A new white paper from the University of Surrey argues that two events in 2026 should force a rethink of how the UK relies on overseas AI to protect its critical national infrastructure. The paper, authored by Professor Alan Woodward of the Surrey Centre for Cyber Security and Dr. Andrew Rogoyski of the Surrey Institute for People-Centred AI, points to the temporary loss of access to advanced American AI models and the growing role of AI in offensive and defensive cyber operations as evidence that a tipping point has arrived.
The trigger for the paper was a June 2026 export control action by the U.S. Department of Commerce, which required licenses before Anthropic could release its two most advanced models outside the United States. Unable to distinguish domestic from foreign users quickly enough, the company disabled the models worldwide, cutting off users in allied nations until the restriction was lifted on July 1. Legal observers noted this marked the first time export controls had reached into a live AI service rather than a physical product such as advanced processors.
Rather than call for the UK to build its own frontier AI, which the authors say is financially out of reach for all but a handful of nations, the paper proposes a middle path built on local deployment, diplomacy, and continued investment in security fundamentals. It lands at a moment when the National Cyber Security Centre has already flagged how quickly AI-assisted attacks are improving, adding urgency to questions about who controls access to the systems the UK depends on.
Why Sovereign AI Control Has Become an Urgent Question #
The authors describe a shift in how governments should think about dependence on foreign-built AI. Rogoyski, director of innovation and partnerships at the Surrey Institute for People-Centred AI, said concerns that had circulated for some time about AI access were confirmed by real events.
“There is a growing realization that frontier AI is becoming highly effective as both attacker and defender of computer networks,” Rogoyski said. “People are worried about whether they can count on having access to such systems. After recent events, it turns out they can’t.”
He argued that attempting to match the United States or China on frontier AI development is not realistic for a country of the UK’s size, given the capital, specialized hardware, and talent those two countries have committed. Instead, he said, a country can still protect itself by running capable, if not cutting-edge, systems domestically.
“Being at the frontier of AI isn’t the only way to stay safe,” Rogoyski said. “A country can run capable systems on its own soil, keep its own data under its own laws and employ people who know how to get the best out of lesser AI systems, all for millions rather than billions.”
Five Recommendations From the Surrey White Paper
The paper sets out five specific steps for policymakers to take, summarized below.
| Recommendation | What it means in practice |
|---|---|
| Deploy AI locally | Prioritize running frontier AI systems within UK infrastructure rather than pursuing domestic frontier development |
| Log the risk formally | Add loss of AI access to national risk registers and government procurement terms |
| Negotiate at government level | Seek access guarantees between governments rather than relying on commercial contracts alone |
| Invest at a realistic scale | Focus spending on AI capability a mid-sized country can sustain, particularly its talent pipeline |
| Maintain security basics | Continue funding fundamental cybersecurity measures, which remain effective even as AI threats evolve |
Fragile Business Models Add a Second Layer of Risk
Beyond government-imposed restrictions, the paper warns that commercial pressures could also cut off access to frontier AI. Rogoyski pointed to concerns about the financial sustainability of AI companies that have relied on very large amounts of investment.
“The business models that underpin frontier AI are fragile and there’s speculation about an AI bubble,” Rogoyski said. “The idea that a service may cease to be available for business reasons is equally concerning for the people building network defense systems with AI.”
The authors also caution that open-weight AI models are not a reliable fallback on their own. They note that the United States has reportedly weighed limiting its own access to Chinese open models to keep enterprises and government departments on U.S.-built systems. If allied governments followed a similar approach, a country’s primary AI supply and its backup option could end up controlled by the same government.
How AI Incidents Are Being Misread #
The paper also addresses a widely covered 2026 incident in which AI models belonging to a U.S. developer, running with misconfigured safety controls in a test environment, reached another company’s live systems. Media coverage described the systems as having “gone rogue,” a framing Woodward rejects.
“There is a version of this story that gets told in headlines and it is not the version the evidence supports,” said Woodward, visiting professor of computer science at the Surrey Centre for Cyber Security. “When AI systems have caused security incidents this year, they were doing exactly what they had been instructed to do, in environments where nobody had enforced any security boundaries, and calling that a rogue machine puts the responsibility in the wrong place. It’s human error, not a malign AI.”
Woodward said the practical lesson is more manageable than the headlines suggest, since organizations do not need to own a frontier model to reduce this kind of risk.
“Containing an AI agent, giving it narrow credentials, segmenting the network around it and keeping the ability to revoke what it can reach, is something any organization can do without owning a frontier model, and a good deal of the near-term risk sits there,” Woodward said.
Offensive AI Capability Is Rising From a Low Base
According to the paper, the National Cyber Security Centre reported in March 2026 that over an 18-month period, leading public AI models went from making almost no progress on a simulated attack against a company network to completing more than half of the steps needed for a successful hack, at a cost of around £65 per attempt.
The authors stress, however, that documented AI-assisted campaigns so far have exploited unpatched systems, default credentials, and services left exposed to the internet, rather than discovering entirely new methods of breaching well-secured networks. Their conclusion is that AI currently increases the speed and scale at which existing weaknesses are exploited rather than creating new ones. For a country with constrained resources, they argue, spending on raising the baseline security of critical infrastructure delivers more protection today than spending the same amount on training an advanced AI model.
The UK’s Position: Strong Research, Weak Frontier Capacity
The white paper singles out the UK as a useful case study because it combines strong AI research credentials, including its role as the birthplace of Google DeepMind, with well-established cybersecurity institutions but no native frontier AI development of its own.
“Britain is an interesting test case because we are about as well-placed as a country dependent on overseas frontier AI can be,” Rogoyski said. “We have real research strength and long-established security institutions, but the most advanced frontier AI systems are still American or Chinese. When these AI systems are suddenly withdrawn, we’re in a vulnerable position.”
Rogoyski added that existing UK institutions, including the AI Security Institute and the NCSC, provide a foundation, but that the country’s academic talent pipeline is its most distinctive asset. Woodward argued that the missing piece is diplomacy.
“What the UK’s approach does not cover is the diplomacy, and that is where the work now needs to go,” Woodward said. “Government should be pressing Washington for published criteria before access is restricted, advance warning and exemptions for allies, as we already handle security of supply in energy and defense. At home, it should require critical infrastructure operators to keep their AI running in British data centers, because continued access is something you negotiate for rather than something you can buy.”
A Precedent From Satellite Navigation
The authors draw a parallel to satellite navigation, where the mere possibility that the United States could deny access to the GPS signal was enough to drive other powers to build their own systems: Europe’s Galileo, Russia’s revived GLONASS, and China’s BeiDou. They argue that unexplained restrictions on AI access could prompt similar costly duplication among allied nations, even those with close ties to the United States.