U.S. — An international alliance of intelligence agencies issued a joint statement warning that artificial intelligence (AI) models are months, not years, away from being capable of launching major cyberattacks. The Five Eyes alliance urged governments and business leaders to "act now" to improve defenses against sophisticated cyber threats.

The Five Eyes group includes the United States, the United Kingdom, Canada, Australia, and New Zealand. In a release, the intelligence agencies stated: "Leading-edge AI models are expected to exceed current industry expectations, radically transforming both offensive and defensive cyber capabilities. The timeline is not years, but months." The alliance added: "The changing landscape of artificial intelligence is rapidly transforming cyber risk, and we must act quickly to stay ahead." Five Eyes leaders described emerging AI capabilities as able to reduce "barriers for malicious actors and increase the speed and complexity of attacks." The security alliance stated: "Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviors, and respond more quickly to incidents." The alliance advised companies to invest in cybersecurity, update legacy systems, fix defective software, and limit access to critical systems.

Olivia Shen, director of the Strategic Technologies Program at the United States Studies Centre at the University of Sydney, said: "What is meant is that in the AI era, security breaches will occur. It is not a question of if they will occur, but when, so it is important to prepare from now." Shen stated: "The key lesson is that AI capabilities are evolving with incredible speed." Independent evaluations have shown that some AI models already reach expert levels of cyber capability.

Shen stated that sophisticated companies, generally large corporations, already invest in cybersecurity and will be better prepared. "Those that will be most exposed will be small and medium-sized enterprises that may not have invested enough until now, and they will basically be easy prey," she said. She added: "We know that these technologies can be used for both defensive and offensive purposes, and we need to establish some additional safeguards on how we can maximize the benefits for defensive cybersecurity, while keeping it away from potential cyber adversaries, scammers, and cybercriminals."