
The Five Eyes warning was blunt: AI is transforming cyber risk so rapidly that the threat landscape will look fundamentally different within months. Most of the coverage that followed focused on the threat itself – how AI is lowering barriers for attackers, accelerating exploitation of vulnerabilities and enabling attacks at a scale and speed that defenders are struggling to match.
But what happens to an organisation after an AI-driven attack succeeds? Not in the immediate hours of incident response, but in the weeks and months that follow, when the regulators come knocking and the legal consequences begin to take shape. That is where the real exposure sits for many organisations, and it is where AI changes the picture in ways most boards have not completely thought through.
Why AI makes the aftermath harder
When an attack occurs, organisations face an immediate obligation. Getting the forensic facts right, quickly, is critical. Getting them wrong, or notifying too late, can significantly affect the size of a subsequent fine.
AI-driven attacks make that assessment considerably harder. They move faster, operate at greater scale and are specifically designed to blend into normal user behaviour. Investigators examining a compromised environment may struggle to distinguish between legitimate employee activity, attacker activity and automated AI agents acting through stolen credentials. Traditional security controls may not generate obvious alerts as evidence can be fragmented across multiple systems or minimised by evasion techniques built into the attack itself.
By the time an organisation’s incident response team has contained the breach, reconstructing a coherent timeline of what was accessed, by whom and when, has become a significantly more complex and time-consuming exercise. That timeline is exactly what a regulator will ask for.
What regulators actually look for
When a breach occurs, regulators will examine the specific controls that were in place at the time of the attack, assess whether those controls met the relevant standards, and evaluate whether the organisation can evidence its decisions. Recent research found that only 53% of security leaders feel prepared to defend against AI-enabled adversaries, even though 45% expect AI-powered attacks to affect their organisations within the next 12 months. That preparedness gap affects not only the organisation’s ability to defend itself but also its ability to account for itself afterwards.
Under GDPR, the 72-hour notification window is not triggered solely by confirmed data exfiltration. While proof of data staging (data being collated in one place) or evidence from firewall logs (or fin the case of business email compromise, evidence of mailbox exfiltration or synchronisation) is strong indication of a notifiable breach, it can also be triggered by other evidence. The ICO has previously fined organisations that failed to notify a breach on time, even where forensic analysis found no proof of data leaving the network. In one reported case, an organisation concluded it did not need to report to the regulator since logs showed no proof of egress. Yet forty-three days later, data surfaced on the dark web, and the regulator ultimately concluded that the loss of personal data was itself notifiable, regardless of what the logs showed.
This is why lawyers and technical incident response teams need to work closely together from the start. The Digital Forensics and Incident Response (commonly known as “DFIR”) team establishes the technical and digital facts. Lawyers then interpret what those facts mean for reporting obligations. Making assumptions about which facts matter most to a regulator, without that joint analysis, is where organisations get into difficulty.
Regulators are incorporating specific industry frameworks into their enforcement decisions such as ISO 27001, the NIST Cybersecurity Framework, and sector-specific guidance, thereby giving those standards the force of law in practice. The guidance on security controls in the Five Eyes call to action is in line with that precedent and may, in time, become part of that body of precedent.
Building a narrative, not just a defence
One of the most underappreciated aspects of regulatory exposure is the ability to retroactively build a coherent narrative of the organisation’s security and risk management posture. When a regulator investigates, they need to build a picture of the organisation at the moment of the attack: what data was held, how sensitive it was, how many people it affected, what controls were around it and whether those controls were adequate given what was known at the time. The ability of an organisation to present a narrative that coherently explains their decision making around which controls they did – or did not – have in place is key.
Non-compliance with a particular standard is may not automatically be fatal, but the organisation needs to have documented why a decision was made and what was done to mitigate the risk, where a particular control was not in place (a common issue with legacy systems that many organisations have in their estate). Supplier and third-party contributions to the breach also matter, since regulators can and do issue fines to both controllers and processors depending on how the incident unfolded.
Regulators also pay close attention to whether organisations have acted on their own findings. The ICO’s fine notice in the Capita case cited the failure to share penetration testing takeaways across the organisation and act on them. Therefore, having security assessments carried out is not enough. The findings need to go somewhere and result in action.
What to do now
The Five Eyes warning is specific about the controls organisations need to prioritise: reducing the attack surface, accelerating patching, addressing legacy system risk, strengthening identity and access controls and preparing for incidents on the assumption that they will occur. These are the same controls that regulators cite most frequently in enforcement actions: insufficient MFA, poor network segmentation, weak vulnerability management, and inadequate privilege controls.
The organisations that come through regulatory investigations in the best shape are the ones that treated these controls seriously before the attack, documented their decisions carefully and used expert advisors whose recommendations were grounded in the specific risk profile of the business rather than a standard template. The Five Eyes warning is a useful moment to ask honestly whether that work has been done.

