Artificial intelligence remains far more useful to those launching cyberattacks than to those defending against them, according to a senior figure at Britain's National Cyber Security Centre (NCSC). Dave Chismon, the agency's chief technology officer for architecture, outlined this imbalance in a recent blog post, arguing that the disparity will probably lead to a surge in AI-driven attacks as machine-powered defenses fail to match the pace.

The warning reflects broader anxieties about how artificial intelligence will reshape the cybersecurity landscape. During the summer months, AI models developed by Google, Anthropic, OpenAI and Meta were tested against real-world systems as part of security evaluations. In the majority of instances, these models breached defenses by exploiting straightforward vulnerabilities, such as leveraging previously disclosed login credentials.

In June, the Five Eyes intelligence partnership—which encompasses GCHQ, the parent organization of the NCSC—cautioned that cutting-edge AI systems could fundamentally alter both offensive and defensive cyber capabilities in a matter of months, not years. Comparable warnings have come from other bodies, ranging from the chair of the G20's financial stability board to China's top intelligence official, though the specifics of what such a transformation would entail remain uncertain.

Software vendors have responded by releasing patches at unprecedented volumes since the Five Eyes assessment, yet a corresponding spike in actual cyberattacks has not materialized so far.

Why attackers have the advantage

Chismon grounded his explanation in an observation from security researcher Halvar Flake: "All offensive problems are technical problems, and all defensive problems are political problems." Because offensive operations are fundamentally technical in nature, they produce clear, measurable outcomes—an exploit either succeeds or fails, malware either communicates back to its operator or does not—giving automated systems the kind of unambiguous feedback they require to function effectively.

Defensive operations lack this clarity. Success in defense, Chismon noted, "doesn't always have a clear success state" that would allow an automated system to determine whether an action worked. Moreover, defensive measures operate on live systems that organizations depend on. A miscalculation—such as a security patch that disables the VPN or a firewall rule that disrupts a critical business process—can inflict the very damage the defender sought to prevent.

Because the stakes are so high and success is so difficult to quantify, human judgment must guide each defensive decision, and someone must take responsibility for the outcome. Chismon noted that some corporate boards would view a system outage caused by a bungled defensive measure the same way they would view one caused by an actual attack, "except that the board can't shout at an attacker over the phone." This reality means defenders "simply cannot put AI to work in the same way attackers can," which Chismon described as "an inconvenient truth."

The NCSC's own AI defense push

The NCSC itself is developing a cyber defense system called Cyber Shield, designed to deploy autonomous AI systems capable of identifying and remediating security vulnerabilities across government infrastructure and critical national systems.

Despite this effort, Chismon acknowledged that defenders have pathways to harness autonomous AI more effectively. He recommended starting with lower-risk applications, such as using AI to distill threat intelligence reports for human analysts to review. The NCSC has published a framework to help organizations evaluate the risk level of any automated security action based on five dimensions: reach, impact, criticality, predictability and reversibility.

Chismon was candid that rendering autonomous defensive systems safe enough for deployment remains an unsolved challenge. The NCSC plans to release an "AI for Cyber Defence" research agenda as part of the Cyber Shield initiative to address these outstanding questions.

For now, Chismon cautioned that autonomous defense technology is not mature enough to be trusted as a primary security layer and that developing it "will take time, effort, and research." In the interim, he stressed that organizations "cannot risk just waiting for agentic defence to roll in and protect them" and must continue strengthening their defenses "the traditional way."