Skip to content
The ColumnEssay· No. 1680

ESSAY: Offensive AI in Months — The Five Eyes Alarm That Changes Everything

On June 22, 2026, something unusual occurred in the Western intelligence world. The cybersecurity agencies of the Five Eyes — the CISA (United States), the NSA (United States), the NCSC (United Kingdom), the CCCS (Canada), the ACSC (Australia), and the NCSC-NZ (New Zealand) — published a joint advisory that breaks with the usual restraint of such documents. Their central conclu

Premium reading
MadMax
Key takeaways
  1. On June 22, 2026, something unusual occurred in the Western intelligence world. The cybersecurity agencies of the Five Eyes — the CISA (United States), the NSA (United States), the NCSC (United Kingdom), the CCCS (Canada), the ACSC (Australia), and the NCSC-NZ (New Zealand) — published a joint advisory that breaks with the usual restraint of such documents. Their central conclu
  2. ESSAY: Offensive AI in Months — The Five Eyes Alarm That Changes Everything
  3. Introduction: When the world's most powerful intelligence alliance says time is running out
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

ESSAY: Offensive AI in Months — The Five Eyes Alarm That Changes Everything

Introduction: When the world's most powerful intelligence alliance says time is running out

June 22, 2026 — a joint warning that breaks from the usual register

On June 22, 2026, something unusual occurred in the Western intelligence world. The cybersecurity agencies of the Five Eyes — the CISA (United States), the NSA (United States), the NCSC (United Kingdom), the CCCS (Canada), the ACSC (Australia), and the NCSC-NZ (New Zealand) — published a joint advisory that breaks with the usual restraint of such documents. Their central conclusion: frontier AI models will reshape offensive cyber capabilities "in months, not years." This is not a cautious warning for a distant future. It is an alert for right now.

The advisory explicitly names four actors: China, Russia, Iran, and North Korea — the same four nations that analysts call the Axis of Disorder. According to the Five Eyes, these four regimes are the primary potential beneficiaries of this revolution in offensive cyber capabilities. And the window for Western democracies to adapt their defenses before these capabilities are fully operational with the adversary is measured in months, not decades.

Why this advisory is different from previous ones — urgency as signal

The intelligence agencies regularly publish advisories on cyber threats. What distinguishes the June 22 advisory is its explicit language of urgency. The phrase "in months, not years" is not a diplomatic or nuanced formulation. It is a statement that says: we have detected something materializing now. This shift in register — from abstract warning to concrete alert — deserves attention and analysis of what motivates it.

The answer, in part, comes from Google itself: the company revealed that AI had been used to discover a zero-day vulnerability and weaponize it into an operational cyber weapon. This is no longer theoretical. It is no longer experimental. AI is already being used in the vulnerability exploitation cycle, radically shortening the time between discovering a flaw and weaponizing it. The Five Eyes are not talking about the future. They are describing a present that is accelerating.

What AI changes in offensive cyberwar — a revolution in attack methods

Automated vulnerability discovery — the most fundamental change

The discovery of software vulnerabilities has long been a human process, slow and costly: teams of specialized researchers spend weeks or months analyzing code, testing configurations, and identifying exploitable flaws. This cost in time and human expertise was a genuine barrier for adversary actors. AI changes this equation fundamentally: models trained on millions of lines of code can identify vulnerability patterns in hours that human researchers would have taken weeks to find.

The Google example — using AI to discover a zero-day flaw and turn it into an operational weapon — is the proof of concept that the Five Eyes observed and that motivated their alert. If a Western company can do this in defensive-offensive mode, the intelligence services of China, Russia, Iran, and North Korea can do the same with the same tools. Access to large language models is not reserved for democracies. And Beijing has been actively developing its own models for years.

Personalized phishing attacks — when AI crafts undetectable lures

Another domain where AI's impact on offensive cyberwar is already measurable: the generation of phishing content. Traditional phishing attacks are often detectable by their linguistic imperfections, their lack of personalization, their spelling errors. Generative AI now allows the production of lures indistinguishable from legitimate emails, perfectly tailored to the target's profile, in any language, at a scale and speed impossible for human operators. The group GREYVIBE, documented by WithSecure, is already using ChatGPT and Gemini to generate its phishing campaigns against Ukraine.

This capacity for mass personalization is one of the most troubling developments the Five Eyes flag. It means that existing phishing detection tools — which rely heavily on syntactic and stylistic filters — are progressively becoming ineffective. The new challenge for defensive cybersecurity is to develop detection methods that work against AI-generated lures, which is a fundamentally harder technical problem than filtering poorly written emails.

China, Russia, Iran, North Korea — four actors, four levels of maturity

China leading the race — a national strategy for military AI

Among the four actors named by the Five Eyes, China is the one with the greatest resources and most coherent strategy for integrating AI into its offensive cyber capabilities. The Made in China 2025 plan and its successors explicitly include the development of AI capabilities for military and intelligence use. Major Chinese tech companies — Baidu, Alibaba, Tencent — are legally required to cooperate with national security services. And China invests billions of dollars in AI research each year.

The UNC6508 campaign, revealed by Google on June 15, illustrates the sophistication already achieved: a China-linked group maintained invisible presence in North American military-medical networks for more than a year, deploying malware whose characteristics suggest the use of behavioral adaptation techniques that resemble AI-based methods. This is not yet a certainty — technical attribution remains complex — but it is consistent with the profile of an actor progressively integrating AI into its operations.

Russia — reduced resources but tactical creativity

Russia is in a different position. The economic sanctions imposed since 2022 reduce its access to the technological components necessary for AI development in compute terms. Its capacity to develop frontier models is inferior to that of China or the United States. But Russia has shown, with groups like GREYVIBE or Void Blizzard, a capacity to use existing tools — including Western models like ChatGPT and Gemini — creatively and effectively to amplify its operations.

This approach — using adversaries' tools against their own interests — is characteristic of Russian hybrid warfare doctrine. It does not require developing a proprietary frontier AI model. It requires creative operators capable of using available tools to maximize operational impact with limited resources. And in this domain, Russia has demonstrated a capacity for rapid tactical adaptation that neither sanctions nor technology access restrictions have managed to eliminate.

The adaptation window — what "months" concretely means

Defensive capabilities are not built in weeks

The phrase "in months" in the Five Eyes advisory may be the most alarming signal in the document. Because building defensive capabilities adapted to an AI-based cyber threat — detectors for AI-generated code, next-generation behavioral analytics systems, protection of language models against hijacking — requires years of research, development, and deployment. If adversaries will have AI-based offensive capabilities in months, and if our defenses require years to adapt, the defensive gap is real and immediate.

This is not pessimism. It is a structural reality that Western governments and cybersecurity companies must address urgently. Companies like CrowdStrike, Palo Alto Networks, and the cybersecurity divisions of Microsoft, Google, and Amazon are working on AI-based detection solutions. But the delay between laboratory development and operational deployment across thousands of organizations is measured in quarters, not days. And it is this delay that the Five Eyes are seeking to compress through their alert.

What organizations must do now — without waiting for governments to act

Faced with the urgency flagged by the Five Eyes, organizations with security responsibilities cannot wait for government directives. Measures that can be taken immediately: audit and update all existing detection solutions, strengthen multi-factor authentication protocols, segment networks to limit an attacker's lateral movement, and intensively train personnel on new AI-generated phishing methods. None of these measures are new. But their urgency is multiplied tenfold by the Five Eyes alert.

For organizations managing sensitive data linked to defense, military research, or critical infrastructure, the June 22 advisory should trigger an immediate review of their security posture. Not in six months. Now. Because "months" is the timeline the Five Eyes give for adversary capabilities to be fully operational. And some of those capabilities — like GREYVIBE using generative AI against Ukraine — already are. The window is not yet closed. But it is closing.

Ukraine as a laboratory — the first applications of AI in real cyberwar

GREYVIBE and others — what the war in Ukraine teaches us about weaponized AI

Since 2022, the war in Ukraine has been the global laboratory of cyberwar and new military technologies. Ukrainian drones integrating AI to counter Russian GPS jamming, automated reconnaissance systems, real-time analysis tools for enemy positions — Ukraine innovates at a speed forced by necessity. But the conflict also reveals AI use on the Russian side: the group GREYVIBE, documented by WithSecure, uses tools like ChatGPT, Gemini, and Ideogram to generate malicious content, obfuscation code, and visual lures in its attacks against Ukraine.

This use of generative AI in active cyberespionage operations represents a qualitative step in the evolution of the threat. GREYVIBE is not merely a group of hackers using AI tools: it is an operational model that demonstrates how AI can be integrated into every phase of a cyber operation — from the generation of the initial lure to the creation of malicious code, through to malware obfuscation to evade detection. This operational model is one that the Five Eyes expect to see replicated and amplified by other actors in the coming months.

Ukrainian AI-equipped drones — the offensive technology that forces defense to adapt

If Ukraine is an AI experimentation laboratory in cyberwar, it is also one for the integration of AI into conventional weapons systems. Ukrainian drones equipped with AI for autonomous navigation when GPS is jammed represent exactly the type of disruptive military technological innovation that the Five Eyes advisories highlight. AI is not only changing cyberwar — it is changing the very nature of kinetic warfare, making precision strikes possible at distances and in conditions that conventional systems could not achieve.

The convergence of AI in both cyberwar AND conventional warfare is what makes the Five Eyes alert particularly serious. This is not a threat in a single domain. It is a systemic transformation of the nature of conflict, simultaneously affecting physical battlefields, computer networks, influence operations, and intelligence capabilities. And this transformation is unfolding right now, in real time, in the servers and on the battlefields of Ukraine.

The governance of military AI — a dangerous regulatory void

Democracies facing the dilemma — regulate without disarming

The Five Eyes alert highlights a fundamental dilemma for Western democracies: how to regulate the military use of AI without creating competitive disadvantages against adversaries who have no intention of submitting to these regulations? Democracies have traditions of ethical governance of military technologies — treaties, conventions, international norms. These traditions are strengths, not weaknesses. But they create constraints that China, Russia, Iran, and North Korea do not impose on themselves.

The response to this dilemma cannot be to abandon all ethical governance of military AI. That would mean abandoning what distinguishes us from our adversaries. But it cannot be to impose unilateral constraints that leave our adversaries advancing freely in a space where we have tied our own hands. The solution lies in intelligent, coordinated governance: norms that apply among democracies, combined with pressure mechanisms on non-cooperative actors, and a robust defensive capability that does not depend on adversaries' goodwill.

The UN, NATO, and international institutions — can they keep pace with AI?

International institutions have historically operated at a pace incompatible with the speed of technological evolution. The UN has been debating a regulatory framework for Lethal Autonomous Weapons Systems (LAWS) for years without reaching consensus. NATO adopted "responsible AI principles" in 2021 — an important text but without binding mechanisms. These institutions are not capable, in their current form, of producing binding norms on military AI at the speed of months suggested by the Five Eyes.

This does not mean they are useless. Multilateral processes have a signaling and legitimation value that unilateral actions lack. But in the immediate term, the response to the urgency flagged by the Five Eyes will come through ad hoc coalitions of like-minded democracies — as is the case for support to Ukraine. Specific, agile alliances capable of acting quickly on defensive and offensive AI governance, without waiting for a global consensus that will not come.

What this means for democracies — a call for collective action

Investing in AI-based cyber defense — a priority that can no longer be deferred

The Five Eyes advisory is, ultimately, a call to invest. Invest in research on detecting AI-generated attacks. Invest in training cybersecurity personnel in new adversarial methods. Invest in public-private partnerships that allow tech companies to share their findings on new threats. And invest in the resilience of critical infrastructure — energy, transport, communications networks — against attacks that could exploit vulnerabilities discovered and weaponized by AI in hours.

These investments have a cost. But they also carry a cost-benefit ratio that hesitant governments should calculate seriously: the cost of a successful attack on critical infrastructure — a power plant, a water distribution network, a healthcare system — is incomparable to the cost of protecting it. The Five Eyes alert is not an abstract hypothesis. It is grounded in real incidents, identified groups, and documented capabilities. The risk is real. The response must be equally so.

Democratic solidarity as a strategic response

The joint advisory of the six agencies of the Five Eyes is itself a demonstration of what democratic solidarity can produce: a shared analysis, a common language, a coordinated signal. This coordination must expand and deepen. The threat respects no national borders — Ukraine, Belgium, Canada, and the United States are all targeted by the same actors with the same tools. The response must match this reality: not national first, but collective and coordinated from the outset.

Supporting Ukraine in its war against Russia also means supporting the democracy on the front lines of this transformation of cyberwar. The lessons learned on Ukrainian battlefields — about drones, offensive AI, coordinated cyberattacks — are strategic intelligence that benefits the entire alliance. Sharing these lessons, funding Ukrainian technological innovation, and integrating Ukraine into cyber intelligence-sharing circles are strategic investments in the collective security of all democracies.

AI as a force multiplier — what adversaries understood before us

AI lowers the cost of entry into cyberwar — and broadens the circle of adversaries

One of the deepest implications of the AI revolution in cyberwar is what experts call the democratization of advanced cyber threat. Previously, launching a sophisticated cyber operation against high-value targets required considerable resources: teams of highly specialized engineers, years of tool development, a state-level budget. AI fundamentally changes this equation: a small team can now accomplish what required an army. And a second-tier state actor can now deploy capabilities that were previously reserved for superpowers.

Iran and North Korea, explicitly named in the Five Eyes advisory, are the most direct beneficiaries of this democratization. Both countries have active offensive cyber capabilities but are limited by their technological and human resources. AI could rapidly close these gaps, allowing them to automate vulnerability discovery, generate sophisticated lures, and deploy complex malware without requiring the teams of hundreds of specialists that China and Russia maintain. This is a qualitatively new threat that current defenses were not designed to counter.

The AI paradox — a technology developed by democracies used against them

There is a profound paradox at the heart of this situation: the frontier AI technologies fueling this cyberwar revolution were developed, largely, in Western democracies. OpenAI, Google DeepMind, Anthropic are American companies. The technologies they produce — accessible through APIs and open platforms — are available to anyone with a computer and an internet connection. Including the operators of GREYVIBE, Void Blizzard's hackers, and the Chinese military intelligence services.

This paradox has no simple solution. Closing access to these technologies for adversary actors is technically difficult and economically costly for the companies developing them. Doing nothing is strategically unacceptable. The middle path — technical guardrails, usage audits, targeted geographic restrictions — is the only pragmatic response. But it requires a coordination between governments and tech companies that no one has yet managed to achieve at the speed the threat demands.

Conclusion: The time for warning has passed — the time for action has begun

"Months" — and now what

The Five Eyes advisory of June 22, 2026 marks a turning point. Not because the threat of AI in cyberwar was unknown — security experts had been discussing it for years. But because the formulation "in months, not years" transforms an abstract threat into an operational urgency. It says: this is no longer the time for long-term planning. It is the time for immediate action. And for governments, organizations, and citizens who had not yet integrated this reality into their priorities, this signal cannot be ignored.

The question now is simple: will Western democracies respond at the speed of the threat? Will they invest, coordinate, and act in the weeks and months ahead with the urgency that the situation demands? Or will this advisory, like so many before it, be read, noted, and set aside while waiting for the next incident to create the urgency that words were not enough to create? I am a skeptical optimist. I hope for the first option. I fear it will be the second.

What Ukraine proves to us, once again

There is one democracy that does not have the luxury of waiting. Ukraine has lived under Russian cyber assault since 2014. It has learned to adapt its defenses in real time, to transform every attack into a lesson, to innovate under conditions that no Western country has had to face in this way. Groups like GREYVIBE target Ukraine because it is on the front line. And Ukraine resists, innovates, and shares its lessons with its allies.

If Western democracies take the Five Eyes alert seriously — if they invest, coordinate, and act with the speed the threat demands — they can build the defenses necessary to face offensive AI within the timeframe. It is not easy. It is not free. But it is necessary. As Zelensky has said, again and again, in the face of a threat that does not pause: the only option is to resist. And resistance starts with being ready.

By Maxime Marquette, columnist

Columnist's transparency note

Editorial positioning

This essay is based on the joint advisory published on June 22, 2026 by the Five Eyes cybersecurity agencies. My position is that of an observer concerned about the implications of offensive AI for Western democracies. Passages on GREYVIBE are based on the WithSecure report as relayed by secondary sources — I did not have access to the original technical report. Elements on UNC6508 and the Chinese campaign complete the context without being directly part of the Five Eyes advisory.

Sources and limitations

The Five Eyes joint advisory of June 22 was not published in full in accessible media. My analysis is based on summaries and direct quotes reported by the sources cited below. References to specific incidents such as Google's AI-discovered zero-day are drawn from secondary sources, which may contain imprecisions relative to the original document. I encourage readers to consult the official communiqués from Five Eyes agencies for the full text.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). ESSAY: Offensive AI in Months — The Five Eyes Alarm That Changes Everything. MadMax. https://mad-max.co/en/article/essai-l-ia-offensive-en-quelques-mois-le-cri-d-alarme-des-five-eyes-qui-change-t

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Essay2 reads3347 words5 min read