New Zealand’s National Cyber Security Centre has released its Cyber Threat Report 2026, putting artificial intelligence at the centre of its assessment of the changing cyber threat landscape.
The NCSC says frontier AI is already increasing the speed, scale and sophistication of cyber attacks. More advanced models could make vulnerability discovery, reconnaissance, automated attacks, phishing and highly personalised social engineering substantially easier for malicious actors.
Key facts
- The NCSC’s leading judgement is that AI is rapidly reshaping the cyber landscape.
- It expects advanced AI capabilities currently concentrated in leading frontier models to become more accessible to malicious actors by early 2027.
- AI is already being used to improve phishing, scams and social engineering.
- The NCSC handled 369 incidents of potential national significance during 2025/26.
- 162 were linked to criminal or financially motivated actors, an 18% increase.
- Four incidents were classified as highly significant, equal to the number recorded across the previous ten years combined.
Our take
This is an important shift in how New Zealand organisations should think about AI risk. AI security is no longer just about preventing staff from putting sensitive information into ChatGPT. Organisations also need to prepare for attackers using increasingly capable AI against them.
For boards and executives, that means reviewing incident response plans against faster attacks, shorter vulnerability-to-exploitation windows and more convincing social engineering. The encouraging part of the NCSC’s message is that basic cyber hygiene, good governance and rehearsed incident response remain effective foundations.

