Eighty years after the foundations of Five Eyes were laid in signals intelligence, a new strategic asset is entering the trusted circle: frontier artificial intelligence. The emerging question is no longer simply who shares intelligence with whom, but who receives privileged access to the machines increasingly capable of producing it—and acting on it.
By Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)
For most of its history, the logic of the Five Eyes intelligence relationship was relatively straightforward.
The most sensitive information would be collected by national intelligence agencies and shared among an unusually trusted group of allies.
The strategic asset was intelligence.
The infrastructure consisted of signals collection, communications systems, analysts, cryptographic capabilities and decades of institutional trust.
Artificial intelligence is beginning to complicate that model.
On October 6, Anthropic expanded a program providing vetted cybersecurity professionals with privileged access to some of its most capable AI systems. The new structure includes different levels of access for defensive cybersecurity, authorized penetration testing and work involving safety-critical infrastructure such as power grids, aviation systems and interbank financial networks.
The most sensitive tier is not simply open to anyone willing to pay.
Organizations are vetted.
Restrictions can be reduced.
More capable systems become available.
And the United States government participates with the company in determining eligibility.
This would already be important as a development in AI governance.
Placed beside what Australia, Canada, New Zealand, the United Kingdom and the United States have been saying collectively during 2026, however, it points toward something larger.
At their Five Country Ministerial meeting in Sydney in August, the five governments committed to deeper cooperation with industry on national-security priorities, explicitly including timely access to frontier AI models to strengthen cybersecurity.
They also discussed which characteristics of advanced AI systems might justify additional government scrutiny and exchanged lessons from national AI security exercises.
That language deserves attention.
Because an alliance built around privileged access to intelligence may be approaching an era in which privileged access to intelligence-producing capability becomes strategically important as well.
The Five Eyes system is not becoming an “AI alliance” overnight.
No treaty establishes such an arrangement.
There is no evidence of a formal Five Eyes pool of frontier models comparable to traditional intelligence-sharing mechanisms.
But the direction of travel is becoming visible.
The alliance’s next strategic layer may concern not only what its members know.
It may concern what their machines are allowed to do.
The Alliance Before the Algorithm
The historical starting point is the Second World War.
British and American intelligence cooperation deepened dramatically during the conflict, particularly in signals intelligence and cryptanalysis.
That wartime relationship was formalized on March 5, 1946, through the BRUSA Agreement between Britain and the United States.
The arrangement evolved into what became known as the UKUSA Agreement.
Canada joined the broader structure in the late 1940s.
Australia and New Zealand were subsequently incorporated into the partnership.
What eventually became popularly known as Five Eyes was unusual because it was more than conventional diplomatic cooperation.
States routinely exchange intelligence.
Five Eyes institutionalized an exceptionally deep level of intelligence integration.
Its durability depended on something difficult to manufacture:
trust accumulated over decades.
The participating countries shared political traditions, military relationships, technical systems, strategic interests and intelligence practices.
Most importantly, they developed confidence that extremely sensitive information could circulate within the partnership without destroying the sources and methods through which that information had been obtained.
That trust became a strategic capability in its own right.
Intelligence Alliances Are Access Regimes
The importance of Five Eyes has never been simply that five governments cooperate.
Its deeper significance lies in access.
Who can see what?
Which intelligence can move across national boundaries?
Which systems can connect?
Which personnel are trusted?
Which capabilities remain compartmentalized?
Which allies receive intelligence that other friendly governments do not?
Every intelligence alliance is therefore also an access regime.
Information has strategic value partly because access to it is unequal.
For most of the twentieth century, the most valuable assets inside this architecture were collected secrets.
Intercepted communications.
Signals.
Technical intelligence.
Analytical assessments.
Cryptographic information.
Artificial intelligence introduces a different category of asset.
Capability itself.
A frontier AI model does not merely contain information.
It can analyze information.
Discover vulnerabilities.
Write software.
Search enormous datasets.
Assist intelligence analysts.
Identify patterns.
Generate hypotheses.
Support cyber defense.
And, depending on its capabilities and restrictions, potentially assist offensive cyber operations.
The strategic object is therefore changing.
From Sharing Intelligence to Sharing Intelligence Production
This distinction may become one of the defining changes in twenty-first-century intelligence cooperation.
Traditional intelligence sharing transfers an output.
One agency obtains information and provides some portion of it to another.
Advanced AI can transfer something closer to the means of production.
Give an organization access to a sufficiently capable model and it may acquire analytical or cyber capabilities that previously required large teams of specialists.
That does not eliminate human expertise.
Nor does it transform a commercial model into an intelligence service.
But it changes the economics of capability.
A trusted partner equipped with advanced AI may be able to process malware faster.
Analyze larger volumes of intelligence.
Search for vulnerabilities at greater scale.
Translate and synthesize foreign-language information.
Model possible adversary behavior.
Assist defensive operations.
Automate portions of technical analysis.
The question facing alliances may therefore evolve from:
What intelligence should we share?
to:
What AI capability should we share?
Those are not the same question.
The June Warning Was the First Signal
The Five Eyes cybersecurity agencies provided an important clue in June.
In a rare joint statement, their leaders warned that frontier AI was rapidly transforming cyber risk.
Their assessment was unusually urgent.
The timeline for major changes in offensive and defensive cyber capability, they argued, should be measured in months rather than years.
That statement was important because it showed that the five governments were beginning to develop a shared strategic understanding of frontier AI as a cybersecurity issue.
But threat assessment is only the first stage of institutional adaptation.
Once governments agree that a capability is strategically important, another question follows.
How should they organize access to it?
By August, the Five Country Ministerial had moved closer to that question.
The governments explicitly committed to working with industry to enable timely access to frontier models in support of secure innovation and cybersecurity.
The movement from June to August is analytically significant.
First:
Frontier AI may transform the cyber threat environment.
Then:
Trusted institutions need access to frontier AI capabilities.
That is the beginning of an access architecture.
October 6 Shows What Access Architecture Can Look Like
Today’s development provides a concrete example.
Anthropic’s expanded Cyber Verification Program creates differentiated access to advanced AI capabilities.
Different organizations receive different privileges depending on their purpose and level of verification.
Defensive teams receive one category of access.
Authorized red teams receive another.
A smaller group working on safety-critical systems can receive still broader capability.
The details belong to one company and should not be mistaken for government alliance policy.
But the architecture is revealing.
Identity.
Purpose.
Authorization.
Vetting.
Capability.
Restrictions.
Monitoring.
Trust.
These are familiar concepts in national-security systems.
What is unusual is that they are now being applied to access to commercial artificial intelligence.
The Private Company Inside the Security Perimeter
This creates an institutional novelty.
The original Five Eyes architecture was fundamentally state-centered.
NSA.
GCHQ.
The Communications Security Establishment in Canada.
The Australian Signals Directorate.
New Zealand’s Government Communications Security Bureau.
The institutions collecting and sharing the most sensitive capabilities were government organizations.
Frontier AI is different.
Many of the most powerful general-purpose AI systems are developed by private corporations.
Governments do not necessarily own the models.
They may not own the computing infrastructure.
They may not control the underlying research teams.
They may not determine release schedules.
They may not even know precisely when the next major capability threshold will be crossed until companies report their evaluations.
Yet these systems may become increasingly important to national cybersecurity.
This produces an unusual security arrangement.
The state may remain responsible for national security while depending on privately controlled strategic capabilities.
That relationship is deeper than procurement.
A government purchasing conventional software buys a product.
A government depending on frontier AI may depend continuously on the developer maintaining the model, operating infrastructure, updating safeguards, controlling access and assessing new capabilities.
The private laboratory therefore begins to occupy a position somewhere between technology supplier, critical infrastructure provider and strategic security partner.
Five Eyes Has Seen This Problem Before
There is a historical parallel.
Signals intelligence has always depended heavily on technology.
Telecommunications networks were frequently privately operated.
Computer manufacturers supplied critical systems.
Satellite and cable infrastructure involved commercial actors.
Cybersecurity intensified the relationship between intelligence agencies and technology companies.
But frontier AI pushes the relationship further.
A telecommunications company transports information.
A cloud provider stores or processes information.
An AI model can actively interpret it.
And increasingly, it can perform technical tasks based on that interpretation.
The difference is agency.
The more capable AI becomes, the more the security relationship moves from infrastructure toward operational capability.
That is why access governance matters.
The Model as a Dual-Use Strategic Asset
The easiest historical analogy is export control.
States have long restricted access to strategically important technologies.
Cryptography.
Advanced semiconductors.
Missile components.
Nuclear technologies.
Certain surveillance capabilities.
Artificial intelligence does not fit neatly into these categories.
A frontier model can simultaneously be:
a commercial product;
a research tool;
a coding assistant;
a scientific instrument;
a cybersecurity capability;
an intelligence-analysis tool;
and potentially a component of military systems.
Its strategic character depends partly on what it can do and partly on who is using it.
That makes traditional control mechanisms difficult.
Restrict the hardware?
The model can still spread through APIs.
Restrict the model weights?
Capabilities may remain available through cloud access.
Restrict users by nationality?
Multinational companies complicate enforcement.
Restrict specific tasks?
AI systems can generalize beyond predetermined categories.
The emerging alternative is therefore increasingly based on trusted access.
Not everyone receives identical capability.
From Classification to Capability Tiering
Traditional national security uses classification systems.
Information is categorized according to sensitivity.
Access depends on authorization and need-to-know.
Frontier AI could create an analogous—but importantly different—system.
The model itself may not be classified.
Instead, capability becomes tiered.
A public user receives one set of capabilities and safeguards.
A verified researcher receives another.
A cybersecurity organization receives fewer restrictions.
A critical-infrastructure defender receives still broader access.
Government security organizations may receive early access or specialized configurations.
The governing principle becomes:
need-to-capability.
That would represent an important shift.
Security institutions historically controlled access to secrets.
They may increasingly need to control access to machine capability.
Could Alliance Membership Determine AI Access?
This is where Five Eyes becomes geopolitically important.
If the most capable AI systems become national-security assets, governments will eventually face pressure to determine which foreign partners can access them.
Not every ally is equally trusted.
Not every country maintains equivalent cybersecurity standards.
Not every government has the same relationship with technology companies.
Not every jurisdiction provides the same protections against technology transfer.
Five Eyes already possesses something extremely valuable in this environment:
a mature trust architecture.
The five governments do not need to invent an intelligence relationship from zero.
They already possess decades of procedures for handling sensitive information, coordinating threats and establishing trusted institutional relationships.
That makes the grouping a natural environment for deeper AI-security cooperation.
This does not mean frontier AI access will become exclusive to Five Eyes.
Indeed, current industry programs extend beyond those five states, and broader G7 discussions have considered trusted-partner approaches.
But Five Eyes may function as an inner circle within a larger architecture.
That would resemble other areas of international security.
Broad coalitions outside.
Higher-trust arrangements inside.
The G7 Problem Shows Why This Matters
The political difficulty became visible earlier this year.
When U.S. restrictions affected access to particularly capable American AI systems, allied governments began asking a basic question:
Are allies treated as partners or simply as foreign users?
That distinction matters.
European states may share security interests with Washington while simultaneously resisting technological dependence on American companies.
If access to strategically valuable AI can be restricted unilaterally by the United States, allies have an incentive to develop sovereign alternatives.
That is one reason European AI sovereignty has become strategically important.
The debate is therefore not merely:
Who gets American AI?
It is:
What kind of technological alliance system will exist around frontier AI?
The Democratic Technology Bloc
One possible outcome is the emergence of a trusted technology bloc.
At its center could be the United States and its closest intelligence allies.
Around that core could sit NATO partners, G7 states and other governments meeting security requirements.
Access could depend on factors such as:
cybersecurity standards;
export-control compliance;
research-security practices;
data protections;
counterintelligence safeguards;
model-monitoring requirements;
and commitments preventing onward transfer.
The result would not necessarily be a formal treaty.
It could emerge gradually through regulations, commercial agreements, government procurement rules and company access programs.
That is how many international architectures develop.
Practice comes before doctrine.
China Makes the Question Unavoidable
Any trusted AI-access architecture would inevitably have a China dimension.
Washington already treats advanced semiconductors, AI infrastructure and some frontier capabilities as strategic technologies.
Beijing has simultaneously invested heavily in domestic AI capability and promoted alternative technological ecosystems.
The strategic competition therefore increasingly concerns not simply who possesses the best model.
It concerns who can distribute capability across a network of partners.
This is an alliance advantage.
China can develop powerful AI.
The United States can develop powerful AI.
But if one side can safely distribute advanced capabilities across trusted partners while the other cannot, alliance structure itself becomes a technological multiplier.
Five Eyes has historically provided precisely this kind of multiplier in intelligence.
The same principle could apply to AI.
But AI Is Harder to Contain Than Intelligence
There is a fundamental problem.
Intelligence is secret by design.
Commercial AI is designed for distribution.
Companies need customers.
Researchers need access.
Developers build applications.
Models improve partly because they are used.
Excessively restricting access can therefore weaken the very ecosystem producing strategic advantage.
This creates a security paradox.
A country wants to protect its frontier capabilities.
But it also wants its companies to dominate international markets.
It wants allies to depend on its technology.
It wants researchers to build on its platforms.
It wants developers to create applications.
It wants defenders to use the models before adversaries do.
Too much openness creates security risk.
Too much restriction creates strategic isolation.
The optimal system is therefore unlikely to be complete control.
It will be selective openness.
Five Eyes Could Become a Laboratory for Selective Openness
The alliance is unusually well positioned to experiment with that model.
Its members already share sensitive threat information.
Their cybersecurity agencies routinely publish joint advisories.
They conduct intelligence cooperation.
They coordinate on state threats.
Their governments possess extensive relationships with technology companies.
They share broadly similar political and legal traditions, despite important differences.
This could make Five Eyes a laboratory for questions the international system will eventually have to confront more broadly.
What level of AI capability should allies share?
Who certifies trusted users?
Should governments or companies make access decisions?
What happens if one member considers a model safe and another does not?
How are model-generated intelligence products handled?
Can sensitive government data be processed by commercial models?
Should models used for national-security work operate on sovereign infrastructure?
Who audits them?
Who is responsible if they behave unpredictably?
These are no longer theoretical governance questions.
They are alliance-management questions.
The Attribution Problem
AI also complicates another cornerstone of intelligence cooperation: attribution.
Five Eyes governments frequently coordinate assessments of malicious cyber activity.
But increasingly autonomous AI systems introduce another actor between human intention and technical effect.
A model may discover a vulnerability.
An agent may select a method.
An automated system may execute part of an operation.
Human operators may supervise at varying levels.
Intelligence agencies will therefore need to distinguish among:
the state;
the organization;
the human operator;
the AI developer;
the deployed model;
and the autonomous actions performed by the system.
Alliance intelligence sharing may become essential to making those distinctions.
The Five Eyes advantage could therefore lie not merely in possessing AI.
It could lie in collectively understanding AI-mediated activity better than adversaries do.
Private Models Could Become Alliance Infrastructure
The most consequential possibility is that certain commercial AI systems become functionally embedded in alliance security architecture.
Not formally.
Not necessarily permanently.
But operationally.
Cyber defenders may use them.
Intelligence analysts may use them.
Critical-infrastructure operators may use them.
Defense organizations may integrate them.
Government agencies may receive early access.
Companies may coordinate safeguards with security agencies.
At that point, the distinction between commercial technology and security infrastructure becomes difficult to maintain.
The model remains privately owned.
But the capability becomes strategically embedded.
This would be a significant change in alliance history.
The Sovereignty Problem Inside the Alliance
Even close allies may become uncomfortable with this arrangement.
Suppose an Australian agency depends on an American AI model for an important cybersecurity capability.
Who ultimately controls access?
The Australian government?
The U.S. government?
The company?
Could access be withdrawn?
Could model behavior change after an update?
Where is sensitive information processed?
Which country’s law governs the system?
What happens during a political disagreement?
These questions explain why sovereign AI has become politically attractive even among allies.
Trust reduces dependency risk.
It does not eliminate it.
Five Eyes cooperation may therefore develop alongside national efforts to preserve sovereign capability.
That tension is not a weakness unique to AI.
All alliances contain tension between integration and autonomy.
AI simply introduces it into a new technological layer.
Intelligence Sharing Could Become Model Sharing
The strongest version of the future is easy to imagine.
A major vulnerability is discovered.
Five Eyes cyber agencies share the intelligence immediately.
Advanced models analyze affected software across allied networks.
AI systems search for variants.
Defenders generate patches.
Critical-infrastructure operators receive prioritized remediation.
Intelligence agencies compare evidence of exploitation.
Models assist attribution.
Indicators circulate across the alliance.
Human analysts supervise the process.
The advantage would come not from one model.
It would come from the combination of:
AI capability;
shared intelligence;
trusted infrastructure;
institutional coordination;
and allied scale.
That is precisely how alliance power works.
Capabilities become more valuable when connected.
The Risk of an AI Intelligence Divide
There is also a wider diplomatic consequence.
If powerful AI capabilities increasingly circulate through trusted security networks, a new international hierarchy may emerge.
At the top:
states developing frontier models.
Then:
states receiving privileged access.
Then:
states relying on commercially available systems.
Finally:
states unable to obtain advanced capability or compute infrastructure.
This could create an AI equivalent of the intelligence divide.
Countries inside trusted networks would receive capability earlier.
Countries outside them would receive it later, in restricted form, or not at all.
That has implications far beyond cybersecurity.
Scientific research.
Economic productivity.
Military capability.
Intelligence analysis.
Biotechnology.
Advanced engineering.
The politics of AI access could therefore become part of alliance diplomacy.
Cyber Diplomacy Will Have to Address Capability, Not Only Behavior
For years, cyber diplomacy concentrated on responsible state behavior.
Norms.
International law.
Confidence-building measures.
Attribution.
Capacity building.
Those remain essential.
But frontier AI introduces another diplomatic question:
Who gets capability?
The international politics of cyberspace increasingly concerns access to the technologies shaping cyber power.
Semiconductors.
Cloud infrastructure.
Data centers.
Advanced models.
Cybersecurity tools.
The diplomatic architecture built around behavior may therefore need to coexist with an architecture built around technological access.
Five Eyes could become one of the first places where those two systems converge.
This Is Not Yet an AI Alliance
Precision matters.
Five Eyes has not transformed into a formal frontier-AI alliance.
The Five Country Ministerial is not identical to the intelligence-sharing arrangements commonly described as Five Eyes.
Commercial verification programs are not intelligence treaties.
Company vetting does not equal security clearance.
And access to an AI model is not equivalent to access to classified intelligence.
Those distinctions should be preserved.
But institutions rarely transform in a single announcement.
They evolve by absorbing new functions.
Signals intelligence expanded into broader intelligence cooperation.
Intelligence cooperation expanded into cybersecurity coordination.
Cybersecurity coordination is now intersecting with frontier AI.
The pattern matters even before the endpoint is known.
Bottom Line Assessment
The Five Eyes partnership began in an era when strategic advantage depended heavily on intercepting communications.
Its institutions were built around secrets.
Eighty years later, strategic advantage increasingly depends on something different:
the ability to process information, discover vulnerabilities, automate technical work and convert enormous amounts of data into usable intelligence at machine speed.
That makes frontier artificial intelligence relevant not merely as another technology intelligence agencies must monitor.
It may become part of the infrastructure through which intelligence and cybersecurity are performed.
The Five Countries have already publicly identified frontier AI as a rapidly developing cyber-security challenge.
They have already committed to deeper industry cooperation and timely access to frontier models for cybersecurity.
Private AI developers are already constructing tiered systems in which trusted organizations receive capabilities unavailable to ordinary users.
Those developments do not prove that a formal AI-security alliance is emerging.
But together they reveal the beginnings of a new strategic question.
For most of the Five Eyes era, the decisive privilege was access to intelligence.
In the next phase, another privilege may become equally important:
access to the machines capable of producing strategic insight and cyber capability themselves.
The alliance that began by sharing intercepted signals may eventually find that its most valuable shared asset is no longer the signal.
It is the model.
Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)


Leave a comment