Summary
- Seven Dutch security and government bodies warn that AI will increase the number, scale, and complexity of cyberattacks.
- The agencies say accessible AI models are already accelerating established techniques, including vulnerability discovery and exploitation.
- Their joint statement puts cyber resilience at senior-management level rather than treating AI-enabled threats as a narrowly technical issue.
Dutch intelligence, cyber, police, and government bodies have issued a joint warning that artificial intelligence is accelerating cyber threats, arguing that organisations need to adjust their security and governance as established attack techniques become easier to automate.
The statement brings together the National Coordinator for Counterterrorism and Security, National Cyber Security Centre, General Intelligence and Security Service, Defence Intelligence and Security Service, Public Prosecution Service, central-government CIO organisation, and police.
The agencies expect AI to increase the number, scale, and complexity of cyberattacks against government and society. Their assessment concentrates less on wholly new attack categories than on the technology’s ability to automate and accelerate techniques attackers already use.
Matthijs van Amelsfort, CEO of the National Cyber Security Centre, said: “AI is automating the kill chain, from identifying vulnerabilities to exploiting them.”
The agencies say malicious actors do not need access to the most advanced frontier models to benefit. Existing and readily accessible AI systems can already help automate tasks, identify weaknesses more quickly, and improve the efficiency of established attack techniques.
That compresses a security problem organisations have dealt with for years. Vulnerability management, detection, incident response, and configuration control all depend partly on the interval between a weakness becoming discoverable and an attacker being able to use it. Automation can reduce that interval without requiring the underlying attack method to be novel.
The Dutch warning also moves the issue beyond security tooling. Senior leaders are being urged to provide sufficient resources, review whether existing protection remains appropriate, and take emerging AI-related threat signals seriously.
That governance emphasis reflects organisations’ dependence on interconnected digital systems. A faster attack cycle affects more than vulnerability teams: it can change assumptions behind patching windows, outsourced security arrangements, crisis preparation, business continuity, and the authority needed to respond when an emerging threat demands rapid action.
The agencies point to prolonged disruption of critical systems and theft of personal information as consequences already associated with inadequate cyber defences. Their argument is that AI can amplify those existing exposures rather than creating a separate risk environment that can be managed in isolation.
The breadth of organisations behind the statement is also notable. Intelligence services, prosecutors, police, the national cyber authority, and central-government technology leadership are presenting the same issue as one involving prevention, resilience, investigation, and organisational accountability.
European regulation is already pushing some organisations towards similar links between technical controls and governance. NIS2 places greater emphasis on management responsibility and risk management, while DORA has forced regulated financial organisations to formalise resilience testing and oversight of technology dependencies.
The Dutch statement does not establish that every organisation is already experiencing a surge in successful AI-driven attacks. Its claims about the future scale of the threat remain an official assessment rather than a measured incident rate.
The more immediate finding is that several Dutch security bodies believe the economics and pace of established attack activity are changing enough to justify action now. AI does not need to invent a new form of intrusion to alter risk materially: reducing the time, labour, or expertise required to identify weaknesses, analyse environments, or iterate through unsuccessful attack paths can change how quickly existing weaknesses become operational incidents.
The agencies are therefore treating AI-enabled cyber risk as an organisational resilience problem, with responsibility extending beyond teams operating individual technical controls.





