Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics
theconversation.com

Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics

Tech News
6 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRFive Eyes cybersecurity agencies warn that AI is accelerating cyber threats through automated vulnerability discovery and exploitation, urging defenders to prioritize foundational security practices before deploying AI defense tools. For AI builders, the shrinking patch window and the need for secure-by-construction software are the key takeaways.

Five Eyes cybersecurity agencies from Australia, Canada, New Zealand, the United Kingdom, and the United States have issued a joint call to action warning that artificial intelligence is dramatically accelerating cyber threats through automated vulnerability discovery and exploitation. The statement urges defenders to act urgently but emphasizes that mature cybersecurity fundamentals must come before deploying AI for defense. For AI builders and product teams, the message is clear: the window for patching vulnerabilities is shrinking, and secure-by-construction software design is no longer optional.

What happened

The joint statement from the heads of the Five Eyes cybersecurity agencies warns that AI is already helping adversaries carry out more sophisticated attacks more quickly. AI enables adversaries to find software flaws orders of magnitude faster and to determine how to exploit them, dramatically shrinking the time between vulnerability discovery and exploitation. Defenders can no longer afford to wait weeks before deploying software patches.

The statement comes shortly after the US government caused Anthropic to block access to its most advanced AI models, Mythos and Fable, over fears they could be misused by foreign adversaries to attack US government systems. This context underscores the urgency of the agencies’ call to action.

Why AI builders should care

For teams building AI products, infrastructure, or workflows, this is not a distant policy discussion. The same AI capabilities that accelerate vulnerability discovery for attackers can also be used by defenders, but only if foundational practices are solid. The Five Eyes report notes that cyber fundamentals are crucial and that deploying AI without first investing in cybersecurity basics would be a mistake. As Toby Murray, Professor of Cybersecurity at the University of Melbourne, puts it: “Before reaching for AI, defenders should first invest in their fundamentals. Otherwise, they are effectively deploying a robot guard dog to defend an unlocked door.”

AI builders must assume their adversaries already have access to AI on par with what they use for defense. Open-source models like DeepSeek lag only months behind the most advanced models from OpenAI and Anthropic, and recent research suggests that gap can be closed by pairing less powerful models with complementary technologies. This means the threat is immediate and not limited to state actors.

Practical implications

What should AI builders and operators do now? The Five Eyes statement points to several concrete actions:

  • Rapid patching and vulnerability management: Organizations must have evidence-based processes for tracking known vulnerabilities and prioritizing which to patch. The window for patching is shrinking, so rapid testing and rollout of software patches is essential.
  • Secure-by-construction software: When AI makes finding software vulnerabilities cheap, the next generation of software needs to be engineered to be secure by construction. This means integrating security into the design phase, not bolting it on later.
  • AI-enabled defense tooling: AI can help defenders fix vulnerabilities, confirm patches, and map sensitive assets. But these tools should augment rather than replace strong cyber fundamentals.
  • Asset inventory and exposure management: Defenders must know exactly what assets they need to protect, which systems are exposed, and what defenses are in place. Measuring defense effectiveness and identifying gaps is a prerequisite for AI-driven security.

For product teams shipping AI features, this means ensuring your own infrastructure follows these principles. If you are building AI agents or tools that interact with external systems, consider how automated vulnerability discovery could be used against your stack.

Caveats

The Five Eyes statement is high-level and does not provide specific metrics, timelines, or technical requirements. The reference to Anthropic’s Mythos and Fable blocking is a notable recent event, but details about the models’ capabilities and the exact nature of the threat remain limited. The statement also acknowledges that AI benefits attackers and defenders alike, and that a blanket export ban on advanced AI models is likely to be counterproductive given the availability of open-source alternatives. Defenders should therefore assume adversaries have access to comparable AI capabilities and plan accordingly.

FAQs

AI can play a significant role in cyber defense, but only after foundational cybersecurity practices are in place. The Five Eyes statement notes that AI can help defenders find and fix vulnerabilities, confirm patches, and map sensitive assets. However, deploying AI without mature fundamentals is ineffective.

Sources

Latest Tech News