Britain’s legacy technology is already being exposed by rapid advances in AI, GCHQ director Anne Keast-Butler has warned, as the country faces an increasingly acute mix of cyber and hybrid threats.
Speaking at Resilience Conference, Keast-Butler said significant developments in AI models were beginning to reveal weaknesses in the technology underpinning organisations across the UK and Europe.
“[In May] we were at a moment of consequence, and that moment has only got sharper,” she said. “In technology, we’re seeing really significant developments in the models that are out there. They are starting to really expose vulnerabilities in legacy tech that we’re all sitting on.”
Keast-Butler said the focus should be not only on what new technology can do, but on whether the systems beneath it are secure enough to withstand emerging threats.
“Are we really on sure enough foundations, and how can our adversaries take advantage of those gaps in those foundations?” she said, adding that such activity was already being seen “at a scale in the UK and in Europe”.
The warning came as GCHQ and the UK’s Cyber and Specialist Operations Command (CSOC) urged defence and industry to rethink how they prepare for cyber attacks, arguing that resilience increasingly means being able to recover quickly when systems are breached rather than assuming every compromise can be prevented.
General Sir Rob Magowan, commander of CSOC, said the changing threat environment was forcing defence away from a relatively static approach to managing cyber risk.
“We are rapidly moving from a fairly static defend-on-the-data-goal-line, managing our cyber risk, to one of much greater fluidity, accepting that we’re going to be compromised,” he said.
The result, he added, was a greater emphasis on “agility and resilience and redundancy and adaptability” rather than attempting to “close everything down.”
Keast-Butler stressed that this did not mean organisations should simply accept being hacked. Failures to address basic security weaknesses, she warned, would leave organisations increasingly exposed.
“Where we haven’t got our basics right, we are leaving ourselves open to attack, and we are not going to be as resilient as we know we need to be,” she said.
The warnings come against a threat environment that both officials said was becoming more serious. Magowan said Russia was testing NATO in the “hybrid zone,” including through cyber activity occurring on a “daily basis, minute-by-minute basis in certain areas.”
“We should be under no illusion of what we’re facing,” he said, describing the current threat as the most serious of its nature since the end of the Cold War.
The agencies are also pushing for a closer relationship with Britain’s technology sector. Keast-Butler said intelligence about adversaries was no longer confined within government and called for a shift away from simply buying technology towards a “much more integrated ecosystem” with industry.
That could require traditionally-guarded parts of the national security establishment to open up. Magowan argued that government and industry should increasingly work physically alongside one another, use the same systems and share information where security clearances allow.
“We should be sharing workforce across the boundary,” he said. “We’ve got to take a bit more risk across that industry, security and defence boundary.”
Ukraine is already demonstrating what that increasingly integrated battlefield looks like. Keast-Butler said GCHQ was bringing Ukrainian AI lessons into the UK to examine the data and inform its own planning, while stressing that cyber operations can no longer be viewed separately from conventional warfare.
“There is no kinetic activity without cyber around it,” she said, “either defending it or supporting it.”













