Supporting AI adoption for UK cyber defence
We need to collaborate to accelerate AI adoption. Getting there will require time, the development of new capabilities and careful oversight.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
We need to collaborate to accelerate AI adoption. Getting there will require time, the development of new capabilities and careful oversight.

BlackJack3D via Getty Images
As the NCSC’s CEO set out in his letter to the Financial Times last week, AI can ultimately be a good thing for cyber security. In the near term, however, AI is likely to expose weaknesses in organisations that have not taken appropriate steps to secure their systems. That is why the NCSC continues to insist organisations improve their cyber security by implementing basic cyber hygiene.
At the same time, as we recently discussed, the NCSC considers the discovery and development of ways in which AI technologies could enhance cyber defence a priority. There is clear potential across a range of areas, including:
These developments are promising. But defender adoption will be complex and incremental. Frontier AI tools can perform some tasks extremely well, but they can also be unreliable, difficult to validate, and hard to integrate safely into existing environments. Adoption will take time, require the development of new capabilities and need careful oversight. That's why, as Security Minister Dan Jarvis pointed out during his keynote speech at CYBERUK 2026, we are seeking collaboration to support adoption of AI for cyber defence.
To successfully adopt AI-enabled cyber defence, there are a number of risks and challenges that need to be managed. We highlight these below to encourage future collaboration on how best to support defenders.
Gaining approval to deploy AI tools and understanding how they change organisational risk.
Ensuring AI operates within the law, within organisational policy and with appropriate human oversight.
Ensuring AI tools are secure by default and cannot themselves introduce harm.
Safely connecting AI tools into existing systems, workflows and operational processes.
Managing the risk of data or intellectual property being exposed externally.
Recognising that AI-enabled defence (and risk) extends beyond the organisation to suppliers and partners.
Validating that AI tools are performing as intended, and that outputs are accurate and actionable.
AI tools can be better at finding cyber security issues than at reliably implementing responsive actions. Defenders will need to consider how they will manage the output of AI tools.
Due to the complexity of these issues, AI-enabled cyber defence cannot be the sole answer to AI-enabled cyber attackers in the near-term, and implementing basic cyber hygiene must remain the priority. But through working together, we can overcome the above challenges and AI can deliver that ultimate improvement to our cyber defence.


