Organizations/government

UK National Cyber Security Centre

11 records11 policyWebsite
Jun 22, 2026
Five Eyes cyber agency heads tell leaders AI is shifting cyber risk on a timescale of months
PolicyGuidanceAustralian Signals Directorate (ACSC), Communications Security Establishment, GCSB

The heads of the Five Eyes cyber agencies issued a joint statement that AI is rapidly transforming cyber risk and that organizations must act within months, not years. They ask leaders to reduce attack surface, accelerate patching as exploitation windows shorten, replace unsupported legacy systems, strengthen identity controls, and prepare for incidents.

May 15, 2026
UK NCSC advises incremental agentic AI adoption with minimal, expiring permissions
PolicyGuidanceUK National Cyber Security Centre

NCSC authors advise deploying agentic AI incrementally through tightly bounded pilots, granting agents only the minimum permissions with temporary credentials, and defining in advance who approves access, monitors behavior and can halt the agent. They recommend incident response plans for agent failure and loss-of-control scenarios.

May 11, 2026
UK NCSC issues ten questions for organizations using AI models to find vulnerabilities
PolicyGuidanceUK National Cyber Security Centre

The head of the NCSC's Vulnerability Management Group published ten questions for organizations considering AI-driven vulnerability discovery. The questions stress having a process to triage and fix findings, prioritizing exploitable issues, weighing data, permission, legal and jurisdiction risks of the chosen model, starting with the external attack surface, and planning for future models.

May 1, 2026
CISA, ASD's ACSC and international partners publish joint guidance on careful adoption of agentic AI
PolicyGuidanceCISA, NSA, Australian Signals Directorate (ACSC)

CISA and the Australian Signals Directorate, with US and international partners, published guidance on the cybersecurity risks of agentic AI services and recommended mitigations. CISA highlights expanded attack surface, privilege creep, behavioral misalignment and obscure event records as risks, and recommends avoiding broad access, starting with low-risk use cases, and folding agent security into existing risk models.

Mar 30, 2026
UK NCSC and AISI warn defenders that frontier AI is rapidly improving at simulated enterprise attacks
PolicyGuidanceUK National Cyber Security Centre, UK AI Security Institute

An NCSC technical director and an AI Security Institute researcher wrote that leading models went in about 18 months from barely progressing on a simulated enterprise attack range to completing over half of a 32-step scenario. They urge defenders to prioritize fundamentals such as asset inventory, access control, secure configuration and logging, and to adopt AI carefully for defense. NCSC CEO Richard Horne followed on April 15, 2026, warning that AI will make discovering and exploiting weaknesses easier, faster and cheaper.

Dec 8, 2025
UK NCSC says prompt injection may never be fully mitigated and urges impact reduction
PolicyGuidanceUK National Cyber Security Centre

An NCSC technical director argued that prompt injection differs from SQL injection because LLMs do not separate data from instructions, so it should be treated as a residual confused-deputy risk rather than a patchable bug. The NCSC recommends deterministic safeguards that constrain system actions, dropping an LLM's privileges to those of the party whose content it is processing, and logging full inputs, outputs and tool calls.

Dec 3, 2025
CISA, ASD and partners issue principles for securely integrating AI, including agents, into OT
PolicyGuidanceCISA, Australian Signals Directorate (ACSC), NSA Artificial Intelligence Security Center

CISA and the Australian Signals Directorate, with NSA, FBI and national cyber agencies of Canada, Germany, the Netherlands, New Zealand and the UK, published four principles for integrating AI into operational technology. The guidance explicitly covers machine learning, LLM-based AI and AI agents because of the security and safety challenges they pose in industrial environments.

May 7, 2025
UK NCSC judges AI-assisted vulnerability research is the most significant AI cyber development to 2027
PolicyGuidanceUK National Cyber Security Centre

The NCSC's second assessment judges that AI will almost certainly make elements of intrusion more effective through 2027, with AI-assisted vulnerability research and exploit development the most significant development. It warns that the window between disclosure and exploitation, already days, will shrink further, and judges fully automated end-to-end advanced attacks unlikely before 2027.

Apr 15, 2024
NSA-led Five Eyes guidance on deploying externally developed AI systems securely
PolicyGuidanceNSA Artificial Intelligence Security Center, CISA, FBI

The NSA's Artificial Intelligence Security Center led joint guidance with CISA, the FBI and the national cyber centres of Australia, Canada, New Zealand and the UK on deploying and operating externally developed AI systems. It sets objectives to improve the confidentiality, integrity and availability of AI systems and to mitigate known vulnerabilities, organized around protecting, detecting malicious activity against, and responding to incidents involving AI systems.

Jan 24, 2024
UK NCSC assesses AI will almost certainly increase volume and impact of cyber attacks by 2025
PolicyGuidanceUK National Cyber Security Centre

The NCSC's near-term assessment judged that AI would almost certainly increase the volume and heighten the impact of cyber attacks over the following two years, with uneven effects across actor types. It identified social engineering and reconnaissance as the areas of greatest uplift, and judged that more advanced uses would remain limited to actors with quality data, expertise and resources through 2025.

Nov 27, 2023
UK NCSC and US CISA publish multinational Guidelines for Secure AI System Development
PolicyGuidanceUK National Cyber Security Centre, CISA

The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach.