The UK’s National Cyber Security Centre has warned that recent incidents involving frontier artificial intelligence models carrying out unauthorised actions and exhibiting what it described as human-like deceptive behaviour demonstrate the need for stronger safeguards and continuous oversight, the UK Defence Journal understands.
The NCSC issued the statement on 4 August in response to recent incidents arising from evaluations of advanced AI systems operating on the open internet.
The agency did not discuss individual cases in the statement, instead concentrating on the wider security implications of increasingly capable AI models being allowed to interact with external systems and online services.
Ollie Whitehouse, Chief Technology Officer at the NCSC, said, as quoted in a news update: “Recent incidents of frontier AI models carrying out unsanctioned actions and, in some cases, human-like deceptive behaviour on the open internet are a serious reminder of the risks AI capabilities pose.”
Frontier AI generally refers to the most capable general-purpose models available or under development, particularly systems whose abilities may extend into areas such as autonomous decision-making, software development, cyber operations and interaction with external tools.
The security implications become more complex when models operate as agents rather than producing responses solely in a controlled interface. Agentic systems can be granted access to software tools, online accounts, files or other services and may be able to perform sequences of actions with reduced human intervention.
Whitehouse said safeguards should be incorporated into such systems from the beginning rather than relying solely on identifying problems after they occur.
“These technologies must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens. Relying on detection alone after the fact of an incident will not be enough,” he said.
The NCSC, which is part of GCHQ, is responsible for providing cyber security guidance to government, businesses and the public while supporting the UK’s response to major cyber incidents. Its work increasingly includes security questions arising from the deployment of artificial intelligence.
The agency has previously published guidelines for secure AI system development, covering the design, development, deployment and operation of systems incorporating artificial intelligence.
Those principles include securing supply chains, controlling access to models and infrastructure, protecting sensitive data and considering security throughout the lifecycle of an AI system.
The NCSC has also urged organisations to consider carefully how agentic AI is deployed. Systems capable of independently planning and executing tasks can introduce different security risks from conventional software because their behaviour may depend on model outputs that are probabilistic rather than fully predetermined.
Potential controls include restricting the tools and data available to an AI agent, defining limits on the actions it can perform, monitoring its activity in real time and ensuring that human operators can intervene when required.
Whitehouse added: “As AI continues to evolve and create both opportunities and challenges, following established evidenced cyber security fundamentals, as set out by the NCSC’s guidance, remains essential to maintaining trust, resilience, and a defensive advantage in the AI era.”
The NCSC maintains separate guidance on frontier AI security and associated risks, alongside advice for organisations considering the adoption of autonomous and agent-based systems.











