I am today updating the House on the rapidly advancing capabilities of frontier Artificial Intelligence, a series of recent incidents, and the action the Government is taking in response.
Artificial Intelligence is one of the defining technologies of our age. It could drive a new era of economic growth, accelerate breakthroughs in science and medicine, transform public services, and help to strengthen the security of our country. This Government is determined that Britain should seize that opportunity: that we should be a country which develops, deploys, and benefits from the most advanced AI – not one that watches the next technological revolution happen elsewhere.
Seizing that opportunity requires confidence in and understanding of the technology itself. The capabilities of frontier AI models continue to advance rapidly. Frontier AI models are increasingly able to act autonomously, use digital tools, and complete long and complex tasks with little or no human intervention beyond the setting of the task. Testing by the AI Security Institute published in May found that the length of cyber tasks frontier models could reliably complete had doubled every five months since late 2024, with most recent models substantially exceeding that trend.
As the capabilities of these models rapidly advance, our ability to understand, secure, and control these systems must advance with them.
Over the summer, there have been several high-profile cases in which AI agents, whilst carrying out tasks set by humans, undertook consequential actions beyond what their operators intended. These include incidents reported by OpenAI, Anthropic, and the AI Security Institute itself.
In each case, an AI agent was given a task by its operators, usually along with details about its environment or rules on how to complete it. The agent was then left to complete that task, over hours or days, with little or no further human involvement or instruction. How it went about the task was decided by the agent alone. Across the reported incidents, AI agents acted in ways their human operators had not anticipated, including: circumventing technical controls, including in one case exploiting a previously unknown vulnerability to break out of an isolated test environment; gaining access to real-world systems they were not intended to reach; establishing unintended channels of communication to coordinate with other agents (in one case, at a scale of hundreds of agents over several days); and, in some instances, attempting to get real humans to take action in the real world, in ways their operators had not intended, for example uploading malicious code onto the internet.
These incidents should be understood in context. All arose in testing or development environments designed to probe or improve the capability limits of frontier models, in some cases with safeguards deliberately reduced for that purpose, and, in AISI’s case, with internet access enabled by design. In some cases, the environments were misconfigured, the tasks set were impossible to complete as instructed, or models were told they were in a simulation and continued to believe this after reaching the real internet. Existing best practice security measures and technical controls for keeping agentic AI operating within intended limits, as advised by the UK’s National Cyber Security Centre, as well as comprehensive monitoring would have almost certainly prevented these incidents.
Nevertheless, these incidents demonstrate how advances in AI capability can create new security challenges if safeguards do not keep pace. They occurred because highly capable AI models were operating without sufficiently robust controls to contain them. As the capabilities of frontier models continue to advance, the standard of security and oversight techniques required to contain them will advance too. Should AI capabilities advance faster than the techniques to secure, control, or reliably direct them, this could pose a significant risk to public safety and national security.
That is why the Government is already acting.
As part of the Defence Investment Plan, we have committed £115 million to two new programmes: one on AI biosecurity, and one to build a UK Government agentic AI incident response capability. The National Cyber Security Centre published practical advice in August on deploying agentic AI systems securely and is continuing to develop and pioneer formal guidance and standards in this area so businesses and the public can manage the risks and opportunities of AI with confidence. The NCSC is also leading development of Cyber Shield: a longer-term, national-scale and collaborative approach to AI-enabled cyber defence, working with industry to identify and mitigate cyber risk. This sits alongside our wider work to strengthen the country's cyber resilience. Our Cyber Security and Resilience Bill will strengthen the cyber defences of the UK's most critical services, including health, energy and transport, by requiring organisations to identify, manage and mitigate evolving cyber threats, including those enabled by AI. It is complemented by the Government Cyber Action Plan, backed by £210 million to rapidly improve the cyber security and resilience of public services, and by a further £90 million committed over three years to build resilience across the wider economy.
I am working closely with the Security Minister to ensure that the lessons from these incidents inform the continued development of the UK’s cyber-security framework. We will consider whether protections for increasingly autonomous AI systems should be clarified or strengthened through the Cyber Assessment Framework, the forthcoming statutory code of practice or NCSC technical guidance. AISI will provide evidence and technical expertise to support that work.
Alongside this, the work of the AI Security Institute continues.
AISI grew out of the commitments made at Bletchley Park in 2023 and was the first body of its kind anywhere in the world. AISI was established to build a rigorous, scientific understanding of the capabilities of the most advanced AI systems and the risks they may pose; to work with developers to strengthen security and alignment before models are released; and to ground government action and policy in independent evidence, working alongside national experts including the NCSC. Following the detection of its own incident, AISI stopped all relevant activity and carried out an investigation, the results of which it has published. AISI is now strengthening the security of its own evaluation environments, including tighter constraints on internet access, real-time monitoring of evaluations, and stronger model and agent sandboxing, drawing on NCSC advice.
This risk is not confined to those with weak or no defences. In each incident the organisations affected had met cyber security standards in their jurisdictions. That is why we will continue to monitor risks from AI and will step up our efforts where required, working in lockstep with our partners.
As the United Kingdom invests in the capacity to use increasingly powerful AI, we will invest in parallel in the capacity to understand it, to control it, and to recover when something goes wrong. These risks are inherently transnational: the systems involved are developed and deployed across borders, and no country can address them alone, as has been the case in wider technology for the last three decades. The UK will continue to work closely with international partners, including through the AI Security Institute's relationships with counterpart bodies overseas and the National Cyber Security Centre’s peer agencies. We will approach this challenge with both confidence and urgency, ensuring that the UK can harness the benefits of frontier AI while managing the risks responsibly.
https://www.theyworkforyou.com/wms/?id=2026-09-07.hcws314.0
seen at 09:59, 8 September in Written Ministerial Statements.