
Concern over access to frontier AI models peaked recently when the US imposed a temporary export ban imposed on Anthropic’s Mythos 5 and Fable 5. While it has since been revoked, the ban focused hearts and minds on the need to develop sovereign alternatives, and with good reason.
Approximately 75% of the world’s total compute capacity for AI rests in the USA’s hands, compared to 15 percent in China and just 10 percent in Europe, according to the Tony Blair Institute for Global Change, with the report also claiming the French Mistral AI model is the most developed in Europe. But it’s the UK and Germany that lead the field when it comes to AI in defence, with both pledging billions in defence spending in their annual reviews.
In the UK, the government has further announced its intention to create a Cyber Shield. This will be “a new national cyber defence capability that will hardwire cutting-edge agentic AI into machine-speed cyber defence”, according to GCHQ Director, Anne Keast-Butler. The intention is for the Cyber Shield to be developed in tandem with network defenders, with core capabilities expected to include federated agents, automated vulnerability discovery and mitigation, coordinated detection and response, and automated scanning and mitigation at the national level, states a blueprint released by the NCSC.
Where cyber is struggling with AI
All well and good so far, except there’s been very little detail on how the government plans to get the cyber security sector on side. Most of the AI capabilities we’ve seen thus far have seen AI bolted onto existing solutions rather than being built from the ground up. There’s been a noticeable reluctance to invest the time and resources into building AI native tools because AI rewrites the security rulebook. To provide detection and response, for example, you can’t use the same processes. You need to completely rethink how those processes work and reorganise them.
Consider that stalwart of defence, the Security Operations Centre (SOC). The AI SOCs that we see on the market today continue to be organised around the alert queue. When an alert is triggered, a case is opened and an investigation begun which is then overseen by either a human or an AI agent. AI is hugely useful in this context as it can provide triage, enrichment, summarisation, correlation and make recommendations BUT it sees AI used after the fact.
If we reverse that approach so that the alert comes at the end rather than the beginning, with AI involved from the outset, the process is completely upended. It’s a crucial distinction and one that could well make the difference between a SOC that is able to fend off a rising tide of AI-driven attacks and those that flounder because the response window is shrinking, so that by the time an alert comes through, the events that caused it have already happened.
In the traditional alert-driven process, the analyst has to work backwards to tap into the data to be found in raw telemetry, process trees, authentication flows, network sessions, package execution traces, cloud control-plane activity, endpoint state and identity context. That process of alert->case->investigation doesn’t change, it just gets a jet boost from AI. So, while it does become faster, it still sees the SOC working against the clock to piece together the jigsaw of what’s happened, when and what the response should be.
Putting AI at the start
If, however, we insert AI earlier in the process, we see the SOC transformed. As AI reasoning happens closer to the event stream, the causal state is preserved. Behavioural detection runs continuously which means it can provide structured context, rather than needing to be recreated on demand after the alert. Detection engineering also moves up, with rules that express patterns on the stream as well as against the store, and that provides some groundbreaking capabilities. Chief among them is that threat hunting can be carried out continuously instead of at a specific point-in-time, paving the way for a zero-day approach whereby threats are identified and headed off before they can be realised and become incidents.
Of course, none of this is easy to achieve. It requires the SOC to be completely re-engineered. But doing so allows every facet of the SOC to perform to the best of its ability. We see AI used upfront to provide rapid correlation, lookups, hypothesis generation, causal timeline drafting, and next questions. We allow the analyst to make the judgement call, apply business context, regulatory awareness and to take accountability. And the Security and Incident Event (SIEM) platform at heart of the detection and response process remains the system of truth that can be relied upon for the retention of data, forensic search, evidencing compliance and regulator records.
Rejigging the process makes a fundamental difference because the AI is not waiting for the SIEM to turn the event into a story that then fires the alert before it’s able to weigh-in. It also doesn’t see AI given control over the process.
How AI can create new perspectives
AI is then used as a facilitating tool and one that is subject to scrutiny. Several AI models are used, each with specific expertise in threat identification, risk scoring, MITRE ATT&CK mapping, forensic planning, log comprehension, and hunt query consensus. This then allows these models to cross-check every investigation from different perspectives. In the event the counsel of agents disagrees, the analyst is able to see exactly where and why that happened and to make the final call.
This concept of a Zero-Day SOC holds huge potential in that it could see not just commercial organisations but critical national infrastructure (CNI) providers also protected under the Cyber Shield. In critical environments, a customer dedicated LLM could be trained on that specific infrastructure and even used to spin up a digital twin. Twinning the customer environment by using passive discovery across IT and operational technology (OT) systems then enables safe attack simulation, risk identification before exploitation and immutable preservation of analytical integrity without endangering real operations.
In summary, the Zero-Day SOC sees AI not just relocated but used in numerous new ways. We have a local model to handle environment-specific detection and analysis, a counsel of models that act as a security intelligence layer to aggregate and correlate threat data at scale, and a frontier model for non-sensitive enrichment and analytical tasks. Plus putting AI closer to the action means live threat intelligence can be applied immediately as detection rules, eliminating the risk from emerging threats and even preventing incidents from happening.
What this all goes to illustrate is that advocating the development of a Cyber Shield is all well and good but it will require so much more than enlisting cyber security partners. Existing cyber processes can’t just be bolted to AI and expected to deliver sovereignty. To do that, they must be painstakingly re-engineered and use each of the technologies at our disposal to the best of their abilities. It is achievable – all those capabilities described above are with us today – but the UK government needs to throw its support behind those committing to this R&D and not just be seduced by start-ups or snake oil solutions.



