Site navigation

AI Ushering in A “Digital Divide” in Cybersecurity, NCSC Warns

Elizabeth Greenberg

,

ai cybersecurity digital divide NCSC
GCHQ’s National Cyber Security Centre warns a ‘digital divide’ between organisations that can keep pace with AI-enabled threats and those that cannot is set to heighten the UK’s overall cyber risk.

Over the next two years, a growing divide will emerge between organisations that can keep pace with AI-enabled threats and those that fall behind – exposing them to greater risk and intensifying the overall threat to the UK’s digital infrastructure, cyber chiefs warn.

A new report from Pat McFadden, the chancellor of the Duchy of Lancaster, outlines how AI will impact the cyber threat landscape from now to 2027, highlighting how AI will almost certainly continue to make elements of cyber intrusion operations more effective and efficient.

It warns that, by 2027, AI-enabled tools are set to enhance threat actors’ ability to exploit known vulnerabilities, adding that whilst the time between the disclosure and exploitation has already shrunk to days, AI will almost certainly reduce this further, posing a challenge for network defenders.

The report also suggests that the growing incorporation of AI models and systems across the UK’s technology base, particularly within critical national infrastructure and where there are insufficient cybersecurity controls, will almost certainly present an increased attack surface and opportunities for adversaries.

As AI technologies become more embedded in business operations, the NCSC is urging organisations to act decisively to strengthen cyber resilience and mitigate against AI-enabled cyber threats.

“We know AI is transforming the cyber threat landscape, expanding attack surfaces, increasing the volume of threats, and accelerating malicious capabilities,” Paul Chichester, NCSC director of operations said.

“While these risks are real, AI also presents a powerful opportunity to enhance the UK’s resilience and drive growth—making it essential for organisations to act.


Recommended reading


“Organisations should implement strong cyber security practices across AI systems and their dependencies and ensure up-to-date defences are in place.”

The integration of AI and connected systems into existing networks requires a renewed focus on fundamental security practices. The NCSC has published a range of advice and guidance to help organisations take action, including by using the Cyber Assessment Framework.

The report also highlights, in the rush to provide new AI models, developers will almost certainly prioritise the speed of developing systems over providing sufficient cybersecurity, increasing the threat from capable state-linked actors and cyber criminals.

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far