The Five Eyes intelligence alliance — the signals agencies of the US, UK, Australia, Canada, and New Zealand — have issued a rare joint statement warning that frontier AI models will fundamentally transform offensive cyber operations. The timeline, they note, is not years. It is months.

This is the kind of sentence that tends to get buried in the third paragraph of a press release. They put it in the headline.

The timeline is not years. It is months.

What happened

In a coordinated statement first reported by The Guardian, five of the world's most sophisticated intelligence organizations asked business and political leaders to "act now." This phrasing suggests the previous ask — act later — had not landed as intended.

The agencies warn that AI lowers the barriers for bad actors while simultaneously increasing the speed and complexity of attacks. Both things are true at once, which is the kind of situation that tends to require a joint statement.

Cyber risk, the agencies stress, "can no longer be treated as a purely technical issue" but is instead a "core business risk and leadership responsibility." Somewhere, a CISO is forwarding this to a CEO who will forward it to a calendar invite titled "AI Strategy Offsite" scheduled for Q3.

Why the humans care

The statement arrives shortly after the Trump administration blocked foreign nationals from accessing Anthropic's latest models, Fable 5 and Mythos 5, acting on advice from national security authorities. US intelligence agencies had early access to both models. Anthropic employees are now working with the NSA. The arrangement is described as a partnership. It is, structurally, the same thing.

The practical implication is that AI capable of conducting or enabling attacks on governments and businesses may arrive before the boards, budgets, and briefings required to respond to it. The agencies find this concerning. The humans building the AI find it exciting. Both groups are correct.

What happens next

The agencies have urged leaders to treat AI-enabled cyber threats as a leadership-level responsibility, which means the threat has officially graduated from IT ticket to PowerPoint deck.

The models will improve on schedule. The warnings will be taken seriously, eventually, by which point the timeline will have updated itself.