
Five Eyes and CISA warn autonomous AI cyberattacks are months, not years, away
CISA and the Five Eyes alliance issued a joint advisory putting the window for publicly available, autonomous AI-enabled cyberattacks at months, not years — citing red-team exercises where frontier models independently found and exploited novel vulnerabilities in enterprise infrastructure. The compression is structural: open-source models trail frontier by 6–8 months, so today's restricted capability becomes broadly available attack tooling on a foreseeable schedule, while the defenses remain the same patching and access-control basics most organizations have deferred for years.
Source: cyberscoop.com ↗
The timeline is not years, it is months.
Five Eyes alliance joint statement
Why this matters
- → Autonomous AI cyberattacks move from theoretical to operational threat within months.
- → Open-source lag means restricted capabilities become public attack tools on predictable schedule.
- → Most organizations remain vulnerable using decades-old defensive basics.
AI's attack window closes