What happened
On 21 September 2026, the UK National Cyber Security Centre published a blog by Dave Chismon, 'One does not simply defend agentically', setting out the NCSC's position on agentic cyber defence. It argues defenders cannot use AI the same way attackers do and instead must solve the problem by explicitly considering constraints. The post confirms the NCSC and DCMS are jointly building 'Cyber Shield', a national-scale agentic cyber defence ecosystem, and announces the forthcoming publication of an 'AI for Cyber Defence' problem book delineating research areas needed to unlock agentic defensive actions.
Why it matters
This is authoritative national guidance from the UK NCSC on how defender organisations should approach agentic AI — the nominal counterweight to the well-documented attacker-side use of agentic tooling. It frames the research agenda (via CETAS work on Autonomous Cyber Defence, the Cyber Shield ecosystem and the upcoming problem book) that will inform future NCSC guidance and UK defensive investment. It signals where NCSC expects autonomous defensive actions to be made possible and where they should remain human-gated.
Action needed
SOC and cyber-defence leaders should monitor the NCSC's forthcoming 'AI for Cyber Defence' problem book and factor the defender-specific (rather than attacker-mimicking) framing into their agentic defence roadmaps.