# AI is set to help cyber attackers much more than defenders, says UK official

> Source: <https://therecord.media/ai-set-to-help-attackers-more-than-defenders>
> Published: 2026-09-22 13:05:00+00:00

# AI is set to help cyber attackers much more than defenders, says UK official

Defenders cannot yet put artificial intelligence to work as freely as attackers can, a senior official at Britain's National Cyber Security Centre (NCSC) warned Monday.

 Dave Chismon, the NCSC’s chief technology officer for architecture, said in a [blog post](https://www.ncsc.gov.uk/blogs/one-does-not-simply-defend-agentically) this imbalance means AI-enabled cyberattacks would likely grow as automated defenses struggle to keep pace. 

His warning comes amid concerns about the kind of cybersecurity future AI will lead to. Over the summer, models from Google, Anthropic, OpenAI and Meta reached real-world systems during security evaluations. In most of these cases the models got in through basic means, including reusing exposed credentials.

In June, the Five Eyes intelligence alliance — which includes GCHQ, the agency NCSC is part of — warned that frontier AI could transform offensive and defensive cyber operations within months rather than years.

 Similar concerns have been expressed by other authorities — from the chair of the G20’s [financial stability board](https://therecord.media/cyber-risk-from-frontier-ai-most-immediate-concern-to-global-finance) through to the Chinese Communist Party’s [top intelligence official](https://therecord.media/china-spy-chief-warns-of-us-ai-models) — but the nature of the “fundamental transformation” remains unclear. 

While software makers have in the months since the Five Eyes warning issued patches at record rates, a comparable rise in cyberattacks has not yet been observed.

Chismon’s argument regarding why AI favors attackers opened with a maxim he cited from security researcher Halvar Flake: “All offensive problems are technical problems, and all defensive problems are political problems.”

As it is largely technical, attackers’ work has a clear measure of success, Chismon wrote — an exploit works, or malware “calls home” — providing the kind of unambiguous signal of success that automated tools handle well.

Defensive work offers no such signal, he added, explaining it “doesn't always have a clear success state” to tell an automated system whether it worked.

And unlike attacks, which may simply fail to be successful, defensive actions are taken on the live systems they’re trying to protect. A wrong move — for instance a patch that takes down the VPN, or a firewall rule that breaks a business function — can cause the very disruption the defender was trying to prevent.

Chismon wrote that as the downside is so steep, and success is so hard to measure, a human has to weigh each action and answer for it. Some board members, he added, would see little difference between an attack that takes down a company's IT and a botched defensive action that does the same, “except that the board can’t shout at an attacker over the phone.”

As such defenders “simply cannot put AI to work in the same way attackers can,” Chismon wrote, calling it “an inconvenient truth.”

 His comments come as the agency itself builds a cyber defense capability, called [Cyber Shield](https://therecord.media/britain-plans-autonomous-ai-cyber-shield), that intends to deploy agentic AI systems to discover and fix cybersecurity weaknesses across government networks and critical national infrastructure. 

Still, Chismon wrote, “there’s much [defenders] can do to unlock the potential of agentic cyber defence.” Organizations should start with low-risk uses, he said, such as having AI summarize threat intelligence for human analysts. The NCSC blog provides a framework helping defenders judge the risk of automation by its reach, impact, criticality, predictability and reversibility.

But he acknowledged that making autonomous defensive actions safe enough to deploy remains an unsolved problem. As part of the Cyber Shield effort, the agency will soon publish an “AI for Cyber Defence” research agenda to help find the answers to those problems.

Chismon cautioned that, at the moment, agentic defense is not ready to be relied on and that building it “will take time, effort, and research.” In the meantime, he wrote, organizations “cannot risk just waiting for agentic defence to roll in and protect them” and should keep improving their security “the traditional way.”

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
