From AI ally to adversary: Why securing AI can’t wait 

Countless news stories, reports and social posts are published about AI daily – hopscotching between opportunities, threats, studies and more. Over the past week alone, we’ve seen reports suggesting AI… will cure cancer; could kill all humans in the next decade; is causing workers to reconsider career paths.

Once the preserve of computer scientists and researchers, modern AI has increasingly been normalised in workplace platforms and consumer products. But it’s much more than a productivity tool, AI is increasingly embedded within government initiatives and critical systems to deliver essential efficiencies, such as predictive maintenance and process automation, while security advances include accelerated threat detection and response.

These themes have just been reinforced by Martin McCluskey, Minister for Local Energy and Jobs, who stated on Tuesday 8th September: “AI has a fundamental part to play not just in modernising our energy system, but in allowing our industries to compete globally and in protecting our national security.” 

Contextualising where AI fits into energy, he said: “The grid today is managing millions of decentralised energy generating assets from small- to large-scale and the only way we can handle that generation and demand in real-time is through using AI.” 

The minister acknowledged risks of introducing more AI to this sector, noting the Department for Energy Security and Net Zero will launch an AI in Energy Strategy next year and conduct an independent review of AI deployment in UK electricity networks. 

Energy is just one of 13 critical national infrastructure (CNI) sectors recognised in the UK, including government itself, health, defence, water and more, which demonstrates how wide the scope for AI adoption is – and why securing AI can’t wait.

Spotlight on AI security 

The UK government has introduced various initiatives – such as the 2017 Industrial Strategy and 2021 National AI Strategy – to “boost the UK’s global position as a leader in developing AI technologies”. 

And in 2023, the global AI Safety Summit was launched then-Prime Minister Rishi Sunak to “embrace the extraordinary opportunities of artificial intelligence… tackle the risks to ensure it develops safely in the years ahead”. 

But AI security, the intersection of AI and cyber security that keeps AI models, data and infrastructure protected from attacks, also needs to remain under the spotlight as the country and society at large continues chasing development and “extraordinary opportunities”. 

Government research organisation, the AI Security Institute, is a key fixture in this area. Its focus is to test the security of AI systems before they receive public release and keep policymakers updated with developments to ensure risks and capabilities can be defended against or managed as necessary. 

The threat to AI security is so severe, GCHQ’s Cyber Shield is “a new national cyber defence capability that will hardwire cutting-edge agentic AI into machine speed cyber defence”. According to GCHQ Director General Anne Keast-Butler: “We need to reimagine cyber security in the AI world.” 

There’s no shortage of frontier AI options for organisations and individuals to choose from, be that Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini or otherwise. Then there’s players outside the US, such as China’s DeepSeek and Kimi K3 from Moonshot AI, which “can rival top American firms”.  

As these AI capabilities advance, the UK government has its AI Opportunities Action Plan in place to signpost how the technology can upskill workers, assist healthcare and supercharge the economy. But on the flipside, these developments can also empower cyber criminals. 

Bill Gates recently voiced his fears about this rapid rate of AI advancement. “The smartest cyber security experts I know are scared about the next few years, because the attackers are getting powerful new capabilities faster than the defenders can fix all the weaknesses,” he wrote. “After all, the same AI model that can find a flaw in software so a company can fix it can also help a criminal exploit it.” 

Government’s evolving embrace 

The new UK Government continues to position AI as a centrepiece of its objectives. As Prime Minister Andy Burnham took over from Keir Starmer, AI was instantly positioned as a priority.  

“AI is likely the most significant technology in human history,” said Kanishka Narayan MP, who was appointed Minister for Artificial Intelligence. “That is why it is now at the UK Cabinet’s table, so we can reindustrialise with AI, secure our country and support our public services.“ Simultaneously, the government’s AI Taskforce plans to “unlock growth and prosperity across the country”. 

Business buy-in is key to “unlock growth and prosperity across the country” and use of AI in UK businesses with ten or more employees grew from 12% to 35% between 2023 and 2026, according to the Office for National Statistics (ONS). This fell to 28% for businesses with under ten staff but spiked to 49% for firms with 250 or more staff. 

Even so, the average number of AI technologies used per business climbed just slightly from 1.4 to 1.6, with top barriers including difficulty identifying business use cases, cost and a lack of expertise. 

British AI innovations themselves tell a different story. UK-founded DeepMind, acquired by Google for £400m in 2014 to mark a milestone moment as the tech firm’s largest European deal, was spotlighted in the AI Opportunities Action Plan for winning the Nobel Prize. 

And seemingly there’s no shortage of AI startups looking to follow the footsteps of DeepMind, nor lack of VCs keen to back talented companies, as funding in UK AI businesses hit £7.1bn in H1 2026 – a 360% year-on-year growth.  

Couple that private investment with fresh public sector cash, which arrives in the form of a £100m competition from government’s Sovereign AI fund to back British AI startups tackling societal challenges, and there’s plenty of incentives to keep developing. 

So, while we’re on the path to “reindustrialise with AI”, security remains a must – especially with so much expectation that these investments will deliver for the UK economy.

Moving forward with a LASR focus 

Since 2024, Plexal has been part of the Laboratory for AI Security Research (LASR), which brings together academia, industry and government to advance UK leadership in AI security research. 

Within this public-private collaboration, we’re leading LASR’s engagement with industry – big and small, local and global – to address AI security challenges, build confidence and drive adoption.  

Some of the SMEs we’re working with are responsible for solutions such as AI system monitoring and compliance; agentic AI controls; AI assurance and supply chain security. 

In Plexal’s new report, Attacks to Resilience: AI in Critical Infrastructure, supported by Microsoft and LASR, we’ve explored security risks from adversarial AI and AI adoption up close.  
 
Darren Lewis, Senior Innovation Lead at Plexal, said: “Although AI has the potential to introduce novel risks, it also represents a transformational opportunity for CNI organisations to strengthen resilience, modernise operations and improve cyber defence at scale and speed.  
 
“When deployed with proactive governance, security-by-design principles and robust oversight, AI can provide several benefits including situational awareness, predictive insights, automated threat detection and faster incident response across complex environments and legacy infrastructure.” 

As AI capabilities become more powerful and accessible, the UK needs an AI security ecosystem with equal strength – and we’re seeing the benefits first-hand through our role in LASR. 

Dave Rowley, CCO at Plexal, added: “We’re seeing strong momentum across the AI market, from rising business adoption to significant public and private investment. But that momentum is also creating new demand for the technologies, expertise and partnerships that can make AI secure and dependable at scale. 

“Meeting that demand will help more organisations adopt AI with confidence, create growth opportunities for British security companies and strengthen the resilience of the services and infrastructure the country depends on.”