Whakataunga 1 Judgement 1

Artificial Intelligence is rapidly reshaping the cyber landscape. Frontier AI will supercharge the risks and opportunities

He tere hoki te huri a te Atamai Hangahanga (AI) i te ao ipurangi: He kaha te whakaara a Frontier AI i ngā mōrea me ngā arawātea

Artificial Intelligence (AI) continues to rapidly reshape the cyber landscape. AI capabilities are already in the hands of malicious actors and are being used to enhance the speed and scale of cyber attacks, create deep-fakes, execute targeted phishing attacks, and undertake reconnaissance at scale. 

Why does this matter?

For some time, AI models have enabled cybercrime, espionage and other malicious online activity. Now, the deployment of frontier AI systems will lead to a step-change in capabilities, both positive and negative. While frontier AI models can and in some circumstances already are being used to improve cyber defences, it is certain they will be used by cybercriminals and state actors for malicious purposes.

The key capability shifts to be aware of include: 

Zero-day vulnerabilities. Frontier AI can better analyse code to identify vulnerabilities, and AI agents are becoming capable of chaining together vulnerabilities into more complex exploits. On the other hand, the same tools can be used by defenders to strengthen code, identify exploitable weaknesses in system configuration, or respond to security events at speed.

Reconnaissance. Frontier AI can automate and dramatically accelerate reconnaissance by malicious actors of your business, its people and systems. This capability can be used to develop personalised attacks on individuals and identify weaknesses in your systems.

Brute forcing. Brute force attacks use compute power and automation to guess username and password credentials in order to access a system or tool. AI makes brute forcing smarter and faster. It also enables the fusion of information gained from multiple sources (e.g. social media and stolen credentials) to generate highly targeted attacks.

Personalised phishing and deep fakes. AI is enabling the easier creation of customised messages from what appear to be trusted sources. These messages are moving beyond text-based messages to convincing and personalised audio and video content. This capability is enhanced by AI translation tools that allow cybercriminals to target individuals across many communities and cultures with messages in their own languages that appear authentic.

Workflow and chatbot vulnerabilities 

Businesses introducing AI into their workflow also expose themselves to risk. Unauthorised use of chatbots trained on commercially sensitive or personal information can enable access to bulk data of a sensitive nature. Similarly, chatbots exposed to the public, for instance to lower customer support barriers, may be ‘jailbroken’ through maliciously crafted prompts to reveal underlying data or logic, unintended for public consumption. This threat is now so pervasive that a leading cyber defence organisation, the MITRE Foundation, has updated its response framework to document and enable defence against malicious activity targeting AI agents.

The time to act is now. Cyber defence fundamentals are essential

Highly capable AI models are already widely available and already being used by malicious actors. Our message is that you should act now to apply basic cyber security principles to your systems and support your people to apply good cyber behaviours. 

The best defence against cyber attacks, by humans or AI, continues to be effective cyber security controls. 

What has changed is the urgency and resourcing to deliver and maintain these controls. We recommend that organisations review their current cyber security controls to ensure they are fit-for-purpose and sufficiently resourced. The National Cyber Security Centre (NCSC) has published guidance for cyber 
defenders and business leaders to help them understand the risk of AI-enabled attacks. 

  • Reduce your attack surface: Limit unnecessary system access and external connectivity. Challenge whether systems need to be exposed at all and isolate those that do not.
  • Accelerate patching processes: AI is shortening the time between vulnerability discovery and exploitation. Delays in patching increase risk, especially for operational systems with long update cycles. Prioritise security updates to manage risks.
  • Address legacy systems: Unsupported systems are easy targets. They don’t just represent technical debt; they are strategic liabilities. Ensure assets nearing the end of their supportable life are replaced.
  • Review and strengthen identity and access controls: Limit who can access critical systems. Enforce strong authentication and regularly review permissions.
  • Prepare for incidents before they happen: Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery.

Long term benefits of AI

In the longer-term AI has potential to assist network defenders by strengthening their ability to protect systems at scale and pace.

AI will be most effective when used to augment and strengthen existing tools and processes, not as a standalone solution or a replacement for cyber security fundamentals. Human oversight, governance and policy remain essential particularly where decisions relate to high-value information or high consequence environments.Much of the focus on frontier AI has been around its capability to test code for vulnerabilities prior to deployment. While this is an important use-case, the benefits of deploying AI in a deliberate and well-governed way extend across the cyber-defence spectrum. For example:

  • Defenders can use AI to baseline resource utilisation, assets and user behaviour to detect anomalous activity in traffic or host systems. 
  • Enhanced monitoring of data by AI can enable early identification of attacks, enable triage of impact and support faster response and recovery. 
  • Using AI to reduce repetitive manual processes or improve risk prioritisation can enhance the capability of cyber defence teams in an increasingly complex and fast-moving threat environment. 

Most organisations that use AI for business purposes or to enhance cyber security will purchase these tools or services from a third-party supplier. When procuring these tools or services organisations should ensure that suppliers are building in security from the outset, not as an added afterthought. Organisations should also test AI tools to ensure they operate as intended in their environment. Supply chain risks from the adoption of AI need to be actively managed, as do the business risks should AI tools be compromised or 
services interrupted.

Five Eyes call to action on AI

In June 2026 the leaders of the Five Eyes cyber security agencies issued a joint Call To Action about the accelerating cyber security risk caused by frontier AI. 

The Five Eyes is a grouping of the national security agencies of Australia, Canada, New Zealand, the United Kingdom and the United States. The agencies rarely issue joint statements but did so on this occasion because of the significant risks to businesses and organisations from the rapidly changing capability of frontier AI models.

The Call To Action stated that cyber resilience is integral to advancing business continuity, market confidence and long-term value. It urged leaders to: 

  • Understand and assess risk, readiness and accountability  
  • Prioritise foundational cyber security practices and controls  
  • Empower cyber leaders with authority and resources  
  • Stay actively engaged as threats and guidance evolve.
What should leaders do?

Don't wait for more information, or the newest AI tools. Start preparing now.

Cyber threats are a business issue for Chief Executives and governance bodies. The impact of a cyber incident can undermine the confidence of investors, regulators and customers, disrupt operations and have severe 
financial impacts to a business. In the infrastructure sector the potential risks can extend to community, regional or even national disruption. 

Leaders need to be having conversations now, not only with IT and cyber security teams, but across their organisations, to ensure the risks of AI are identified and appropriately treated. The imminent arrival of frontier AI tools makes this focus more urgent.

Questions leaders should be asking:

  1. Do we have the people and resources to support an increased tempo of system patching and updates caused by frontier AI? 
  2. Are we using AI chatbots or other AI tools? How do we manage and protect sensitive data used in these tools? 
  3. Are we confident our suppliers are building and supplying systems that are secure by design?
  4. Do our business continuity plans and crisis response plans factor in cyber attacks and business disruption? Have we exercised these responses? 
  5. Are our leaders, both in governance and operations, regularly discussing and planning for disruption?
AdobeStock 2148129062

Example

In November 2025 Anthropic announced it had disrupted a threat actor, who it assessed was a People’s Republic of China (PRC) state-sponsored group, from using AI’s agentic capabilities to infiltrate around thirty global organisations. 

Top