From the journal

Five Eyes Agencies Issue Joint AI Cyber Threat Statement, June 22, 2026

CISA (US), NCSC (UK), ACSC (Australia), CCCS (Canada), and NCSC-NZ jointly published a cyber security statement on June 22, 2026. The agencies assess that AI will accelerate the speed, scale, and sophistication of cyber threats, with frontier models expected to exceed current defensive assumptions within months. The statement directs organizations to treat cyber risk as a board-level concern and strengthen foundational controls without delay.

2 min read

On June 22, 2026, the cybersecurity agencies of the United States (CISA), the United Kingdom (NCSC), Australia (ASD's ACSC), Canada (CCCS), and New Zealand (NCSC-NZ) published a joint statement titled Five Eyes Cyber Security Agencies Statement. The statement is advisory in character, representing a formal coordinated government assessment that constitutes regulatory guidance to critical infrastructure operators and senior organizational leadership.

The statement assesses that the timeline for AI-driven cyber threat escalation is measured in months, not years. Frontier AI models are anticipated to exceed current industry-standard defensive assumptions and to alter both offensive and defensive cyber capabilities. The agencies direct organizations to take three actions: assess AI-driven cyber risk at board and executive level; prioritize foundational controls including patching, identity management, and incident response; and empower chief information security officers with authority and resources commensurate with the threat environment.

Critical infrastructure operators, financial institutions, telecommunications providers, and AI deployers are the primary addressees of the statement. Organizations in those sectors should treat this Five Eyes guidance as a signal of forthcoming regulatory expectations. Joint advisories from CISA, the NCSC, and peer agencies have in prior supervisory cycles preceded enforceable obligations, and the explicit urgency language in this statement amplifies that risk.

The statement does not impose specific mandatory controls or direct legal obligations. Its regulatory significance is forward-looking: all five jurisdictions' regulators are expected to scrutinize AI cyber risk governance and cyber resilience investment in forthcoming supervisory cycles. The NCSC published a companion piece, The AI shift in cyber risk: why leaders must act now, concurrently, elaborating on the technical threat assessment underlying the joint statement.

We may advise on cyber regulatory positioning across the Five Eyes jurisdictions and have a partner network with specialist counsel. Organizations reviewing their AI cyber risk posture are invited to contact us. Work we undertake includes cyber regulatory advisory, AI security governance, critical infrastructure compliance, and board-level cyber risk briefings.

Source: Five Eyes Cyber Security Agencies Statement, CISA, June 22, 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.