NCSC CTO on sandbox breakouts: Cohesity VP UK&I comments

167 Views

The NCSC is right to highlight that British businesses can no longer rely on detection alone to protect themselves. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t, which is why organisations need to move beyond thinking about AI as just another software tool. These systems must remain observable, auditable and governable throughout their lifecycle.

Safety testing exists to detect unexpected behaviour before deployment. It’s reassuring that unexpected behaviour from AI agents is being discovered in controlled environments, not in production. However, the reality is that AI is already exhibiting uncontrolled behaviour in the enterprise, emerging from optimisation processes rather than explicit programming.

The NCSC’s statement offers British businesses foundational cyber-hygiene advice when it comes to AI agents, but what’s needed now is detailed, step-by-step guidance on how to control the movements of these systems in the enterprise. And, crucially, how to protect the data they interact with.