NCSC publishes agentic AI guidance for cybersecurity teams

Published: 24/09/2026
| NCSC

The National Cyber Security Centre (NCSC) has published new guidance on deploying agentic artificial intelligence (AI) for cyber defence. 

The guidance highlights a fundamental asymmetry between offensive and defensive operations. Threat actors face predominantly technical challenges with clearly defined success states, such as deploying exploits, avoiding detection, stealing funds, or exfiltrating data to generate profit. As a result, offensive operations can easily make use of agentic AI to achieve quantifiable technical objectives.

In contrast, defensive security operations are primarily constrained by organisational and political challenges, including budgets, resource allocation, and operational approvals. Because cyber defence represents a cost of doing business rather than a core mission, defensive measures must compete with broader corporate priorities. Boards must evaluate security spending against business requirements, ensuring that addressing vulnerabilities does not impede critical operations or result in system downtime similar to a cyberattack.

Furthermore, because defensive issues lack simple technical success rates and carry operational liability, defenders cannot deploy autonomous tools the same way attackers can. The NCSC notes that organisations approach AI implementation differently, stressing that defensive teams must account for organisational constraints when automating technical defence tasks. The guidance examines the range of defensive tasks and how to use AI automation. It highlights the need to establish robust human oversight while evaluating technical mechanisms alongside system vulnerabilities.

In a related article, the Organisation for Economic Co-operation and Development (OECD) considers real-world situations where agentic AI is already being used effectively. 


Training Announcement: The BCS Foundation Certificate in AI examines the challenges and risks associated with AI projects, such as those related to privacy, transparency and potential biases in algorithms that could lead to unintended consequences. Explore the role of data, effective risk management strategies, compliance requirements, and ongoing governance of the AI lifecycle and become a certified AI Governance professional. Find out more.

Read Full Story
artificial intelligence, ai security

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.