Dutch security and law-enforcement authorities have issued a joint warning that artificial intelligence is accelerating and amplifying cyber threats. The statement was published on 24 September by the National Cyber Security Centre together with the NCTV, AIVD, MIVD, Public Prosecution Service, CIO Rijk and the police.
The warning focuses on acceleration, not a new attack category
The agencies say attackers can use readily available AI systems to automate parts of the attack chain, identify vulnerabilities more quickly and improve the efficiency of established techniques. Their public notice does not document a measured new wave of AI-driven incidents. It is a forward-looking risk assessment and a call for organisations to prepare before the effects appear at larger scale.
Three immediate expectations for leaders
The joint statement asks senior leaders to make resources available, prioritise cybersecurity and give specialists room to strengthen resilience. Its three headline actions are to put basic security measures in order, reassess whether the organisation's current level of protection is still appropriate and take signals about AI-enabled threats seriously.
What nonprofit leaders should review
For an NGO, the practical translation starts with an owned asset inventory, supported software, timely security updates, multi-factor authentication, tested backups, incident reporting routes and monitoring that covers outsourced systems. Leaders should also know which services hold beneficiary, donor or staff data and confirm who can isolate those services when suspicious activity appears.
Limits of the evidence
The primary statement is an official Dutch assessment rather than a technical study of attack prevalence. Independent reporting by NL Times confirms the participating authorities and their recommendations, but largely reports the same statement. Organisations should use the warning to review controls, not as evidence that every AI-related threat claim or security product is proven.