NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 24 of 32
Artificial intelligence

Over the past year, the NCSC has significantly advanced its work in artificial intelligence, focusing on securing AI systems, enabling autonomous cyber defence, and deepening collaboration across government, academia, and industry. This period marked the first full operational year of the Laboratory for AI Security Research (LASR), the publication of the AI Security Code of Practice, and major progress in understanding the potential of agentic AI for cyber defence.
Securing AI systems and establishing standards
A cornerstone achievement was the publication of the AI Security Code of Practice, developed jointly with DSIT. This led to the development of the first global standard that sets minimum security requirements across the entire AI life cycle for all stakeholders in the AI supply chain, published by the European Telecommunications Standards Institute (ETSI). The Code of Practice builds on the NCSC’s Guidelines for secure AI system development, and has been widely adopted across sectors and internationally endorsed by 18 countries.
The NCSC contributed to workshops and consultations with stakeholders such as the Coalition for Secure AI, the Financial Conduct Authority and the G7, helping shape global approaches to AI security, including Software Bills of Materials (SBOMs) for AI and conformity assessments.
Deliveries from LASR and research partnerships
The Laboratory for AI Security Research (LASR) has become a central pillar of the UK’s AI security ecosystem, and the NCSC has played a leading role in its establishment, direction, and delivery. As the primary government sponsor and technical lead, the NCSC has shaped LASR’s research agenda, coordinated cross-sector engagement, and ensured alignment with national cyber defence priorities.
The first year of LASR saw the delivery of impactful research from partners including the Alan Turing Institute, Queen’s University Belfast, Lancaster University, and others. Key outputs included:
- research into secure federated learning, and adversarial patch mitigation
- a novel taxonomy of attacks and defences on AI systems, enabling systematic gap analysis
- the launch of an AI Security Demonstrator with Cisco, focused on CNI scenarios
- a new heatmap tool to visualise LASR research activity and identify priority areas
Other research partnerships supported the development of an agentic AI demonstrator for automated Sigma rule generation and refinement, and contributed to defensive AI red-teaming research, helping shape future cyber defence scenarios.
Human-AI collaboration and teaming
Recognising the importance of effective Human-AI teaming, the NCSC produced a dedicated problem book on Human-AI Collaboration for Cyber Defence, outlining research priorities and identifying potential collaborators. The BLUE HAI project from Lancaster University delivered a blueprint for dynamic task allocation in mixed teams, while other initiatives explored emotional and behavioural responses to AI in high-stakes environments.
Autonomous cyber defence
The NCSC has made major strides in autonomous cyber defence, supporting the development of AI agents capable of defending networks with minimal human intervention. A foundational research plan, developed with MITRE and the Turing Institute, sets out a roadmap for experiments in evaluation, explainability, assurance, and adversary modelling.
Real-world experimentation platforms such as R3ACE and CAGE-Challenge-2 have enabled testing of reinforcement learning agents in dynamic environments. Collaborations with the Dstl ARCD programme, US National Labs, and international partners have provided high-quality datasets and experimental frameworks for advancing autonomous defence capabilities.
Agentic AI
A key strategic focus this year has been agentic AI systems that exhibit autonomous decision-making capabilities, including the ability to perceive, reason, act, and learn independently. These systems can operate without direct human oversight, pursue goals, and adapt to changing environments. While agentic AI offers powerful capabilities for cyber defence, it also introduces new risks related to control, alignment, and misuse.
The NCSC has:
- provided feedback on the OWASP Top-10 for Agentic AI Security
- participated in the Agentic AI Security Forum
- engaged with leading labs such as Anthropic, Google DeepMind, and Palo Alto Networks to define cyber risk thresholds and safeguards for frontier models
Joint exercises with Cybersecurity and Infrastructure Security Agency (CISA), the FCA, and the NSA explored the use of agentic AI in automating incident response and red/blue agent testing.
Research into multi-agent platforms for cyber security decision-making, iterative threat detection, and adversary emulation continues to push the boundaries of what is possible in AI-enabled defence. The NCSC remains committed to ensuring that agentic AI is deployed securely and responsibly, with robust safeguards and clear operational oversight.