Agencies warn of faster cyberattacks driven by AI
A joint government statement calls on leaders to treat cybersecurity as the responsibility of the entire organisation.
Dutch security and law-enforcement organisations warn that artificial intelligence is making cyberattacks faster, larger and more complex. They call on leaders to put basic security in order and not to treat signals surrounding AI as an exclusively technical problem.
The warning appears in a joint statement by, among others, the NCTV, the National Cyber Security Centre, the AIVD, the MIVD, the Public Prosecution Service, CIO Rijk and the police. According to the organisations, AI lowers the threshold for malicious actors to carry out digital attacks and makes existing attack techniques more efficient.
The agencies point out that AI can help with various parts of an attack chain, such as searching for vulnerabilities and automating exploitation. They do not claim that every cyberattack is caused by AI. They do expect attacks to be prepared and scaled up more quickly because of the wide availability of existing models.
The organisations warn that the consequences go beyond temporary disruptions. A cyber incident could, they say, lead to prolonged outages of vital systems or the theft of large quantities of personal data. The scale of the future threat is not expressed in the statement as an exact number of incidents or a financial amount.
The call is therefore aimed at leaders of public and private organisations. According to the statement, they must check their basic security, assess whether protection is still appropriate and take signals concerning AI seriously. Experts must be given sufficient scope to design security measures and assess incidents quickly.
The warning is not a new legal obligation and contains no general prediction that a major attack will take place in the short term. It is a policy signal from Dutch security and law-enforcement organisations. For companies, this mainly means that existing security measures must be reassessed against a threat landscape in which attackers can automate more.
One story, several perspectives
What is established
- Dutch government organisations have jointly warned about attackers’ use of AI.
- The organisations are calling on leaders to make cybersecurity a priority.
- The statement contains recommendations but no new legal obligation.
Left
Arguments The left will emphasise that cybersecurity is a public responsibility and that small organisations, municipalities and citizens should not have to bear the costs alone. Open standards, public expertise and strong privacy safeguards are, in this view, part of the approach.
Values Digital rights, public protection, equality and democratic oversight.
Consequences More public support could increase resilience, but would require structural government spending and could slow innovation.
Centre
Arguments The centre will opt for risk-based security: basic measures in place everywhere, additional protection for vital systems and cooperation between government and business. AI should be assessed as part of a broader security chain.
Values Proportionality, expertise, continuity and practicality.
Consequences Targeted investment may be more effective than general obligations, but differences between organisations will remain.
Right
Arguments The right will mainly point to the responsibility of leaders and companies to secure their own systems. Less bureaucracy, clear liability and room for private security firms are seen as ways to act more quickly.
Values Individual responsibility, security, efficiency and innovation.
Consequences A market-oriented approach can produce new solutions quickly, but organisations with limited resources may fall behind.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The warning is based on a joint government statement and a recent publication by the police and the Public Prosecution Service. Causal claims are limited to what the organisations themselves say about AI’s capabilities.
- confirmed Dutch security and law-enforcement organisations warn that AI can accelerate and enlarge cyberattacks. — This is the core of the AIVD statement. source
- confirmed The call is aimed, among others, at the NCTV, NCSC, AIVD, MIVD, OM, CIO Rijk and the police. — These organisations are named in the joint statement. source
- confirmed AI can automate parts of the attack chain, such as searching for vulnerabilities and exploitation. — The AIVD and NCSC describe this as a development in the threat landscape. source
Editor's note
The joint warning and the recommendations mentioned have been confirmed by the AIVD and the Public Prosecution Service. The statement contains no precise prediction of the number of attacks; the text makes no claim on that point.Sources
- AI versnelt en vergroot de dreiging: nu handelen noodzakelijk — AIVD
- Politie en OM: cybercrime is grenzeloos, bedreiging groeit door inmenging van staten en inzet AI — Openbaar Ministerie
- Cybercrimebeeld Nederland 2026 — Openbaar Ministerie
More on this in Dutch media
- Het Parool — „kunstmatige intelligentie”
- NRC — „kunstmatige intelligentie”
- Tweakers — „kunstmatige intelligentie”