GCHQ Director Anne Keast-Butler spoke at Bletchley Park this month to announce what is described as the world’s first national AI-enabled cyber defence capability, designed to detect and respond to threats targeting critical national infrastructure. The programme would use agentic AI to identify suspicious activity and accelerate response operations across national infrastructure environments, with a deployment timeline of up to five years.¹
The response from some quarters has been enthusiastic. One commentator summarised the announcement as proof that the only way to survive an AI-driven storm is to build an AI-driven shield. That framing is intuitive, widely shared, and wrong.
The fight-AI-with-AI argument rests on a premise that the problem is purely one of speed and scale. Attackers use AI to move faster, therefore defenders must use AI to respond faster. The arms race logic is seductive. It is also incomplete, because speed is not the only problem and a faster version of the same approach does not resolve the structural failure.
The structural failure is this: consequential actions are executing without verified human authority. An AI defensive system that detects threats faster and responds autonomously is still operating downstream of execution. It is still in the business of catching damage after it occurs or containing it after it starts. And an AI defensive system making autonomous decisions at machine speed introduces its own governance problem: who authorised the AI defender to take that action? The execution boundary problem does not disappear because the actor on the other side is an AI defender rather than an AI attacker.
The expert commentary in the original article makes this point indirectly. Jacob Krell from Suzu Labs notes that the ICO fined South Staffordshire Water after investigators found 20 months of undetected adversary access and five percent monitoring coverage. An AI overlay watching five percent of the network is still blind to the other ninety-five. A faster AI watching five percent is still blind to the other ninety-five. The monitoring coverage problem is not solved by accelerating the monitor.
Keast-Butler herself acknowledged the threat represents a narrowing window and a moment of consequence. A programme with a five-year deployment timeline is not calibrated to a narrowing window. CNI operators cannot wait five years for a national AI shield while facing daily hybrid activity from Russian state actors, Iranian proxies, and Chinese strategic campaigns that are patient, persistent, and already inside many of the networks they are targeting.
The GCHQ programme is valuable and should be built. National-level AI-enabled threat detection across CNI sectors will improve the collective defensive picture. But it operates at the national visibility layer. It does not sit at the execution boundary of individual organisations. It does not require a named human authority to confirm a consequential action before it proceeds. It does not prevent the attacker who is already inside a network from executing the action that causes the irreversible harm.
The South Staffordshire Water incident is the clearest illustration. Twenty months of undetected access. Five percent monitoring coverage. An AI-driven national shield, had it existed, might have shortened the detection window. It would not have prevented a consequential action from executing during those twenty months if no execution boundary control was in place. The attacker inside the network, with valid credentials and legitimate-looking behaviour, still faces no confirmed authority requirement before acting.
GoFirm operates at exactly that boundary. Before any high-consequence action executes across a CNI operator’s environment, whether initiated by a human, an AI agent, or a compromised system, GoFirm requires a confirmed biometric response from the named human authority on their registered personal device through a channel separate from the operational environment. The attacker inside the network cannot produce that confirmation. The action stops.
The national AI shield and the execution boundary control are complementary, not competing. The shield improves collective visibility and accelerates national response. The execution boundary ensures that even when visibility fails, even when the attacker is already inside, the consequential action cannot proceed without confirmed human authority.
Building a faster AI to fight a faster AI is necessary. It is not the only answer. The organisations that survive the AI-driven storm will be the ones that also built the control that stops the action before the damage, not just the one that detects it afterwards.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. Intelligent CIO Europe, UK GCHQ develops AI-enabled national cyber defence capability to protect critical infrastructure, June 2026, https://www.intelligentcio.com/eu/2026/06/01/uk-gchq-develops-ai-enabled-national-cyber-defence-capability-to-protect-critical-infrastructure/
