
Retaining defensive advantage in the age of frontier AI cyber capabilities
As AI accelerates vulnerability discovery, organisations must raise their security baselines to safeguard their cyber security.
The enhanced threat from AI-powered cyber attacks is real, but organisations can use AI to improve defences and embrace opportunities.
Artificial intelligence (AI) is no longer a distant or speculative issue for cyber security. The most advanced AI tools, often referred to as frontier AI, make it easier, faster and cheaper for even low-skilled hackers to carry out sophisticated cyber attacks.
AI is making it easier and faster for criminals to attack those organisations that do not have basic cyber security protections in place.
The NCSC believes that AI will ultimately be a ‘net positive’ for cyber security, but the path to reaching this point requires urgent action now and board-level engagement.
The rise of agentic AI tools (a new class of frontier AI) means organisations need to understand how they are used, and what access they have to systems and data.
Maintaining good cyber security fundamentals remains the best way to protect your organisation from all digital threats, whether those are AI-assisted or not.
Cyber attacks which once required specialist skills (such as writing code, understanding system architecture, or discovering weaknesses in computer systems) can increasingly be automated using AI. This does not fundamentally change cyber risk, but it does increase the speed and scale at which existing weaknesses can be found and exploited.
Agentic AI tools - a new class of frontier AI - go even further and can plan, make decisions and take actions on your behalf.
However, by carefully adopting frontier AI tools, network defenders can retain an advantage over cyber criminals. Technology suppliers are already using AI to identify and fix vulnerabilities in their products and services to protect users from new threats.
Organisations that act now can strengthen their resilience, reduce future disruption and demonstrate to customers, prospects and suppliers that they’re ready to face the future opportunities that AI promises. Those that delay risk exposing their organisation to a wave of vulnerabilities that AI tools are rapidly exploiting.
The NCSC provides guidance to help organisations keep pace with AI developments.
As AI accelerates vulnerability discovery, organisations must raise their security baselines to safeguard their cyber security.
When it comes to using agentic AI, make sure you can walk before you run.
Using Artificial Intelligence to find vulnerabilities can bring added security considerations.
An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.
The following resources have been created by the NCSC for security professionals and the wider technical community.
Defenders can’t use AI in the same way attackers can, but there’s much they can do to unlock the potential of agentic cyber defence.
Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
Organisations must act now to prepare for a wave of patches that will address decades of technical debt.
Understanding the threats and staying ahead of the adversary
If ‘vibe coding’ disrupts the software market like SaaS did 20 years ago, what does this mean for cyber security?
Introducing a common language to improve awareness, threat modelling, and collaboration on AI security
There are crucial differences between prompt and SQL injection which – if not considered – can undermine mitigations.
Frontier AI is a global challenge that requires a global response. Together with international partners across government, industry and academia, we have contributed to the following publications.
Agencies from 18 countries, including the US, endorse new UK-developed guidelines on AI cyber security.
Joint guidance, co-authored by the NCSC with international partners, that explores security challenges and risks posed by agentic AI.
Technical report published by the European Telecommunications Standards Institute (ETSI).
Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems
Content Credentials’ guidance, co-authored with the NSA, seeks to counter the erosion of trust.
Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era
A call to action from the Five Eyes security agencies. The evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.











