Skip to main content

Supporting AI adoption for UK cyber defence

We need to collaborate to accelerate AI adoption. Getting there will require time, the development of new capabilities and careful oversight.

Ai button on a blue background

BlackJack3D via Getty Images

As the NCSC’s CEO set out in his letter to the Financial Times last week, AI can ultimately be a good thing for cyber security. In the near term, however, AI is likely to expose weaknesses in organisations that have not taken appropriate steps to secure their systems. That is why the NCSC continues to insist organisations improve their cyber security by implementing basic cyber hygiene.

At the same time, as we recently discussed, the NCSC considers the discovery and development of ways in which AI technologies could enhance cyber defence a priority. There is clear potential across a range of areas, including:

  • threat detection such as enhanced endpoint detection and response.
  • network and system vulnerability discovery, including scanning, penetration testing and red teaming
  • software vulnerability research and remediation, including vulnerability discovery and patching
  • automated system security management, for example within security operations centres (SOCs)
  • incident response automation, supporting faster triage and containment

These developments are promising. But defender adoption will be complex and incremental. Frontier AI tools can perform some tasks extremely well, but they can also be unreliable, difficult to validate, and hard to integrate safely into existing environments. Adoption will take time, require the development of new capabilities and need careful oversight. That's why, as Security Minister Dan Jarvis pointed out during his keynote speech at CYBERUK 2026, we are seeking collaboration to support adoption of AI for cyber defence.

To successfully adopt AI-enabled cyber defence, there are a number of risks and challenges that need to be managed. We highlight these below to encourage future collaboration on how best to support defenders.

  • Authorisations and risk management

    Gaining approval to deploy AI tools and understanding how they change organisational risk. 

  • Legality, policy and permissions

    Ensuring AI operates within the law, within organisational policy and with appropriate human oversight.

  • System Protection / Sandboxing

    Ensuring AI tools are secure by default and cannot themselves introduce harm.

  • Secure system integration

    Safely connecting AI tools into existing systems, workflows and operational processes.

  • Information, IP and data protection risks

    Managing the risk of data or intellectual property being exposed externally.

  • Customers and supply chain

    Recognising that AI-enabled defence (and risk) extends beyond the organisation to suppliers and partners.

  • Efficacy and verification

    Validating that AI tools are performing as intended, and that outputs are accurate and actionable.

  • Responsible action

    AI tools can be better at finding cyber security issues than at reliably implementing responsive actions. Defenders will need to consider how they will manage the output of AI tools.

Due to the complexity of these issues, AI-enabled cyber defence cannot be the sole answer to AI-enabled cyber attackers in the near-term, and implementing basic cyber hygiene must remain the priority. But through working together, we can overcome the above challenges and AI can deliver that ultimate improvement to our cyber defence.

Peter Haigh 
Deputy Chief Technology Officer, NCSC

Written by

Peter Haigh Deputy Chief Technology Officer, NCSC