# NCSC: AI to intensify cyber threats by 2027

Published: 2025-05-07 · Severity: high · Sectors: infrastructure, government-national, financial-services, healthcare, energy, telecommunications, transportation
Canonical: https://vorant.io/reports/88520782-cb96-5c03-9f1e-9e421386bf36/ncsc-ai-to-intensify-cyber-threats-by-2027

> UK NCSC warns AI will increase cyber attack frequency and intensity through 2027, creating a digital divide between protected and vulnerable systems.

The UK National Cyber Security Centre assesses that artificial intelligence will almost certainly make cyber intrusion operations more effective and efficient between now and 2027, leading to increased frequency and intensity of cyber threats. Threat actors are already using AI to enhance reconnaissance, vulnerability research, exploit development, social engineering, malware generation, and data exfiltration. The most significant development will be AI-assisted vulnerability research and exploit development (VRED), which will almost certainly reduce the time between vulnerability disclosure and exploitation from days to even shorter windows, particularly threatening critical national infrastructure and operational technology with lower security levels.

The report identifies a looming digital divide between systems that can keep pace with AI-enabled threats and those that cannot. By 2027, there is a realistic possibility that critical systems will become more vulnerable to advanced threat actors, particularly through enhanced zero-day discovery and exploitation techniques. The proliferation of AI-enabled cyber tools will highly likely expand intrusion capabilities to a wider range of state and non-state actors, including criminal groups offering AI-enabled tools as a service. Meanwhile, the growing incorporation of AI systems across UK infrastructure presents an expanded attack surface through techniques like prompt injection and supply chain attacks.

The NCSC emphasizes that only highly capable state actors will initially harness AI's full potential in advanced operations, while most threat groups will repurpose commercially available and open-source models. Fully automated end-to-end attacks remain unlikely by 2027, with skilled actors still required in the loop. However, human-machine teaming will make threat identification and mitigation more challenging without effective AI-assisted defense. The assessment warns that organizations rushing to deploy AI without prioritizing security—through weak encryption, poor identity management, or insecure configurations—will create opportunities for state-linked actors and criminals to exploit these systems.

Source reporting: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/88520782-cb96-5c03-9f1e-9e421386bf36/ncsc-ai-to-intensify-cyber-threats-by-2027.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
