What the Five Eyes AI cyber warning means for London SMEs

In June 2026, the Five Eyes cyber security agencies, covering the UK, United States, Australia, Canada and New Zealand, issued a joint statement warning that AI is rapidly changing both cyber attack and defence. For a London SME, the message is calmer than the headlines suggest. You do not need the security budget of a bank. You need the basics done properly, done sooner, and treated as a business risk rather than an IT afterthought.

Most of what the agencies recommend is work a good managed IT support partner in London already helps with. What has changed is the pace.

What the warning actually says

The blunt line is that the timeline is now measured in months, not years. AI lowers the barrier for attackers, increases the speed and scale of attacks, and shrinks the gap between a weakness being found and that weakness being exploited.

This is not only about a single dramatic “AI super attack”. It is about ordinary attacks getting faster, cheaper and harder to spot. Think of a phishing email with flawless grammar, a fake login page that looks exactly right, or a scan of your systems that once took a skilled person a week and now takes an automated tool far less time.

Why London SMEs are more exposed

Larger organisations usually spend more on cyber security, so they often have stronger monitoring, patching and response processes already in place. The businesses most exposed are often the ones that have underinvested, especially smaller firms that have been meaning to “tidy things up” for a while.

The scale is not abstract. The UK government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses reported a cyber breach or attack in the previous 12 months. That equates to around 612,000 UK businesses. Phishing remained the most common type of breach or attack by far, experienced by 38% of businesses.

Picture a 30-person agency in Clerkenwell. Someone in accounts receives an invoice that matches a real supplier, a real project and a real tone of voice. They click, enter details, and the attacker now has a foothold. That is the everyday version of this threat.

The 5 actions, in plain terms

The agencies set out 5 practical actions. None of them are exotic. The table below turns each one into what it means for a smaller London business.

Five Eyes action What it means for your business
Reduce your attack surface Switch off services you do not use and review who can reach what. Regular vulnerability management services London firms rely on helps here.
Patch faster Update software, firmware and cloud systems on a schedule, not when it happens to be convenient.
Remove or isolate legacy systems Replace old unsupported systems, or separate them from the rest of your network.
Improve identity management Use multi-factor authentication everywhere, limit access, and monitor for stolen logins.
Test your response Rehearse an incident before you have one. A plan you have never practised is only a guess.

People are still the easiest way in, and AI makes that worse. Voice cloning, polished email and realistic fake login pages mean the old advice to look for bad spelling is no longer enough. This is why cyber awareness training earns its place, alongside simple habits like confirming any change of bank details by phone.

It also helps to understand how attackers push malware through malicious online adverts, and how external AI bots can join your Teams meetings and quietly record sensitive conversations if meeting controls are weak.

AI is also on the defender’s side

The warning is not all doom. The agencies were clear that AI can also help defenders. Organisations that build AI into security operations can detect vulnerabilities earlier, monitor unusual behaviour and respond faster.

In practice, that is what managed SOC services in London and managed detection and response in London now bring to smaller firms: the kind of monitoring that used to sit only inside large enterprises. Watching for leaked credentials matters too, which is where dark web monitoring for executives gives you an early signal before a stolen password is used.

This is now a boardroom issue

One final point matters. Cyber risk is a leadership responsibility, not just an IT one. It belongs on the board agenda next to cash flow, hiring and client retention.

That includes checking your Microsoft setup is configured properly, which our guidance on Microsoft 365 security for finance directors and a proper Office 365 assessment both cover. It also means keeping evidence that your controls actually work, which is the heart of why IT compliance matters.

Frequently asked questions

What is the Five Eyes AI cyber warning?
It is a June 2026 statement from the cyber security agencies of the UK, US, Australia, Canada and New Zealand. It warns that AI is changing cyber attack and defence quickly, and urges leaders to strengthen resilience now.

Are small businesses really more at risk from AI attacks?
Often, yes. Smaller firms may have weaker controls, and AI makes cheap, automated attacks more convincing and easier to scale.

What should an SME do first?
Start with multi-factor authentication, faster patching, legacy system reviews, vulnerability management, staff training and an incident response plan.

Does the warning mean a breach is inevitable?
No, but the agencies advise assuming breaches can happen and preparing to contain them quickly.

If you want a clear view of where your business is exposed, Northern Star can help you get the fundamentals right without overcomplicating them. Speak to our team about a security review, or call 0800 319 6032 to get started.