NCSC warns AI to escalate cyber threats by 2027
NCSC assesses AI will make cyber intrusions more frequent and effective by 2027, widening the attack surface and deepening a security divide between defenders.
The UK's National Cyber Security Centre has published a forward-looking assessment on how artificial intelligence will shape the cyber threat landscape through 2027. The report, building on a January 2024 baseline assessment, concludes that AI will almost certainly make cyber intrusion operations more effective and efficient across reconnaissance, vulnerability research, exploit development, social engineering, malware generation, and data exfiltration—primarily by enhancing existing TTPs rather than creating novel attack vectors. NCSC judges that only the most capable state actors will fully harness AI for advanced operations in the near term, while most other threat groups will repurpose commercial and open-source AI models to uplift their capabilities, and a proliferation of AI-enabled tools will extend intrusion capability to a wider range of state and non-state actors, including cybercriminals offering AI-enabled tools 'as a service' to novices and hacktivists.
A key concern raised is AI-assisted vulnerability research and exploit development (VRED), which is expected to shrink the already narrow window between vulnerability disclosure and exploitation, increasing risk to unpatched systems and particularly to critical national infrastructure (CNI) and its supply chains, including operational technology with weaker security. The report also highlights the growing integration of AI systems into UK technology infrastructure as an expanding attack surface, citing threats such as direct and indirect prompt injection, software vulnerabilities, and supply chain attacks against AI systems themselves, compounded by insecure data handling, weak encryption, and poor identity management.
NCSC anticipates a growing 'digital divide' between organisations that keep pace with AI-enabled defensive capability and those that fall behind, warning that keeping pace with frontier AI will be critical to cyber resilience for the coming decade. While fully automated end-to-end attacks are considered unlikely by 2027, skilled actors are expected to increasingly automate elements of the attack chain—vulnerability exploitation, malware mutation, and infrastructure changes—to evade detection, a human-machine teaming trend that will complicate threat detection and mitigation absent comparable AI-enabled defensive tools.
Source reporting: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free