Late on a Monday night in Sydney, five of the world's most secretive intelligence agencies did something they almost never do: they spoke together, in public, with urgency. The signals agencies of Australia, the United States, the United Kingdom, New Zealand and Canada — the alliance known as the Five Eyes, formed in the aftermath of the Second World War — issued a joint statement warning that AI-powered cyberattacks capable of devastating governments and businesses were not a distant theoretical risk. The timeline, they said, was not years. It was months.
The warning landed at a moment of particular tension. Earlier in June, the Trump administration had blocked foreign nationals from accessing Fable, a high-profile AI model developed by the American tech company Anthropic. The restriction applied equally to Mythos, an even more powerful Anthropic tool released earlier this year, which is already limited to vetted organisations because of fears that it could be weaponised. Both models are capable of identifying vulnerabilities in cybersecurity systems — a quality that makes them simultaneously valuable to defenders and dangerous in the wrong hands.
What distinguishes the newest generation of AI models from their predecessors, according to Olivia Shen, a national security and AI expert at the University of Sydney's United States Studies Centre, is a specific and alarming capability: "What's different about the latest ones is they're very good at generating exploits." In other words, these systems do not merely find the cracks in a digital wall — they can help an attacker walk through them.