Skip to content

2026 05 07 five eyes ai risks and advice

github-actions[bot] edited this page May 7, 2026 · 1 revision

Five Eyes stance on Artificial Intelligence risk and policy advice

Research Question

What is the current stance of the Five Eyes intelligence alliance (Australia, Canada, New Zealand, United Kingdom, United States) on Artificial Intelligence (AI) risks, and what concrete policy and operational advice does the alliance provide to governments and regulated organisations?

Scope

In scope:

  • Joint Five Eyes AI-risk publications, advisories, and security guidance
  • Statements and guidance from Five Country Ministerial processes and member cyber agencies where positions are explicitly aligned
  • Common risk categories, for example model misuse, prompt injection, meaning malicious instructions hidden in model inputs that try to change system behaviour (definition source: https://owasp.org/www-community/attacks/PromptInjection), supply-chain risk, data protection, and critical infrastructure impact
  • Actionable recommendations for policy, governance, and security operations

Out of scope:

  • Broad national AI strategy comparison not tied to the Five Eyes alignment question
  • Vendor-specific AI tooling recommendations
  • Non-English or non-public sources

Constraints:

  • Prioritise primary government sources and joint advisories over commentary
  • Distinguish clearly between alliance-level consensus and member-specific guidance
  • Focus on guidance published from 2023 onward unless an earlier source is required for context

Context

[inference] Prior completed research on AI security strategy found that New Zealand had relevant AI security concerns but lacked a tightly bounded synthesis of what the Five Eyes alliance itself was jointly recommending, so this item narrows the question to alliance-level consensus and explicitly aligned member follow-through. [source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-02-28-ai-strategy-security-focus.md; https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]

[fact] The evidence base for this item is dominated by 2023 to 2025 primary government publications from Five Eyes ministers and cyber agencies, with New Zealand public-service guidance included only where it operationalises the same security, accountability, and assurance surfaces for government users. [source: https://www.ncsc.govt.nz/protect-your-organisation/guidelines-for-secure-ai-system-development/; https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]

[fact] This item also checks the newest allied guidance on agentic AI, meaning Artificial Intelligence systems that can take delegated actions through connected tools or services, because it materially qualifies the same access-control, logging, and oversight questions as the earlier Five Eyes deployment material. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

Approach

  1. Identify and catalogue authoritative Five Eyes and Five Country Ministerial sources that address AI risks directly.
  2. Extract explicit risk framing and recommendations from each source, then classify findings as alliance consensus versus country-specific advice.
  3. Map recommendations into a practical checklist for policy, governance, and security controls.
  4. Compare this item's findings with prior corpus coverage (2026-02-28-ai-strategy-security-focus) and identify new or changed guidance.

Sources


Research Skill Output

§0 Initialise

  • Question: What common Five Eyes position is visible in joint ministerial and cyber-agency publications on AI risk, and what practical policy, governance, and operational advice do those publications give to governments and regulated organisations?
  • Scope: Public Five Eyes or explicitly aligned member guidance on AI security, misuse, deployment, governance, and operational controls, with broad national strategy comparison and vendor selection excluded.
  • Constraints: Primary government sources from 2023 onward, alliance consensus separated from member-specific implementation guidance, prior completed work checked before investigation.
  • [inference] Prior work cross-reference: The prior security-focus item established that New Zealand needed more concrete AI security architecture than broad strategy documents supplied, and this item shows that Five Eyes joint guidance now supplies that missing baseline for secure use, development, and deployment. [source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-02-28-ai-strategy-security-focus.md; https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • Output: knowledge item with structured synthesis, Evidence Map, assumptions, and control-oriented interpretation.

§1 Question Decomposition

  • Root question: What is the Five Eyes stance on AI risk, and what concrete advice follows from that stance?
  • A. Alliance-level stance
    • A1. How do Five Country Ministerial statements frame AI opportunities and risks?
    • A2. What common security principles appear across Five Eyes cyber-agency publications?
  • B. Joint risk taxonomy
    • B1. Which AI-specific threats are named repeatedly across the joint publications?
    • B2. Which traditional cyber controls are carried over into AI guidance?
  • C. Operational advice
    • C1. What secure development advice is given to AI providers?
    • C2. What secure deployment advice is given to organisations adopting external AI systems?
    • C3. What ongoing operational and incident-response advice is given after deployment?
  • D. Member-specific implementation
    • D1. What additional New Zealand public-sector guidance operationalises the alliance position?
    • D2. What additional United States guidance operationalises information-sharing and emerging agentic AI risks?
  • E. Synthesis
    • E1. Which recommendations are genuine Five Eyes consensus?
    • E2. Which recommendations are member-specific extensions rather than alliance-wide commitments?
    • E3. What checklist follows for governments and regulated organisations?

§2 Investigation

A. Alliance-level ministerial and cyber-agency stance

  • [fact] The 2024 Five Country Ministerial Communique states that the Five Countries see AI as both an economic and cyber-defence opportunity and as a source of novel security vulnerabilities that can increase the speed and scale of malicious activity. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]
  • [fact] The same communique identifies misuse cases that the Five Countries are particularly concerned about: mis- and disinformation, malware generation, terrorist and violent extremist content, non-consensual deepfake pornography, and child sexual abuse material. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]
  • [fact] The ministerial position is collaborative rather than regulatory: the Five Countries commit to share information on national AI-risk frameworks, shape international AI standards and governance, and align work so deployment and use remain safe, secure, and trustworthy in national-security contexts. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]
  • [fact] The 2023 joint Guidelines for secure AI system development treat cyber security as a necessary precondition for AI safety, resilience, privacy, fairness, efficacy, and reliability, and organise guidance across secure design, secure development, secure deployment, and secure operation and maintenance. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development]
  • [fact] The 2023 guidelines also state that providers, not downstream users, should take primary responsibility for secure outcomes across complex AI supply chains, implement the most secure settings by default, and inform users where residual risk remains. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development]

B. Joint threat framing for organisations using AI

  • [fact] The 2024 Engaging with Artificial Intelligence guidance is explicitly aimed at organisations using AI systems securely, including both self-hosted and third-party hosted systems. [source: https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf]
  • [fact] That guidance names five recurring threat classes: data poisoning, input manipulation including prompt injection, meaning malicious instructions hidden in model inputs that try to change system behaviour, and adversarial examples, hallucinations, privacy and intellectual-property exposure, and model stealing or training-data extraction. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://owasp.org/www-community/attacks/PromptInjection]
  • [fact] The 2024 Deploying AI Systems Securely guidance is scoped to organisations deploying externally developed machine-learning AI systems on premises or in private-cloud environments, especially high-threat and high-value environments. [source: https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [inference] Across the 2023 to 2025 joint publications, the Five Eyes cyber-agency stance is that AI risk is not a separate policy silo; it is an extension of cyber risk that adds AI-specific attack modes while still requiring strong traditional governance, architecture, authentication, monitoring, and incident response. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

C. Concrete secure-development advice

  • [fact] The 2023 joint development guidelines say secure design should include understanding risks, threat modelling, and explicit trade-offs in model and system design before release. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development]
  • [fact] The same guidance says secure development must cover supply-chain security, documentation, asset management, and technical-debt management, rather than treating model development as exempt from normal secure engineering discipline. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development]
  • [fact] The guidelines prioritise secure-by-design principles, radical transparency and accountability, and leadership structures that make security a business priority rather than a late engineering check. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development]

D. Concrete secure-deployment and operational advice

  • [fact] The 2024 deployment guidance says the person accountable for AI-system cyber security should be the same person accountable for the organisation's cyber security overall, and organisations should document threats, impacts, roles, responsibilities, security boundaries, and risk acceptance before deployment. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • [fact] The same guidance tells adopters to require a threat model from the primary developer, catalogue trusted data sources, examine third-party training or fine-tuning data, and use contractual controls where external data sources are involved. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [fact] It also recommends well-designed architecture and hardened configurations, including boundary protections, architecture that assumes breach and requires explicit verification of access, hardened containers or virtual machines, network monitoring, allow-list firewalls, encryption at rest, and protection of model weights and keys in restricted storage or a hardware security module. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [fact] The same document recommends strong authentication, phishing-resistant multifactor authentication, role-based access control or attribute-based access control, privileged-access separation, and strict distinction between users and administrators. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [fact] For software and model integrity, the deployment guidance recommends digital signatures, checksums, version control for code and artefacts, adversarial testing, secure inspection of imported models before enterprise deployment, and supply-chain evaluation for external models and data. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [fact] For live operations, it recommends authenticating and authorising exposed Application Programming Interfaces (APIs), validating and sanitising all inputs to reduce prompt-injection risk, collecting logs on inputs, outputs, intermediate states, and errors, monitoring for configuration changes and model-extraction attempts, alerting on anomalies, performing audits and penetration tests, and keeping rollback paths available. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

E. Data-security and information-sharing extensions

  • [fact] The 2025 NCSC New Zealand AI data-security guidance says organisations should extend AI security controls to the data used to train, test, and operate AI systems, with special emphasis on protecting sensitive, proprietary, and mission-critical data. [source: https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/]
  • [fact] The 2025 CISA AI Cybersecurity Collaboration Playbook does not create regulatory obligations, but it gives AI providers, developers, and adopters a voluntary process for sharing AI-related incidents and vulnerabilities with government and partners to improve collective defence across critical infrastructure. [source: https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook; https://www.cisa.gov/news-events/alerts/2025/01/14/cisa-releases-jcdc-ai-cybersecurity-collaboration-playbook-and-fact-sheet]

F. Member-specific public-sector operationalisation in New Zealand

  • [fact] The 2025 Public Service AI Framework says New Zealand public-service agencies should treat security as a core business requirement, ensure traceability of data, use robust risk management, and maintain accountable human oversight throughout the AI lifecycle. [source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://www.beehive.govt.nz/release/guidance-safe-use-ai-public-sector]
  • [fact] The related governance guidance tells agencies to designate a responsible senior official for Generative Artificial Intelligence (GenAI) adoption, publish agency AI policies and standards, conduct risk assessments with more oversight for higher-risk uses, maintain transparency about AI use, and keep a register of agency AI use where appropriate. [source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]
  • [inference] These New Zealand public-service controls are member-specific implementation guidance, not alliance-level commitments, but they operationalise the same Five Eyes control surfaces of security by design, human accountability, transparency, and risk-based deployment. [source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]

G. Current direction of travel on agentic systems

  • [fact] On 7 May 2026, CISA, the Australian Signals Directorate's Australian Cyber Security Centre, and other partners published guidance on careful adoption of agentic AI services that highlights expanded attack surface, privilege creep, behavioural misalignment, and obscure event records. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]
  • [fact] That 2026 guidance recommends avoiding broad or unrestricted access to sensitive data or critical systems, starting with low-risk and non-sensitive use cases, and explicitly accounting for agentic AI security in the organisation's security model and risk posture. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]
  • [inference] Because the 2026 agentic guidance is not presented as a formal Five Eyes document, it is better treated as a member-led extension that shows where aligned allied practice is moving rather than as settled alliance-wide consensus. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]

§3 Reasoning

  • [inference] The most defensible reading of the evidence is that the Five Eyes stance has two layers: a ministerial layer that frames the strategic risk and a cyber-agency layer that translates that risk into secure-by-design, secure deployment, and secure operation guidance. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • [inference] The common operational pattern is not to invent a wholly separate AI governance regime for every organisation, but to apply existing cyber-security ownership, architecture, authentication, logging, and incident-response disciplines to AI deployments while adding AI-specific controls for prompt injection, poisoned data, model theft, and model-weight protection. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [inference] Governments and regulated organisations should therefore read the alliance advice as a checklist for integrating AI into existing governance systems, not as permission to delay action until dedicated AI regulation appears. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]

§4 Consistency Check

  • [inference] The ministerial and cyber-agency publications are internally consistent on the core point that AI brings real benefits but also increases risk from both malicious use of AI and attacks against AI systems themselves. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • [inference] No material contradiction appeared between the 2023 secure-development guidance, the 2024 secure-use and secure-deployment guidance, and the 2025 data-security and information-sharing guidance; each later document narrows or extends the same control surfaces rather than reversing them. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook]
  • [inference] The main boundary condition is scope, not contradiction: some documents are written for AI providers, some for deployers of external AI systems, some for general AI users, and some for public-service agencies. The practical synthesis must preserve those audience distinctions. [source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]

§5 Depth and Breadth Expansion

  • [inference] Technical lens: The alliance documents imply that prompt injection, poisoned data, model extraction, and model-weight theft are the control surfaces where standard cyber hygiene is insufficient unless AI-specific validation, provenance, and behavioural monitoring are added. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]
  • [inference] Regulatory lens: The Five Eyes position is more mature on security operations than on formal AI regulation. The ministerial communique commits to shaping international standards and governance, but the detailed instructions currently arrive through agency guidance and public-sector frameworks rather than binding alliance rules. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]
  • [inference] Operational lens: For regulated organisations, the strongest shared message is to treat AI deployments like high-value cyber systems that need named accountability, documented threat models, trusted data-source management, rigorous access control, monitoring, incident response, and post-incident information sharing. [source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook]
  • [inference] Current-direction lens: The 2026 agentic guidance indicates that aligned agencies now see autonomy, tool use, and broad system access as a new escalation point, which sharpens the older Five Eyes advice about least privilege, logging, and human accountability. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

§6 Synthesis

Executive summary:

The current Five Eyes stance is best read as support for adopting AI for public benefit and cyber defence only inside security-first governance that treats AI as both a powerful capability and a new attack surface. [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development] Alliance consensus is strongest on secure-by-design development, secure deployment of externally developed systems, protection of model weights and data, awareness of prompt injection, meaning malicious instructions hidden in model inputs, and data poisoning, logging and monitoring, and human accountability. [inference; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://owasp.org/www-community/attacks/PromptInjection] The advice to governments and regulated organisations is concrete: assign accountable owners, use threat models, catalogue trusted data sources, lock down access, sanitise inputs, monitor behaviour, prepare rollback and incident response, and share incident information where possible. [fact; source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook] Member-specific guidance in New Zealand and the United States mainly extends that same baseline into public-service governance, transparency, assurance, and collaborative reporting rather than replacing it. [inference; source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook]

Key findings:

  1. The Five Country Ministerial's 2024 position is that Artificial Intelligence brings economic and cyber-defence benefits, but also creates novel vulnerabilities and accelerates malicious activity, so the alliance is committing to shared frameworks, standards work, and safe, secure, trustworthy deployment. ([fact]; medium confidence; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible)
  2. The joint 2023 cyber-agency guidance establishes a lifecycle-based secure-by-design baseline that requires providers to build security into design, development, deployment, and operation, and to take responsibility for downstream security outcomes across complex artificial-intelligence supply chains. ([fact]; medium confidence; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development)
  3. For organisations deploying externally developed systems, the alliance's concrete advice is to appoint a named accountable cyber owner, document threats and security boundaries, demand threat models from developers, catalogue trusted data sources, evaluate supply chains, and secure model weights, keys, and infrastructure before production use. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf)
  4. The joint secure-use guidance treats data poisoning, prompt injection, adversarial examples, hallucinations, privacy or intellectual-property leakage, and model stealing as routine planning assumptions for adopters of self-hosted and third-party hosted artificial-intelligence systems, not as edge cases for specialist builders alone. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf)
  5. The alliance's operational baseline after deployment is specific and testable: authenticate and authorise Application Programming Interfaces, sanitise inputs to reduce prompt-injection risk, separate user and administrator privileges, use multifactor authentication, collect logs on inputs, outputs, intermediate states, and errors, monitor anomalies, audit, penetration-test, patch, and keep rollback paths ready. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf)
  6. Member guidance from New Zealand and the United States shows an aligned extension from model and infrastructure security toward data security and collaborative defence, with official advice to protect training, testing, and operating data and to share artificial-intelligence incident and vulnerability information voluntarily across government and critical-infrastructure partners. ([inference]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook)
  7. New Zealand's 2025 public-service guidance applies the same security, accountability, transparency, and human-oversight themes that appear in Five Eyes cyber guidance to agency governance, public-facing policy disclosure, and registers of artificial-intelligence use. ([inference]; medium confidence; source: https://www.beehive.govt.nz/release/guidance-safe-use-ai-public-sector; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/)
  8. The newest aligned guidance on agentic systems suggests the control baseline is tightening around least privilege, low-risk initial use cases, and explicit security-model updates for autonomous tool-using systems, but this should be read as an allied extension led by individual agencies rather than as settled formal Five Eyes consensus. ([inference]; medium confidence; source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services)

Evidence map:

Claim Source Confidence Notes
[fact] Five Country Ministerial frames AI as opportunity plus security risk and commits to aligned standards and governance work. https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible medium Single primary source
[fact] Joint development guidance requires secure-by-design lifecycle controls and provider responsibility across supply chains. https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development ; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development medium Joint guidance plus CISA announcement of the same guidance
[fact] Joint deployment guidance requires accountable ownership, threat models, trusted data-source catalogues, supply-chain evaluation, and protection of model weights and infrastructure. https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/ ; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf medium Page and PDF of same guidance
[fact] Joint secure-use guidance names poisoning, prompt injection, hallucinations, privacy leakage, and model stealing as standard risks for adopters. https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/ ; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf medium Page and PDF of same guidance
[fact] Post-deployment baseline includes API security, input sanitisation, multifactor authentication, privilege separation, logging, anomaly monitoring, audits, penetration tests, patching, and rollback. https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf medium Detailed single PDF source
[inference] Member guidance from New Zealand and the United States extends aligned practice toward data security and collaborative AI incident sharing. https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/ ; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook medium Member-specific guidance, not a formal Five Eyes document
[inference] New Zealand public-service guidance applies shared Five Eyes security and accountability themes to agency governance, transparency, and assurance mechanisms. https://www.beehive.govt.nz/release/guidance-safe-use-ai-public-sector ; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/ ; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/ ; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/ medium National implementation layer with alliance comparison inferred
[inference] Agentic guidance shows the next likely expansion of aligned practice, but it is not yet formal Five Eyes consensus. https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai ; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services medium Allied extension

Assumptions:

  • [assumption] Governments and regulated organisations will mostly be deployers or operators of externally developed AI systems rather than frontier-model builders, because the joint Five Eyes deployment guidance is written for that deployment profile and the New Zealand public-service material assumes agency adoption rather than base-model training. [source: https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]
  • [assumption] The 2026 agentic guidance is relevant to the "current stance" question because it was published on the current session date and directly extends the same access-control and risk-posture concerns already present in earlier guidance. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]

Analysis:

The evidence supports a practical conclusion rather than a philosophical one: Five Eyes governments are not telling organisations to avoid AI; they are telling them to adopt AI only inside normal cyber-accountability structures plus a small set of AI-specific controls. [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf] The strongest consensus items are those repeated across multiple documents: secure by design, named accountability, threat modelling, supply-chain scrutiny, least privilege, monitoring, incident response, and human oversight. [inference; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf] Member-specific documents matter because they show how governments are turning the shared baseline into operational rules such as registers, responsible officials, and voluntary reporting channels, but they do not overturn the alliance core. [inference; source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook]

Risks, gaps, uncertainties:

  • [inference] The Five Eyes corpus is much more explicit about cyber security and misuse than about sector-specific legal duties for regulated industries, so regulated organisations still need to map these controls into their own supervisory regimes. [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • [inference] The 2026 agentic guidance is highly relevant to current practice, but because it is not framed as a formal Five Eyes document, its status is best read as direction of travel rather than settled alliance doctrine. [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]

Open questions:

  • [inference] How, if at all, will Five Eyes governments translate the shared cyber-guidance baseline into sector-specific regulatory expectations for banking, health, and critical-infrastructure operators? [source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]
  • [inference] Will allied agentic-AI guidance become formal Five Eyes consensus, and if so, what additional requirements will emerge for delegated actions, event recording, and approval thresholds? [source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai]

§7 Recursive Review

  • Labels checked: complete
  • Source binding checked: complete
  • Alliance and member-specific boundary checked: complete
  • Confidence outcome: medium

Findings

Executive Summary

The current Five Eyes stance is best read as support for adopting Artificial Intelligence for public benefit and cyber defence only inside security-first governance that treats AI as both a useful capability and a new attack surface. [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development] The alliance's strongest consensus is on secure-by-design development, secure deployment of externally developed systems, protection of model weights and data, awareness of prompt injection, meaning malicious instructions hidden in model inputs, and data poisoning, strong logging and monitoring, and clear human accountability. [inference; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://owasp.org/www-community/attacks/PromptInjection] The concrete advice to governments and regulated organisations is to assign accountable owners, use threat models, catalogue trusted data sources, restrict access, sanitise inputs, monitor behaviour, prepare rollback and incident response, and share incident information where possible. [fact; source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook] New Zealand and United States member guidance mainly extends that baseline into public-service assurance, transparency, and collaborative reporting rather than replacing it with a different doctrine. [inference; source: https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook]

Key Findings

  1. The Five Country Ministerial's 2024 position is that Artificial Intelligence brings economic and cyber-defence benefits, but also creates novel vulnerabilities and accelerates malicious activity, so the alliance is committing to shared frameworks, standards work, and safe, secure, trustworthy deployment. ([fact]; medium confidence; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible)
  2. The joint 2023 cyber-agency guidance establishes a lifecycle-based secure-by-design baseline that requires providers to build security into design, development, deployment, and operation, and to take responsibility for downstream security outcomes across complex artificial-intelligence supply chains. ([fact]; medium confidence; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development)
  3. For organisations deploying externally developed systems, the alliance's concrete advice is to appoint a named accountable cyber owner, document threats and security boundaries, demand threat models from developers, catalogue trusted data sources, evaluate supply chains, and secure model weights, keys, and infrastructure before production use. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf)
  4. The joint secure-use guidance treats data poisoning, prompt injection, adversarial examples, hallucinations, privacy or intellectual-property leakage, and model stealing as routine planning assumptions for adopters of self-hosted and third-party hosted artificial-intelligence systems, not as edge cases for specialist builders alone. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf)
  5. The alliance's operational baseline after deployment is specific and testable: authenticate and authorise Application Programming Interfaces, sanitise inputs to reduce prompt-injection risk, separate user and administrator privileges, use multifactor authentication, collect logs on inputs, outputs, intermediate states, and errors, monitor anomalies, audit, penetration-test, patch, and keep rollback paths ready. ([fact]; medium confidence; source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf)
  6. Member guidance from New Zealand and the United States shows an aligned extension from model and infrastructure security toward data security and collaborative defence, with official advice to protect training, testing, and operating data and to share artificial-intelligence incident and vulnerability information voluntarily across government and critical-infrastructure partners. ([inference]; medium confidence; source: https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook)
  7. New Zealand's 2025 public-service guidance applies the same security, accountability, transparency, and human-oversight themes that appear in Five Eyes cyber guidance to agency governance, public-facing policy disclosure, and registers of artificial-intelligence use. ([inference]; medium confidence; source: https://www.beehive.govt.nz/release/guidance-safe-use-ai-public-sector; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/)
  8. The newest aligned guidance on agentic systems suggests the control baseline is tightening around least privilege, low-risk initial use cases, and explicit security-model updates for autonomous tool-using systems, but this should be read as an allied extension led by individual agencies rather than as settled formal Five Eyes consensus. ([inference]; medium confidence; source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services)

Evidence Map

Claim Source Confidence Notes
[fact] Five Country Ministerial frames AI as opportunity plus security risk and commits to aligned standards and governance work. https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible medium Single primary source
[fact] Joint development guidance requires secure-by-design lifecycle controls and provider responsibility across supply chains. https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development ; https://www.cisa.gov/news-events/news/dhs-cisa-and-uk-ncsc-release-joint-guidelines-secure-ai-system-development medium Joint guidance plus CISA announcement of the same guidance
[fact] Joint deployment guidance requires accountable ownership, threat models, trusted data-source catalogues, supply-chain evaluation, and protection of model weights and infrastructure. https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/ ; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf medium Page and PDF of same guidance
[fact] Joint secure-use guidance names poisoning, prompt injection, hallucinations, privacy leakage, and model stealing as standard risks for adopters. https://www.ncsc.govt.nz/protect-your-organisation/engaging-with-artificial-intelligence/ ; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf medium Page and PDF of same guidance
[fact] Post-deployment baseline includes API security, input sanitisation, multifactor authentication, privilege separation, logging, anomaly monitoring, audits, penetration tests, patching, and rollback. https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf medium Detailed single PDF source
[inference] Member guidance from New Zealand and the United States extends aligned practice toward data security and collaborative AI incident sharing. https://www.ncsc.govt.nz/protect-your-organisation/ai-data-security/ ; https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook medium Member-specific guidance, not a formal Five Eyes document
[inference] New Zealand public-service guidance applies shared Five Eyes security and accountability themes to agency governance, transparency, and assurance mechanisms. https://www.beehive.govt.nz/release/guidance-safe-use-ai-public-sector ; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/ ; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/governance-and-genai-in-the-public-service/2025/en/ ; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/ medium National implementation layer with alliance comparison inferred
[inference] Agentic guidance shows the next likely expansion of aligned practice, but it is not yet formal Five Eyes consensus. https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai ; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services medium Allied extension

Assumptions

  • Assumption: Governments and regulated organisations will mostly be deployers or operators of externally developed AI systems rather than frontier-model builders. Justification: The joint Five Eyes deployment guidance is written for that profile, and the New Zealand public-service material assumes agency adoption rather than base-model training. [assumption; source: https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/]
  • Assumption: The 2026 agentic guidance is relevant to the "current stance" question because it was published on the current session date and directly extends the same access-control and risk-posture concerns already present in earlier guidance. Justification: It sharpens, rather than replaces, the least-privilege and accountability themes already present in the joint deployment material. [assumption; source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

Analysis

The evidence supports a practical conclusion rather than a philosophical one: Five Eyes governments are not telling organisations to avoid AI; they are telling them to adopt AI only inside normal cyber-accountability structures plus a small set of AI-specific controls. [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf] The strongest consensus items are the ones repeated across multiple documents, namely secure by design, named accountability, threat modelling, supply-chain scrutiny, least privilege, monitoring, incident response, and human oversight. [inference; source: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development; https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf] A plausible rival interpretation is that governments should wait for sector-specific AI regulation before acting, but the corpus does not support that reading because the practical controls are framed as current cyber-security measures to implement now, not as contingent future obligations. [inference; source: https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf; https://docref.digital.govt.nz/nz/generative-ai-guidance-gcdo/public-service-ai-framework/2025/en/] Another rival view is that AI risk can be handled by generic software-security controls alone, but the repeated focus on poisoned data, prompt injection, model theft, and model-weight protection shows why AI-specific validation, provenance, and behavioural monitoring still need dedicated treatment. [inference; source: https://www.ncsc.govt.nz/assets/guidance/Documents/engaging-with-artificial-intelligence.pdf; https://www.ncsc.govt.nz/assets/guidance/Documents/csi-deploying-ai-systems-securely.pdf]

Risks, Gaps, and Uncertainties

  • The Five Eyes corpus is much more explicit about cyber security and misuse than about sector-specific legal duties for regulated industries, so regulated organisations still need to map these controls into their own supervisory regimes. [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible; https://www.ncsc.govt.nz/protect-your-organisation/deploying-ai-systems-securely/]
  • The 2026 agentic guidance is highly relevant to current practice, but because it is not framed as a formal Five Eyes document, its status is best read as direction of travel rather than settled alliance doctrine. [inference; source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai; https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services]

Open Questions

  • How, if at all, will Five Eyes governments translate the shared cyber-guidance baseline into sector-specific regulatory expectations for banking, health, and critical-infrastructure operators? [inference; source: https://www.gov.uk/government/publications/five-country-ministerial-communique-2024/five-country-ministerial-communique-2024-accessible]
  • Will allied agentic-AI guidance become formal Five Eyes consensus, and if so, what additional requirements will emerge for delegated actions, event recording, and approval thresholds? [inference; source: https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai]

Output

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally