Skip to main content
    Cyber SecurityAI & InnovationLeadership

    AI cyber threats are months away, not years – what the Five Eyes warning means for your business

    The Five Eyes intelligence agencies have warned that advanced AI models are months away from fundamentally transforming cyber attacks. Here's what UK SMEs need to know.

    June 2026
    6 min read
    By the HowTech team

    On Monday, the intelligence agencies of Australia, Canada, New Zealand, the UK and the United States issued a joint warning that stopped just short of declaring a crisis. The message was unusually direct for organisations not known for plain speaking: the timeline for AI-enabled cyber attacks causing catastrophic damage to businesses and governments is not years. It is months.

    This isn't speculation from a think tank or a vendor trying to sell you something. This is the Five Eyes – the most significant intelligence-sharing alliance in the world – telling business leaders to act now.

    What they actually said

    The joint statement warned that frontier AI models are anticipated to 'fundamentally transform both offensive and defensive cyber capabilities.' The specific concern is critical systems running old or unsupported software – exactly the kind of infrastructure that many SMEs and public sector organisations are still relying on.

    The agencies were equally clear about where responsibility sits:

    "Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility."

    That's worth sitting with for a moment. Five intelligence agencies, speaking together, telling chief executives and board members directly that this lands on their desk.

    Why AI changes the threat landscape so dramatically

    Until now, the most sophisticated cyber attacks required significant skill and resources. Nation states and well-funded criminal groups could pull them off. Most others couldn't.

    AI changes that equation entirely. It lowers the barrier to entry for attackers – giving capabilities that were previously limited to highly skilled actors to almost anyone with access to the right tools. Attacks become faster, more targeted, more convincing and harder to detect.

    "We've been telling clients for some time that the threat landscape was accelerating. This statement confirms it at the highest level. The businesses that will come through this are the ones that treat security as infrastructure, not as an afterthought. The ones that don't will find out the hard way." – John Howell, CEO, HowTech

    What this means for SMEs specifically

    Large enterprises have security operations centres, dedicated teams and significant budgets. SMEs typically don't. That doesn't mean the threat is smaller – in many cases it makes SMEs more attractive targets, precisely because their defences are thinner.

    The Five Eyes statement urged organisations to integrate AI tools into their own security operations to strengthen defences. That's the right instinct – but it requires knowing where your vulnerabilities are before you can address them.

    What to do about it

    The good news is that the fundamentals of good cyber security haven't changed, even if the threat has accelerated. These aren't glamorous, but they're what actually reduces your exposure.

    Assess your current posture

    A structured review of where you stand today – before you can fix exposures, you have to know where they are.

    Address unsupported software

    The Five Eyes singled out old and unsupported software as a primary AI-attack target. Patch, replace or isolate it.

    Build an incident response plan

    A plan you will actually use under pressure – not a document that lives in a folder no one opens.

    Achieve Cyber Essentials

    Recognised certification that proves the fundamentals are in place – and that increasingly opens doors with clients and insurers.

    The organisations that will be most vulnerable are the ones that keep treating this as something to get to eventually.

    At HowTech, we work with SMEs across regulated industries to build cyber security that holds up in the real world – not theoretical frameworks, but practical defences built around how your business actually operates.

    If the Five Eyes warning has prompted a conversation in your leadership team, our cyber health check is a good place to start.

    Cyber health check

    A full cyber assessment for your organisation – including gap analysis, technical review and certification submission support.

    Book your cyber health check

    Talk to us about your cyber risk

    If the Five Eyes warning has changed the conversation in your business, we can help you turn it into a plan. Practical, prioritised, and built around how you actually operate.

    Related insights

    A step-by-step guide to achieving Cyber Essentials certification and the local implementation tips that help.

    The strategic approach to cyber security that protects UK SMEs without slowing the business down.

    A practical guide to adopting AI – including the security considerations every SME should weigh up.