UK GCHQ develops AI-enabled national cyber defence capability to protect critical infrastructure

UK GCHQ develops AI-enabled national cyber defence capability to protect critical infrastructure

UK intelligence officials are developing what is believed to be the world’s first national AI-enabled cyber defence capability to help identify and respond to threats targeting critical infrastructure sectors.

The UK’s GCHQ is developing what is described as a national AI-enabled cyber defence capability designed to help detect and respond to threats targeting critical infrastructure sectors including telecommunications, airlines, utilities and major businesses, believed to be the first of its kind.

The system would use agentic AI to identify suspicious activity and accelerate cyber response operations across national infrastructure environments.

GCHQ Director Anne Keast-Butler said the UK and its allies face a “narrowing window” to maintain technological advantages amid rapid advances in artificial intelligence, quantum computing and cyber capabilities. During a speech at Bletchley Park, she warned that Russia is increasing “daily hybrid activity” against the UK and Europe, including cyberattacks, infrastructure targeting and disruption operations.

The proposed cyber defence system could take up to five years to fully deploy and is intended to improve visibility and response speed across critical sectors. Keast-Butler also urged organizations and individuals to strengthen baseline cybersecurity protections as AI-enabled cyber threats continue evolving.

Experts with Xcape, Inc., Suzu Labs and Finite State offer perspectives on the matter.

Damon Small, Board of Directors, Xcape, Inc.:

“The national AI shield by GCHQ marks the official end of human-centric cyber defence for critical infrastructure, signaling a global shift toward a high-stakes game of algorithmic warfare. By openly pivoting to agentic AI, the UK intelligence community is acknowledging a brutal mathematical reality: when nation-states utilize automated, machine-speed algorithms to probe and disrupt networks, relying on human analysts to manually triage alerts is an exercise in structural defeat.

“However, anyone wondering how long before the US takes a similar approach is looking at the wrong playbook. The US isn’t waiting – it is already executing a parallel strategy, albeit through a highly distributed model rather than a single centralized shield. Through DARPA’s AI Cyber Challenge (AIxCC), the US military has spent the last two years piloting fully autonomous Cyber Reasoning Systems designed to find and patch infrastructure flaws at machine speed, while the White House’s recent OMB Memorandum M-26-14 mandates a centralized, AI-enhanced telemetry architecture across federal networks.

“For enterprise risk leaders, the primary takeaway is that the ‘narrowing window’ GCHQ warns about is already closing. While governments spend the next few years scaling these automated umbrellas, critical infrastructure remains under daily, aggressive bombardment from hybrid operations. Security executives cannot afford to treat these state-level announcements as a reason to pass the buck; instead, they must treat them as an urgent mandate to heavily automate their own internal threat-hunting loops, enforce immediate isolation of legacy operational technology and dramatically harden their systems before the machines take over the board entirely.

Critical takeaways:

• “Fighting fire with algorithmic fire: State-sponsored adversaries are already using AI to find vulnerabilities and execute multi-vector hybrid campaigns; matching them requires deploying autonomous, agentic AI capable of countering threats without waiting for human committee approval.

• “The distributed US counterweight: While the UK builds a top-down national capability, the US is using DARPA to pioneer autonomous code-fixing tools and CISA to mandate the massive data-ingestion pipelines required to fuel them.

• “Corporate hygiene cannot be outsourced: National AI shields are aggregate systems; they will completely fail to protect an enterprise if individual corporate boards refuse to fix basic infrastructure vulnerabilities, legacy protocols and unpatched edge devices.

“Deploying agentic AI at a national level means we are finally letting the machines fight the machines…because humans simply cannot move fast enough to defend a modern power grid on a keyboard.

“GCHQ’s five-year roadmap and the US DARPA initiatives prove that the geopolitical arena is shifting from a race of human hacker groups to a full-scale battle of automated algorithms, where the nation with the most resilient, self-healing code wins.”

Jacob Krell, Senior Director: Secure AI Solutions and Cybersecurity, Suzu Labs:

“Hardwiring agentic AI into machine speed cyber defence” is a political statement, not an actionable security plan. GCHQ’s own director acknowledged the cybersecurity message “may sound familiar” given the NCSC is now ten years old, then offered a five-year deployment timeline against threats she described as a “narrowing window” and a “moment of consequence.” The NCSC handles approximately four nationally significant cyberattacks against Britain each week. A blueprint that takes five years to operationalize is not a response to that tempo.

“The gap is governance. The ICO fined South Staffordshire Water earlier this month after investigators found 20 months of undetected adversary access and five percent monitoring coverage. An AI overlay watching five percent of the network is still blind. Critical infrastructure should be architected like a vessel with watertight compartments, where a breach in one section cannot sink the ship. Adversary presence in the IT network should never reach operational technology regardless of who is watching.

“The private sector model taking shape in the US is better suited to the AI era. Organizations including JPMorgan Chase and AT&T launched the Alliance for Critical Infrastructure earlier this year to drive cross sector resilience without waiting for government capacity. Financial accountability and operational speed are decisive advantages when the threat landscape shifts with every model release. A centralized government program on a five year timeline will be obsolete before it is operational.”

Doc McConnell, Head of Policy and Compliance, Finite State:

“I applaud GCHQ for responding with the urgency that this moment deserves. National critical infrastructure is an active battlefield–every government agency, every ISP, every power plant is at risk. New AI models raise the stakes by making attacks simultaneously cheaper and more damaging.

“The greatest risk right now is inaction. GCHQ is taking the right approach by deploying frontier capabilities to disrupt adversarial activity before it can cause harm. This technology is a necessary tool. Like any tool, we must use it safely and responsibly –  but failing to use it at all would also be irresponsible.

“Governments trying to accelerate responsible adoption should engage private-sector collaborators. Cybersecurity companies are rapidly prototyping, identifying and managing risks, and improving the ways that defenders can use these technologies to protect their systems and data.”

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive