NCSC, the UK’s cyber agency, has published an assessment highlighting the impacts on cyber threats from AI developments.
The assessment uses the Professional Heads of Intelligence Assessment (PHIA) probability yardstick to assess probabilities in the following groups:
- Remote Chance
- Highly Unlikely
- Unlikely
- Realistic Possibility
- Likely or Probable
- Highly Likely
- Almost Certain
Key judgements made in the assessment include:
- Artificial intelligence (AI) will almost certainly continue to make elements of cyber intrusion operations more effective and efficient, leading to an increase in frequency and intensity of cyber threats.
- There will almost certainly be a digital divide between systems keeping pace with AI-enabled threats and a large proportion that are more vulnerable, making cyber security at scale increasingly important [through] to 2027 and beyond.
- Assuming a lag, or no change to cyber security mitigations, there is a realistic possibility of critical systems becoming more vulnerable to advanced threat actors by 2027.
- Proliferation of AI-enabled cyber tools will highly likely expand access to AI-enabled intrusion capability to an expanded range of state and non-state actors.
- The growing incorporation of AI models and systems across the UK’s technology base, and particularly within critical national infrastructure (CNI), almost certainly presents an increased attack surface for adversaries to exploit.
- Insufficient cyber security will almost certainly increase opportunity for capable state-linked actors and cyber criminals to misuse AI to support offensive activities.






