Chronicle/Policy & standards

UK NCSC and AISI warn defenders that frontier AI is rapidly improving at simulated enterprise attacks

PolicyGuidanceSignificance assistant-drafted

An NCSC technical director and an AI Security Institute researcher wrote that leading models went in about 18 months from barely progressing on a simulated enterprise attack range to completing over half of a 32-step scenario. They urge defenders to prioritize fundamentals such as asset inventory, access control, secure configuration and logging, and to adopt AI carefully for defense. NCSC CEO Richard Horne followed on April 15, 2026, warning that AI will make discovering and exploiting weaknesses easier, faster and cheaper.

Why it matters

It pairs government capability measurements with concrete defender priorities at the moment frontier cyber capability became a policy issue.

Key facts

As stated in the sources, with where to find them.

  • Within about 18 months, leading models moved from barely progressing to completing over half of a 32-step simulated enterprise attack, at roughly GBP 65 per attempt.March 30 blog, capability trend
  • On the 32-step scenario the authors estimate would take a human expert about 14 hours, Claude Opus 4.6 averaged 15.6 steps with extended processing time (roughly 6 of the 14 hours) and 9.8 steps without it.March 30 blog
  • Horne's April 15 blog recommends reducing exposure, applying updates rapidly, monitoring and responding quickly, and Cyber Essentials certification.April 15 blog, recommendations

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records