/New Zealand) issued a joint public statement on 22 June 2026, signed by all five directors. The statement declares AI is already transforming cyber risk — accelerating attack speed, lowering barriers for malicious actors, and shortening the vulnerability-to-exploit window — and calls on organisational leaders to act now. Key directives: reduce attack surface, accelerate patching, address legacy systems, strengthen identity and access controls, and actively integrate AI into defensive operations. A companion PDF was published on the NCSC website.
This is the highest-authority collective statement on AI-driven cyber risk issued to date, co-signed by the acting director of CISA and the NSA Cyber Directorate head. It formally elevates AI risk to a board-level leadership responsibility — not an IT matter — and signals that Five Eyes agencies are aligned on the urgency and the practical controls required. The statement warns that frontier AI timelines are 'months, not years' and calls secure-by-design a requirement, not aspiration.
Boards and executives should review the five practical actions in the statement immediately: reduce attack surface, accelerate patching, remediate legacy systems, strengthen identity/access controls, and prepare incident response. Integrate AI-enabled defensive tools into security operations.
NCSC News: The AI Shift in Cyber Risk — Why Leaders Must Act Now (22 June 2026)Five Eyes Joint Statement PDF (NCSC, 22 June 2026)Full statement text PDFCyberScoop coverage (22 June 2026)NSA: Five Eyes Cyber Security Agencies Statement (official press room, June 22 2026)ASD/ACSC: Five Eyes Statement PDF (cyber.gov.au, June 2026)Reuters: Five Eyes intelligence alliance warns new AI models pose urgent cyber risk (June 22 2026)ASD (Australia) — Five Eyes Cyber Security Agencies StatementInfosecurity Magazine — Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats (June 23, 2026)CISA — Five Eyes Cyber Security Agencies StatementCSO Online — Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs (22 Jun 2026)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →