UK warns AI gives hackers an advantage over defenders
Cybersecurity teams can’t use AI as freely as their adversaries do.

AI hackers. By GettyImages
- The UK’s NCSC says attackers can use AI more freely than cybersecurity teams.
- AI-enabled attacks are likely to grow as automated defenses struggle to keep pace.
- Agentic AI can help defenders, but greater autonomy can raise the risk of mistakes.
- Organizations should assess control, scope, predictability, and reversibility before deploying AI defenses.
Hackers and other threat actors are unrestrained in putting artificial intelligence (AI) to work, unlike cybersecurity defenders who must navigate organizational policies.
According to the UK’s National Cyber Security Centre (NCSC), defenders can’t simply fight AI-powered cyberattacks by deploying autonomous systems of their own.
In a blog post, NCSC’s Chief Technology Officer (CTO) Dave Chismon states that defending against AI-fueled cyberattacks is a fundamentally different challenge from launching them.
This imbalance means that AI-enabled cyberattacks are likely to grow as automated defenses struggle to keep pace.
“Defenders simply cannot put AI to work in the same way attackers can,”Chismon says.
“For attackers, their core purpose is ‘to conduct cyber offense,’ and success will cause their employer to profit. Whether that’s stealing money from organizations, extorting victims, or exfiltrating information.”
“For the defenders, their mission is to help their organization avoid loss. Cyber defense is effectively ‘a cost of doing business’, one of many priorities that the organization has to manage.”
Chismon calls this “an inconvenient truth,” but there’s a way cybersecurity experts can make better use of AI in securing the digital environment of their employer. And that’s by taking a more controlled approach to agentic AI.
Agentic AI is a system capable of planning and carrying out cybersecurity tasks with limited human intervention. As cyberattacks become more autonomous and nearly fully automated, agentic AI is becoming increasingly more relevant to cybersecurity.
However, allowing agentic AI greater control over security tasks that humans would normally conduct could increase the risks and potential consequences of a mistake.
Organizations should discuss this before investing in AI-enabled cybersecurity defenses. Factors such as an AI system’s level of control, the scope of its actions, the importance of affected systems, the predictability of its behavior, and the ability to reverse an action should all be considered.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Chismon’s warning comes amidst concerns about AI attacking other companies. AI models from Google, Anthropic, OpenAI, and Meta breached their sandboxes during cybersecurity testing, connected to the internet, and attacked third-party companies by exploiting security vulnerabilities in their services.
Industry leaders and prominent citizens, including OpenAI’s CEO Sam Altman and former US President Barack Obama, have suggested slowing down the development of advanced AI technology because it’s moving extremely quickly in private hands and could be “dangerous” if not managed properly.
President Donald Trump, on the other hand, had suggested that slowing down isn’t an option if the United States wants to remain the industry leader.
“We’re leading China in AI. We're the most sophisticated country in the world, and frankly, I want to keep it that way because whoever wins AI wins,” President Trump told reporters at his Ireland golf course earlier this month.