Issued June 23, 2026 by the leaders of the Five Eyes cyber security agencies. Summarized here from the New Zealand NCSC (GCSB) announcement, which quotes the joint text; Catriona Robinson, Deputy Director General Cyber Security and head of the NCSC, signed for New Zealand. The Call to Action itself is a separately published PDF not captured here.
This is distinct from the May 2026 Five Eyes joint guidance on agentic AI (Five Eyes Joint Guidance on Secure Deployment of AI Agents (May 2026)): that document addresses how to deploy agents safely, while this one addresses defensive readiness against AI-accelerated attack.
The core claim
The joint statement opens: "As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead."
The framing rejects a prospective reading: "AI is not a future consideration – it is already here. It lowers barriers for malicious actors and increases the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly. At the same time, AI offers powerful tools to strengthen defence."
The specific threat identified is frontier AI's "ability to identify and exploit vulnerabilities at unprecedented speed and scale." The operative variable is the compression of the discovery-to-exploitation interval — the window within which defenders patch — rather than an increase in the number of vulnerabilities alone. The statement's prediction to organisations follows from that: they should "prepare now for a significant increase in vulnerabilities and incidents, and the subsequent business disruption these will cause."
The four asks
Leaders are urged to:
- "understand and assess risk, readiness and accountability"
- "prioritize foundational cyber security practices and controls"
- "empower cyber leaders with authority and resources"
- "stay actively engaged as threats and guidance evolve"
The second is notable for what it does not recommend: against an AI-specific threat, the agencies direct attention to foundational controls rather than to AI-specific countermeasures — consistent with a threat model in which AI accelerates exploitation of existing weaknesses rather than creating new classes of them.
The statement's posture toward breach is assumed rather than avoidable: "Breaches will occur but preparedness helps you contain them quickly and prevent escalation into major operational and financial crises."
Agency practice
The NCSC describes its own programme as including direct access to the models in question: "The NCSC is accessing frontier AI models and is working with providers to understand and inform our response to cyber security risks and provide advice and guidance to New Zealand organisations."
Its wider work programme covers "collaborating with industry, including vendors who have been testing these models"; ongoing publication of guidance to business and government; and working with agencies implementing the government's digital roadmap "to ensure cyber security and resilience is a foundational component of digital investment and procurement from concept to implementation." Two guidance documents are named: "Frontier AI: Managing the increasing risks from vulnerabilities" and "Cyber readiness in the Frontier AI era."
Relationships
- related: Five Eyes Joint Guidance on Secure Deployment of AI Agents (May 2026) — the companion May 2026 Five Eyes product, addressing safe deployment rather than defensive readiness
- supports: AI and Cybersecurity — a five-nation agency assessment that the discovery-to-exploitation window is closing
- related: National Cyber Security Centre (NCSC), New Zealand — the signing agency whose announcement carries the joint text
- related: Autonomous cyber-agents, Claude Mythos 5, Our evaluation of OpenAI's GPT-5.5 cyber capabilities (UK AISI, April 2026)