
Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics
Published by AINave Editorial • Reviewed by Ramit
Five Eyes cybersecurity agencies from Australia, Canada, New Zealand, the United Kingdom, and the United States have issued a joint call to action warning that artificial intelligence is dramatically accelerating cyber threats through automated vulnerability discovery and exploitation. The statement urges defenders to act urgently but emphasizes that mature cybersecurity fundamentals must come before deploying AI for defense. For AI builders and product teams, the message is clear: the window for patching vulnerabilities is shrinking, and secure-by-construction software design is no longer optional.
What happened
The joint statement from the heads of the Five Eyes cybersecurity agencies warns that AI is already helping adversaries carry out more sophisticated attacks more quickly. AI enables adversaries to find software flaws orders of magnitude faster and to determine how to exploit them, dramatically shrinking the time between vulnerability discovery and exploitation. Defenders can no longer afford to wait weeks before deploying software patches.
The statement comes shortly after the US government caused Anthropic to block access to its most advanced AI models, Mythos and Fable, over fears they could be misused by foreign adversaries to attack US government systems. This context underscores the urgency of the agencies’ call to action.
Why AI builders should care
For teams building AI products, infrastructure, or workflows, this is not a distant policy discussion. The same AI capabilities that accelerate vulnerability discovery for attackers can also be used by defenders, but only if foundational practices are solid. The Five Eyes report notes that cyber fundamentals are crucial and that deploying AI without first investing in cybersecurity basics would be a mistake. As Toby Murray, Professor of Cybersecurity at the University of Melbourne, puts it: “Before reaching for AI, defenders should first invest in their fundamentals. Otherwise, they are effectively deploying a robot guard dog to defend an unlocked door.”
AI builders must assume their adversaries already have access to AI on par with what they use for defense. Open-source models like DeepSeek lag only months behind the most advanced models from OpenAI and Anthropic, and recent research suggests that gap can be closed by pairing less powerful models with complementary technologies. This means the threat is immediate and not limited to state actors.
Practical implications
What should AI builders and operators do now? The Five Eyes statement points to several concrete actions:
- Rapid patching and vulnerability management: Organizations must have evidence-based processes for tracking known vulnerabilities and prioritizing which to patch. The window for patching is shrinking, so rapid testing and rollout of software patches is essential.
- Secure-by-construction software: When AI makes finding software vulnerabilities cheap, the next generation of software needs to be engineered to be secure by construction. This means integrating security into the design phase, not bolting it on later.
- AI-enabled defense tooling: AI can help defenders fix vulnerabilities, confirm patches, and map sensitive assets. But these tools should augment rather than replace strong cyber fundamentals.
- Asset inventory and exposure management: Defenders must know exactly what assets they need to protect, which systems are exposed, and what defenses are in place. Measuring defense effectiveness and identifying gaps is a prerequisite for AI-driven security.
For product teams shipping AI features, this means ensuring your own infrastructure follows these principles. If you are building AI agents or tools that interact with external systems, consider how automated vulnerability discovery could be used against your stack.
Caveats
The Five Eyes statement is high-level and does not provide specific metrics, timelines, or technical requirements. The reference to Anthropic’s Mythos and Fable blocking is a notable recent event, but details about the models’ capabilities and the exact nature of the threat remain limited. The statement also acknowledges that AI benefits attackers and defenders alike, and that a blanket export ban on advanced AI models is likely to be counterproductive given the availability of open-source alternatives. Defenders should therefore assume adversaries have access to comparable AI capabilities and plan accordingly.
FAQs
Sources
- Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics
- I spent the weekend digging into AI Security. | Jason Rebholz - LinkedIn
- The risks of artificial intelligence | Bill Gates
- Impact of AI on Cyber Security: Key Stats & Protective Tips
- Bloomberg - Facebook
- How to Fight AI Malware | IBM
- UK spy chief warns AI is an 'unstoppable force' as Russia cyber threat grows
- AI cyber risk: Why existing AI models are already powerful
- Best way to combat AI cyber threats is with AI, Five Eyes security...
- The danger of AI is weirder than you think | Janelle Shane - YouTube
- Hackers used Anthropic AI to 'to commit large-scale theft'
- AI could soon think in ways we don't even understand... | Live Science
- UK spy chief warns AI is an 'unstoppable force' as Russia cyber threat grows
- AI cyber risk: Why existing AI models are already powerful
- Best way to combat AI cyber threats is with AI, Five Eyes security agencies ...






















