The heads of the Five Eyes cyber agencies issued a joint statement that AI is rapidly transforming cyber risk and that organizations must act within months, not years. They ask leaders to reduce attack surface, accelerate patching as exploitation windows shorten, replace unsupported legacy systems, strengthen identity controls, and prepare for incidents.
CISA
US cybersecurity agency.
Executive Order 14409 directs Treasury, NSA and CISA to develop a classified benchmarking process to assess advanced cyber capabilities of AI models and designate covered frontier models, with a voluntary framework for pre-release government and trusted-partner access. It also orders an AI cybersecurity clearinghouse to coordinate vulnerability scanning, validation and remediation with industry, and states it does not create mandatory licensing or pre-clearance.
CISA and the Australian Signals Directorate, with US and international partners, published guidance on the cybersecurity risks of agentic AI services and recommended mitigations. CISA highlights expanded attack surface, privilege creep, behavioral misalignment and obscure event records as risks, and recommends avoiding broad access, starting with low-risk use cases, and folding agent security into existing risk models.
Anthropic reports that Pacific Northwest National Laboratory built a scaffold around Claude Sonnet 4 to automate adversary emulation against a high-fidelity cyber-physical model of a water treatment plant used for CISA. PNNL estimates attack reconstruction took three hours instead of multiple weeks; in one run the model switched to a different known privilege-escalation technique when a provided tool failed.
CISA and the Australian Signals Directorate, with NSA, FBI and national cyber agencies of Canada, Germany, the Netherlands, New Zealand and the UK, published four principles for integrating AI into operational technology. The guidance explicitly covers machine learning, LLM-based AI and AI agents because of the security and safety challenges they pose in industrial environments.
The White House AI Action Plan recommends establishing an AI Information Sharing and Analysis Center led by DHS with CAISI and the National Cyber Director, DHS guidance on AI-specific vulnerabilities, and updates to CISA incident response playbooks for AI systems. It also directs CAISI to evaluate frontier models for national security risks including cyberattacks, and to assess adversary AI systems for backdoors. As of February 2026, a CISA official described the AI-ISAC as still a pre-decisional memo.
The NSA AI Security Center, CISA, the FBI and international partners released a cybersecurity information sheet on securing data used to train and operate AI systems across the lifecycle. It recommends robust data protection, proactive risk management and stronger monitoring and threat detection, and is aimed at defense industrial base, national security system, federal and critical infrastructure operators.
The NSA's Artificial Intelligence Security Center led joint guidance with CISA, the FBI and the national cyber centres of Australia, Canada, New Zealand and the UK on deploying and operating externally developed AI systems. It sets objectives to improve the confidentiality, integrity and availability of AI systems and to mitigate known vulnerabilities, organized around protecting, detecting malicious activity against, and responding to incidents involving AI systems.
The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach.