Ofcom launches engagement on the role of AI in cyber defence

Published: 15 September 2026

Artificial intelligence is rapidly reshaping the cyber security landscape. Frontier AI models can make it easier for malicious actors to identify vulnerabilities, automate elements of attack chains and target critical services by increasing the speed, scale and sophistication of cyber attacks.

Cyber defence is evolving rapidly to meet this challenge. AI-enabled tools can help organisations detect threats more quickly, improve vulnerability management, accelerate incident response and strengthen the resilience of networks and services. Thanks to its probabilistic nature, AI works differently to many other cyber security technologies, so the way cyber security is achieved and assessed will likely need to evolve too.

As the regulator responsible for the security and resilience of the UK's telecommunications and digital infrastructure sectors, Ofcom wants to work with industry to better understand how advances in AI can support cyber defence across critical communications networks and services.

The engagement will explore both the opportunities and challenges associated with AI-enabled cyber security tools, including questions around trust, assurance, accountability and compliance with existing cyber security requirements. Ofcom is also keen to ensure current regulatory frameworks do not include unintended or perceived barriers to the adoption of technologies that could improve security and resilience outcomes.

Ofcom plans to carry out a series of discussions with industry, technical experts and vendors during autumn 2026. Insights from this engagement will inform Ofcom's understanding of how emerging AI technologies interact with existing cyber security principles and regulatory requirements.

Ofcom's aim is to support innovation while maintaining high standards of security and resilience, reflecting our principal duty to further the interests of citizens and consumers by ensuring that trust, assurance and accountability remain central to the protection of critical communications infrastructure.

We expect to publish findings in early 2027.