Skip to content

Why agentic AI is rewriting the rules of cyber defence

1 October 20265 min read
Guest Insights
Decorative image — no alt text needed

Cyber defence has always been a numbers game, decided by the volume and skill of the experts on either side. That equation is changing, and it is changing faster than most boardrooms can keep pace with. Many have yet to register the full scale of the threat.

Autonomous, agentic AI systems are dismantling the expert-scarcity constraint that once limited how many offensive operations could run at once. For UK businesses, particularly those operating in defence, government-adjacent, and other high-stakes sectors, the implications are both significant and immediate. This is not a distant, theoretical risk.

Threat researchers have already recovered an autonomous multi-agent framework, built on publicly available architectures, that ran intrusion campaigns against government entities in Asia. Over four days, it executed twelve attack waves using eight parallel AI agents, compromised 85 government accounts, and used a closed learning loop to adapt after each failure.

This was not a self-improving model tinkering in a lab. It was a self-adapting attacker, assigning confidence scores to each discovery and pivoting the moment a path failed. This case study should be a wake-up call for every CISO, CTO, and procurement head. The economics of offence have shifted, and our resilience strategies must shift to meet them.

Securing systems against agentic AI models

Agentic AI systems do not simply execute pre-scripted tasks. They reason, adapt, and pursue goals with increasing independence, which is precisely what makes them powerful and unpredictable in equal measure. The National Cyber Security Centre (NCSC) has already flagged incidents involving AI models and agentic systems carrying out unsanctioned activity, and this list will grow substantially over the next twelve months.

An AI agent lacks human common sense. It may interpret an instruction literally, in a way its designers never anticipated, and when that agent holds broad access to networks or credentials, the consequences of a malfunction scale accordingly. The NCSC calls this an agent's "blast radius": the total impact possible if it accesses information it should not or acts beyond its intended scope.

UK organisations built on decades of interconnected legacy applications are particularly exposed. Attacks rarely hinge on one critical vulnerability; they succeed by chaining together ordinary ones, continuously, at a scale no human red team could match. Any business that treats its threat model as static is defending against an adversary that no longer exists.

Securing the agents we deploy

Here the conversation too often stalls. We discuss defending against agentic AI but spend far less energy scrutinising the agents we ourselves put into production. Every agentic system a business deploys is a new attack surface and deserves the same rigour as any other privileged system.

That starts with an honest assessment of how much autonomy a deployment requires, and matching controls to risk tolerance rather than convenience. Sandboxing matters enormously: agents should operate within tightly scoped network access, compute, credentials, and data, following a maturity model ranging from unrestricted access at the lowest end to fully isolated, locally hosted models at the highest.

Oversight should reflect the consequences of unexpected behaviour, not operational expedience, and none of this works without observability built in from day one: chain-of-thought traces, sandbox logs, and network telemetry feeding into round-the-clock operations with immutable logging. Every organisation must retain the ability to halt agentic activity immediately the moment something looks wrong.

AI as a tool for defensive security

It would be a mistake to leave this discussion purely defensive, because the same technology reshaping the threat landscape offers UK businesses a genuine structural advantage.

Unlike an attacker, which must steal its map of an environment one probe at a time, defenders already possess it. Every configuration, credential, and trust relationship belongs to us by default. The constraint has never been merely access to information; it has been human capacity to reason over it, continuously, at speed.

Agentic AI begins to remove that constraint, amplifying expert judgement across thousands of investigations in parallel. The real competitive question is no longer how many security experts each side can field, but how effectively each side scales that expertise into verified outcomes.

Addressing the sceptics

Some will argue that agentic AI introduces its own governance burden, and that many mid-sized UK businesses lack the resource to build sandboxing, observability, and shutdown protocols to this standard. That concern is valid, which is precisely why this cannot be delegated to IT alone. It requires board-level sponsorship and a willingness to start smaller with well-governed deployments rather than waiting for a perfect solution that never arrives. Businesses that delay entirely are the ones most exposed to adversaries already operating at machine speed.

Concrete measures for UK organisations

Enhance AI threat detection capabilities. Modernise your security infrastructure to detect and respond to threats originating from agentic AI systems. This includes deploying advanced intrusion detection systems capable of identifying abnormal patterns in real time, such as unusual lateral movement or AI-driven probing activities.

Adopt proactive vulnerability management. Strengthen your defence by conducting regular penetration testing and vulnerability scans tailored to counter AI-specific attacks. These exercises should simulate the adaptive strategies used by autonomous agents to uncover chained vulnerabilities in your systems.

Implement dynamic threat modelling. Shift from static to dynamic threat models that can reflect the evolving nature of AI-driven attacks. Continuously update these models based on the latest intelligence, allowing your organisation to anticipate and mitigate emerging threats before they materialise.

Invest in incident response readiness. Develop and maintain an incident response framework specifically designed to counter AI-driven cyberattacks. This should include playbooks that account for the speed and scale of agentic systems, ensuring your teams can contain and neutralise threats rapidly.

Foster cross-industry collaboration. Collaborate with other organisations and industry bodies to share intelligence on AI-driven threats. By contributing to and leveraging collective insights, businesses can stay ahead of adversaries that repurpose existing frameworks for malicious activities.

Don’t sit and watch from the sidelines

Agentic AI is not a distant consideration for UK organisations; it is an active force reshaping both the threat landscape and the tools available to counter it. At SecureCloud+, we believe this moment calls for decisive action, not caution dressed up as prudence. The businesses that build governance, sandboxing, and observability practices now will turn AI's potential into lasting resilience. The question is no longer whether agentic AI changes the rules of cyber defence. It already has. The question is who is prepared to lead now the rules have been rewritten.