An abstract design of a terminal display, warning about a cyber attack. Multiple rows of hexadecimal code are interrupted by red glowing warnings and single character exclamation marks. The image can represent a variety of threats in the digital world: data theft, data leak, security breach, intrusion, anti-virus failure, etc..
23 Jul 2026

The UK Government’s Defensive Cyber Pilot

As cyber threats continue to evolve, the UK Government Cyber Action Plan is driving a more proactive approach to resilience across the public sector through the adoption of emerging technologies and modern risk management strategies. As part of this effort, the UK government recently ran a pilot to test whether frontier AI could help protect public sector systems. The Government Cyber Coordination Centre (GC3), a joint team from the National Cyber Security Centre (NCSC) and the Department for Science, Innovation and Technology (DSIT), led the project alongside the UK AI Security Institute (AISI). The trial moved past theoretical benchmarks into real world application. Over the course of a month, teams used frontier AI to run scans against code repositories across nine government organisations. This was a purely defensive exercise to identify and mitigate vulnerabilities before threat actors could exploit them. It did not involve launching simulated attacks against networks.

What is Frontier AI and What Threats Does it Pose?

Frontier AI describes the newest, most capable AI models available today, such as Claude Mythos and GPT-5.5. These models process vast amounts of information and handle complex, human-like tasks with groundbreaking speed and efficiency. While frontier AI brings major opportunities for defenders, it also carries real risks. Threat actors could use these tools to automate cyber attacks at scale, find zero-day software flaws to exploit, or launch sophisticated threats faster than defenders can respond. As AI rapidly evolves, grasping both its threats and defensive uses is increasingly urgent.

Key Findings

The pilot was successful in highlighted several clear lessons on using AI for defence:

  • Which AI model you choose matters less than how you set it up. The best results came from custom setups, multi-agent pipelines where several AI systems work together and check output, or AI layered on top of traditional rule-based security scanning tools.
  • Humans remain essential – AI models scan code fast but cannot replace human judgment. The most valuable findings still required human experts to break down complex problems and add context the model lacked. Without that human layer, the model produced false alarms and low confidence findings that overwhelmed security teams. 
  • Finding a vulnerability is not the same as fixing it – every flaw the model identifies still needs a human team to patch and remediate it.

In conclusion, the pilot demonstrated that you cannot hand code repositories to a frontier AI model and expect it to detect and fix your security problems on its own. Real resilience requires structured multi-agent pipelines and expert human triage to separate the true vulnerabilities from the noise.

Intertek offers a range of cyber assurance services including AI Red Teaming, Cloud Security Reviews, Crisis Simulations, Cyber Essentials assessments, and regulatory assurance and alignment for IoT and OT systems.

Alex Reid headshot
Alex Reid

Technical Manager at Intertek NTA

Alex has more than 12 years of experience in penetration testing and cybersecurity. Alex has been a CHECK Team Leader for more than 8 years delivering high-quality testing and assurance for clients across a range of industries/sectors and is currently recognised as a Principal Cyber Security Professional by the UK Cyber Security Council (UKCSC).

You may be interested in...