The UK’s National Cyber Security Centre (NCSC) has outlined why artificial intelligence may be adopted differently by cyber defenders than by attackers, arguing that organisational risk and accountability remain major constraints on autonomous security operations.
In a blog post, the NCSC’s Dave Chismon said offensive cyber activity often involves technical challenges with relatively clear measures of success, such as exploiting a vulnerability or bypassing detection. Defenders, by contrast, must consider the potential operational impact of any action they take, including whether a patch, firewall change or system scan could disrupt essential business services.
This distinction means organisations cannot simply deploy agentic AI tools to make defensive changes without oversight. Security teams operate within budgets, change-management processes, legal requirements and competing business priorities, the post said. An automated response that accidentally interrupts services may be viewed as seriously as a disruptive external attack by organisational leadership.
Automation requires defined boundaries
The NCSC said AI can still offer substantial value in cyber defence when used within carefully established constraints. It highlighted activities that are technical in nature, including vulnerability discovery, penetration testing and security monitoring, as areas where automation can assist defenders.
However, such capabilities generally require significant preparation before they become routine. For example, organisations may need to establish confidence that vulnerability scans will not affect production systems, or agree policies and data-sharing arrangements before building a security operations centre.
Once detection processes are in place, the findings are typically passed to people responsible for remediation, such as software developers, system owners and incident response teams. The approach reflects a broader model in which technology identifies potential issues while humans retain responsibility for consequential decisions.
- Detection technologies should be designed to avoid harming business operations.
- Automated actions should have narrow, well-understood scope.
- Human teams should remain accountable for higher-impact remediation and response decisions.
The post referenced research on autonomous cyber defence commissioned by the NCSC and conducted by the Centre for Emerging Technology and Security. The research found that organisations have differing levels of comfort with AI-driven security activity. The NCSC’s analysis suggests that successful agentic defence will depend less on matching attackers’ autonomy and more on deploying automation where its authority, risks and expected outcomes are clearly defined.
