UK ministers warn businesses on Artificial Intelligence cyber threats

UK ministers have warned that rapidly advancing Artificial Intelligence models are making cyber offence more capable and more accessible. Businesses are being urged to strengthen basic cyber protections and treat cyber risk as a board-level issue.

UK ministers have warned business leaders that the cyber threat landscape is changing as advanced Artificial Intelligence models become capable of work that previously required highly skilled criminals. These systems can identify software weaknesses, write exploit code, and operate at a speed and scale that was previously out of reach. The government said this shift means businesses must change how they prepare for cyber risk, as attackers are likely to target ordinary companies as well as government systems and critical infrastructure.

Recent testing has sharpened that warning. Last week, Anthropic announced a new model called Mythos. Testing by DSIT’s AI Security Institute found it to be substantially more capable at cyber offence than any model previously assessed. The institute said frontier model capabilities are doubling every 4 months, compared to every 8 months previously. OpenAI also announced scaling up their Trusted Access for Cyber program last night, reinforcing the view that accelerating cyber capability is not limited to one company. Ministers said businesses should plan for frontier Artificial Intelligence model capabilities to rise rapidly over the next year.

The government highlighted its own response, pointing to the AI Security Institute as a core capability for independently assessing frontier Artificial Intelligence systems. It also cited the National Cyber Security Centre’s guidance for businesses, the Cyber Security and Resilience Bill currently progressing through Parliament, and plans to publish a National Cyber Action Plan. These measures are intended to strengthen protections for critical services and support the UK’s national security against cyber threats.

Business leaders were urged to treat cyber security as a matter for boards and senior management rather than something delegated entirely to information technology teams. Organisations were encouraged to use the Cyber Governance Code of Practice, while smaller businesses were directed to the NCSC’s Cyber Action Toolkit. Ministers also stressed the need to prepare for incidents through planning and rehearsal, and noted that free cyber insurance is available to small organisations that obtain Cyber Essentials.

The practical advice focused on established cyber hygiene rather than new or specialised defences. Businesses were told to get the basics right with Cyber Essentials, which addresses common weaknesses such as outdated software, weak passwords, and missing backups. They were also encouraged to embed Cyber Essentials requirements across supply chains, with larger organisations directed to use the NCSC’s Cyber Assessment Framework. In addition, organisations were urged to follow NCSC guidance and sign up for the Early Warning service, which provides alerts on potential cyber attacks so action can be taken before incidents escalate.

54

Impact Score

UK and EU Artificial Intelligence regulatory outlook for May 2026

The UK is moving ahead with targeted Artificial Intelligence measures in policing, online safety, cyber security and copyright policy, while the EU is refining how the EU Artificial Intelligence Act will apply in practice. Consultations, new offences and implementation deadlines are shaping the next phase of compliance on both sides.

Germany sets out national implementation of the Artificial Intelligence Act

Germany has published a draft law to implement the European Artificial Intelligence Act through new supervisory structures, clearer institutional responsibilities, and measures designed to support innovation. The proposal puts the Federal Network Agency at the center of enforcement while preserving sector-specific oversight in sensitive fields.

ECB warns banks about new Artificial Intelligence security risks

The European Central Bank has called major banks to an emergency meeting over cybersecurity risks tied to advanced Artificial Intelligence models. Regulators want banks to speed up security updates as newer tools make it easier to find and exploit vulnerabilities.

Anthropic keeps Mythos restricted after vulnerability findings

Anthropic says its cybersecurity model Mythos is powerful at uncovering software flaws but remains too risky for broad release. Early testing found large numbers of vulnerabilities across major software and open source projects, while fixes have lagged far behind discoveries.

Nvidia targets the CPU market

Nvidia is broadening its semiconductor strategy beyond graphics processors and positioning its CPU business as a major new growth area. The company’s market forecast also highlights China as a key part of its long-term opportunity despite ongoing export restrictions.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.