SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Five Eyes warning: AI reshapes cyber security priorities now

Five Eyes warning: AI reshapes cyber security priorities now

Tue, 4th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Five Eyes cyber agencies have warned that advanced artificial intelligence models will rapidly transform both offensive and defensive cyber operations, sharpening focus on how AI is reshaping risk for critical infrastructure operators and smaller organisations alike.

Recent joint guidance from the UK, US, Canada, Australia and New Zealand says frontier AI systems could change the nature of cyber threats within months. Agencies across the alliance say AI is lowering barriers to entry for less skilled attackers while increasing the speed and scale of operations by more capable actors.

Industry leaders and security specialists are drawing a distinction between AI-driven attacks and AI-driven discovery of long-standing weaknesses. They argue that the most immediate effect is on the volume, quality and tempo of both exploitation and defence.

Terry Lewis, Chief Executive Officer of UK-based security firm Roboshadow, said the surge in recorded software vulnerabilities reflects both hostile use of AI and proactive efforts by defenders.

"The UK, US, Canada, Australia and New Zealand issued joint guidance with a simple message: frontier AI will 'fundamentally transform' both offensive and defensive cyber capabilities within months. The Five Eyes are not wrong. AI is here, and it is compressing timelines and lowering the barrier to entry for people who want to cause trouble.

"Yet while AI is causing a 'tsunami' of new vulnerabilities, that is not the full picture. A huge chunk of the CVE surge comes from the good guys pointing frontier-class, advanced-reasoning AI models at their own code bases and finding latent bugs that had sat there for years, completely invisible. These vulnerabilities existed before the AI era; AI just surfaced them faster. The risk is not frontier AI magically breaking everything everywhere. It is organisations that ignore the warnings, skip patching, and assume they are too small or too obscure to matter," Lewis said.

The warning comes as the Australian Signals Directorate and partners, including the FBI Cyber Division, the UK's National Cyber Security Centre, Canada's Communications Security Establishment and New Zealand's National Cyber Security Centre, issued new joint guidance for operational technology environments. The CI Fortify publication focuses on how critical infrastructure operators can isolate vital systems during incidents or periods of heightened threat.

The guidance reflects growing concern about nation-state actors and advanced criminal groups gaining access to industrial control systems and other operational networks. It urges operators to prepare isolation strategies in advance and understand dependencies between business IT systems and the technology that runs physical processes.

Sean MacKirdy, Area Vice President of National Security at Elastic, said the document marks a shift in how Five Eyes agencies frame critical infrastructure security.

"This CI Fortify guidance for operational technology represents a continued evolution in how Five Eyes cybersecurity leaders are framing critical infrastructure security, moving toward a true operational resilience approach to address nation-state actors who have demonstrated access inside OT environments.

"Effective isolation depends on visibility: knowing what to isolate, when, and how to preserve the communications that keep critical services running. Isolating vital OT systems can disrupt business processes, and automated processes will most likely need to be completed manually during the isolation period.

"That is where broad, unified visibility across IT infrastructure becomes a strategic capability rather than a nice-to-have. To maintain critical infrastructure operations that affect citizen services, operators and cyber first responders must improve visibility, accelerate threat detection and enable containment actions that reduce attackers' lateral movement while preserving critical operations.

"CI Fortify emphasises that preparation is key. Operators should be building isolation and recovery capabilities now by ingesting and correlating logs, endpoint telemetry, network data and alerts across both IT and OT environments. That helps defensive cyber teams map dependencies between IT and OT support systems.

"With full visibility into this security data, organisations can establish a baseline and make anomalies far easier to spot during periods of heightened threat. Achieving that resilience requires the visibility to identify potentially compromised IT and support systems before they affect critical infrastructure, the ability to isolate impacted hosts quickly without going dark on them, and a risk-based approach to segmentation that protects critical operational processes while preserving the monitoring capability defenders need," MacKirdy said.

The combination of AI-enabled threats and new guidance on OT isolation underlines the strain on organisations that still rely on fragmented monitoring and manual processes. Security experts say smaller businesses and regional critical infrastructure providers face particular pressure as they deal with legacy vulnerabilities exposed at machine speed by both attackers and defenders.