Five Eyes Warns AI Is Changing Cyber Threats Faster Than We Can Keep Up

Last week, the Five Eyes intelligence alliance put out a joint statement on AI cyber risks. It’s not as dramatic as the headlines made it sound, but the message is clear: AI changes everything, and fast.

Here’s the core issue. For most of human history, skill and ability meant the same thing. Computers broke that link. Now AI is busting it wide open.

People with minimal expertise can do real damage. We’re talking autonomous hacking, data theft, ransomware deployment — all with minimal prompting. The models don’t need skilled operators anymore. They’re getting good enough to act on their own.

Remember L0pht? Back in 1998, seven hackers told Congress they could take down the internet in 30 minutes. Part bravado, part truth. But here’s what mattered: they had actual skill. Contrast that with script kiddies — people running tools they barely understand. They couldn’t have built those tools, but they could use them.

AI is the ultimate script kiddie enabler. Only worse.

The problem isn’t just the frontier models from OpenAI and Anthropic. It’s the open-source ones running on laptops. No guardrails. No reporting back to headquarters. They’ll be passed around like hacker toolkits.

Can we build models that can’t do harm? No. Same reason you can’t teach doctors to treat poisoning without also teaching them how to poison. The knowledge is the same. We want AI to find vulnerabilities and fix them automatically — but that same capability works for attacks.

The Five Eyes statement doesn’t break new ground. It’s the same advice security pros have been giving for decades. What’s different is the timeline now. AI development moves so fast that risk assumptions go stale in months, not years.

The solution, as far as there is one, involves fighting AI with AI — detecting vulnerabilities earlier, improving software quality, and responding faster to incidents. Standard stuff. Just way more urgent.

References