
Britain’s National Cyber Security Centre (NCSC) published a warning Monday that AI is structurally better suited to helping cyber attackers than cyber defenders — and that this imbalance is set to grow. The warning came from Dave Chismon, the NCSC’s chief technology officer for architecture, in a blog post titled “One Does Not Simply Defend Agentically.”
Chismon’s argument draws on a maxim from security researcher Halvar Flake: “All offensive problems are technical problems, and all defensive problems are political problems.” On the offensive side, success is unambiguous — an exploit fires, a payload calls home. That clean signal lets automated tools know immediately whether they’ve succeeded, which is exactly what makes agentic AI useful in attack chains. Defenders face the opposite problem: a misconfigured firewall rule, a patch that takes down a VPN, or an automated response that blocks a legitimate user can cause the very disruption defenders are trying to prevent — and there’s no equivalent “did it work?” signal to keep an AI agent on track. The NCSC’s concern is that this asymmetry will deepen as frontier AI models become more capable. Over the summer, models from Google, Anthropic, OpenAI, and Meta were tested against real systems in security evaluations and gained initial access in some cases — often through basic means like reused credentials. In June, the Five Eyes intelligence alliance warned that AI could transform offensive and defensive cyber operations within months rather than years.
