AI makes digital extortion more pressing for leaders
Dutch security services warn that artificial intelligence is accelerating and simplifying cyberattacks.
Dutch security and investigative services are urging leaders to put cybersecurity higher on the agenda. According to a joint statement, artificial intelligence can identify and exploit vulnerabilities more quickly, while ransomware has developed into a professional criminal industry.
The warning came this week from the Nationaal Coördinator Terrorismebestrijding en Veiligheid, the Nationaal Cyber Security Centrum, the AIVD, the MIVD, the Openbaar Ministerie, CIO Rijk and the police. They write that AI can accelerate and scale up cyberattacks and keep them under the radar for longer. According to the services, this does not necessarily require the most advanced models; widely available AI systems can also help attackers.
The appeal is explicitly aimed at leaders, not just technical departments. According to the security services, organisations must put their basic security in order, assess whether their level of protection is still appropriate and take signals concerning AI seriously. The reason is that digital systems are now intertwined with public services, business processes and social infrastructure.
De Nederlandsche Bank meanwhile describes ransomware as a professional market with suppliers, negotiators and off-the-shelf services. Criminals can buy stolen passwords, databases and ransomware packages. The approach is also shifting: when organisations have good backups, stealing data and threatening to publish it may be more attractive than merely encrypting systems.
The total global damage cannot be determined precisely because not every incident is reported. A cyber expert at DNB estimates the damage at tens of billions of euros per year. That figure encompasses more than ransom: downtime, recovery costs and lost revenue also count. This uncertainty makes precise comparisons between governments and businesses difficult.
The Netherlands has meanwhile introduced new legal requirements. Since 15 August, the Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten have been in force. According to the Dutch government, thousands of organisations in areas including healthcare, energy, drinking-water supply, digital infrastructure and transport must comply with new obligations.
Requirements for government contracts are also being tightened. The Algemene Beveiligingseisen voor Rijksoverheidsopdrachten will apply from 1 January 2026 to contracts posing risks to national security. The Nationaal Bureau Industrieveiligheid assesses, among other things, suppliers’ organisation, personnel and digital security. Those who fail to meet the requirements may miss out on a contract or lose one.
The current warning does not mean that every AI application will immediately lead to an attack. The services do, however, state that leaders can no longer treat cybersecurity as a technical detail. The comparison in the supplied headline between the vulnerability of governments and businesses is not substantiated in public sources by independent research or a figure; this article therefore focuses on the broader, verifiable warning.
One story, several perspectives
What is established
- Dutch security and investigative services have called on leaders to make cybersecurity a priority.
- According to those services, AI can accelerate parts of the attack chain, but public sources do not show that governments are generally more vulnerable than businesses.
- In 2026, the Netherlands introduced new legal requirements for digital resilience and secure government contracts.
Left
Arguments Digital security is a public responsibility. Governments and businesses must invest sufficiently in security, even when the benefits only become visible when an attack does not occur. Basic security must not depend on an organisation’s financial capacity.
Values Collective protection, privacy and preventing citizens from paying the price for inadequate security.
Consequences More public funding and stricter standards may limit incidents, but increase costs and administrative burdens for organisations.
Centre
Arguments A risk-based approach is the obvious course: set minimum requirements for vital and sensitive services, keep leaders responsible and share threat information between government and business. Not every organisation needs the same measures.
Values Proportionality, continuity and administrative responsibility.
Consequences Phased rules can improve resilience without imposing the same expensive layer of security everywhere, but require ongoing oversight and expertise.
Right
Arguments The government should concentrate on vital functions and prevent broad regulation from imposing the same obligations on every business. Suppliers and leaders should remain liable and responsible for their security choices.
Values Efficiency, limited government intervention and clear responsibility.
Consequences Less regulatory pressure can support innovation and competition, but an overly limited public approach may allow weak links to persist in vital chains.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The factual core has been confirmed by a joint government statement, DNB and Dutch government webpages. Uncertain damage figures and the unsubstantiated comparison between governments and businesses have explicitly been treated as uncertain or not adopted.
- confirmed Dutch security and investigative services jointly warned on 24 September 2026 that AI was accelerating cyberattacks. — This appears in the joint statement published by the NCTV. source
- confirmed AI can identify and exploit vulnerabilities more quickly and automate attacks. — The NCTV and the NCSC describe this explicitly in their warning. source
- confirmed DNB describes ransomware as a professional industry with services, suppliers and revenue models. — This characterisation appears in DNB’s background publication of 23 September 2026. source
- confirmed According to a DNB expert, global damage amounts to tens of billions of euros per year, but is not precisely known. — DNB mentions both the uncertainty and its expert’s estimate. source
- confirmed The Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten have been in force since 15 August 2026. — The Dutch government gives this date and the scope of the laws. source
- confirmed ABRO requirements apply from 1 January 2026 to certain government contracts and are checked by the NBIV. — The Dutch government describes their introduction, oversight and consequences. source
Editor's note
Public sources confirm the joint warning about AI and the legal obligations. The specific comparison that governments are more vulnerable than businesses is not independently substantiated by a public study and has therefore not been presented as fact.Sources
- AI versnelt en vergroot de dreiging: nu handelen noodzakelijk — NCTV
- Hoe ransomware uitgroeide tot een miljardenindustrie — De Nederlandsche Bank
- Cybersecurity verhogen — Rijksoverheid.nl
- Beveiligingseisen bij overheidsopdrachten met risico’s voor nationale veiligheid — Rijksoverheid.nl