Spy agencies do not usually agree on the wording of a press release, let alone on a deadline. So when the cyber chiefs of all five members of the Five Eyes intelligence alliance put their names to a single document and used the phrase "the timeline is not years, it is months," the choice of words was itself the news. On June 22, 2026, the National Security Agency published "The AI shift in cyber risk: why leaders must act now," a joint statement co-signed by the heads of Australia's Australian Signals Directorate, Canada's Communications Security Establishment, New Zealand's Government Communications Security Bureau, the United Kingdom's National Cyber Security Centre, and, in the United States, the NSA and the Cybersecurity and Infrastructure Security Agency.
The central claim is short and unambiguous. "Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities," the agencies wrote. "The timeline is not years, it is months." For an alliance whose members are more accustomed to classifying their conclusions than broadcasting them, publishing a shared assessment about a specific, near-term capability threshold is a departure worth taking seriously.
What the statement actually says
Read past the headline and the document is less a prediction than a call to action aimed squarely at boardrooms. "AI is not a future consideration," it reads. "It is already here." The agencies argue that frontier models are compressing the window between when a vulnerability is discovered and when it is exploited, lowering the barrier for less-skilled attackers while raising the ceiling for sophisticated ones. Crucially, they frame this as symmetric: the same models that will accelerate attacks can accelerate defense, and organizations that fail to adopt AI defensively will, in the statement's words, "face growing operational and strategic disadvantage."
The document lands on three practical thrusts. First, use AI deliberately on defense — to detect vulnerabilities earlier, monitor for anomalous behavior, and shorten response times — rather than merely for efficiency. Second, get the unglamorous basics right, and fast: reduce attack surface, accelerate patching, retire legacy systems, tighten identity and access controls, and rehearse incident response before an incident forces the issue. Third, and most pointed, stop treating cybersecurity as a technical footnote. "Cyber risk can no longer be treated as a purely technical issue," the agencies wrote. "This is a core business risk and leadership responsibility. Boards and executives should ensure cyber resilience is in place and works under pressure."
Which models, and how credible the timeline is
The agencies did not name products, but reporters quickly filled in the blanks. CyberScoop, which broke the statement, tied the warning to a new generation of frontier models from Anthropic and OpenAI whose hacking-relevant capabilities are expected to become broadly available "within the year" despite vendors' efforts to restrict them. That framing is grounded in recent events: the Trump administration ordered Anthropic to suspend access to its most capable Mythos- and Fable-class models over national security concerns, and Anthropic complied while calling the decision a "misunderstanding."
The intelligence agencies, notably, did not lean on secret sourcing to justify the alarm. As CyberScoop observed, the statement "does not specifically cite secret or classified sources or methods to reach this conclusion," and much of its reasoning tracks what independent security researchers have argued for a year. That cuts both ways. It makes the assessment harder to dismiss as spy-shop hype — but it also means the "months" claim rests as much on the observable trajectory of commercial model development as on any classified crown jewel. Independent experts have already noted that capabilities attributed to restricted frontier models can often be reproduced with older or open-source models, and that open-source releases historically trail the frontier by only six to eight months.
Politicians heard the message they wanted to hear. Representative Andrew Garbarino, the New York Republican who chairs the House Homeland Security Committee, said the warning "underscores what the Committee has repeatedly heard" and argued that "China is just months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States."
Why a formal Five Eyes assessment changes the posture
A joint Five Eyes statement is not a regulation, but it functions as one in practice. For government agencies, it becomes the citable justification for tightening rules — and that shift is already visible. CISA has cut the mandatory federal patch deadline for the most dangerous known-exploited vulnerabilities to three days, an aggressive compression of remediation windows that would have been hard to defend a year ago and is now framed as a direct response to AI-accelerated exploitation. For enterprises, the document hands chief information security officers a rare thing: top-cover. When five intelligence agencies jointly declare that cyber resilience "is not an IT issue" but a board-level accountability, a CISO asking for budget, authority, and a shorter patch cycle is no longer making a technical request. They are quoting the NSA.
The deeper significance is timing. Intelligence services are structurally conservative about publishing capability forecasts, because a wrong public call is expensive. Choosing "months" over the safer "years" — and choosing to say it out loud, together — signals that the alliance judged the cost of under-warning to be higher than the cost of being early. That is a meaningful tell about how the people with the best visibility into both offensive tooling and adversary intent are reading the curve.
What to watch
Three signals will show whether the warning was prophecy or overreach. First, remediation reality: can federal agencies actually meet a three-day patch mandate, and will private-sector regulators — financial, energy, healthcare — follow CISA's lead with their own compressed timelines? Second, model access: whether the Anthropic and OpenAI restrictions hold, and whether the capabilities they were meant to contain show up anyway through open-source or foreign models, which would validate the experts who called the containment strategy leaky. Third, board behavior: whether "cybersecurity is a leadership responsibility" translates into real accountability — named executives, tested response plans, resourced security leaders — or becomes another line in an annual report. The alliance has, for once, put a clock on its own forecast. The next few quarters will tell us whether it was right to start it.
"Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months."— Five Eyes cyber security agencies, Joint statement, June 22, 2026