Skip to content

The AI evolution in public sector cyber security

Ukauthority • November 11, 2025

AI is rewriting the public sector’s cyber playbook writes Marc Lueck, EMEA CISO-in-residence at Zscaler, introducing a new UKAuthorITy research paper on quickly evolving threats and opportunities

Artificial intelligence (AI) is changing the terms of engagement for cyber security in the public sector. Its rise is rapid, its potential undeniable, and its risks increasingly visible.

Digital and cyber leaders across central government, the NHS and local government now face a dual challenge: harness AI to strengthen defences against AI-powered attack, while ensuring that it does not become a tool internally that outpaces their ability to manage risk.

Zscaler has collaborated with UKAuthorITy to research the main factors on how AI is being used to attack the sector, defend the sector, and the new risks its use within the organisation brings. A series of roundtable discussions with leaders from across the public sector in the early summer of 2025 explored how AI is fundamentally changing the cyber challenge today.

The National Cyber Security Centre (NCSC) has previously identified some of the key threats, including that AI provides a capability uplift in reconnaissance and social engineering that can be used by threat actors, almost certainly making attacks easier to create, more effective and harder to detect.

There was consensus in the roundtable discussions that this threat is evolving fast. AI is making phishing more convincing, enabling faster exploitation of vulnerabilities and giving attackers new ways to exfiltrate and weaponise data. The spread of “intrusion tools as a service” has indeed lowered the barriers to entry, expanding the number of actors able to launch attacks and create, for example, sophisticated ‘deep fakes’ with ease.

And while organisations grapple with these external risks, the growth of shadow AI - employees using tools without authorisation or oversight - has further weakened the defensive perimeter. Raising the risk of data loss as enthusiastic users have failed to consider ‘where’ that data is being sent and processed.

Suppliers, too, are embedding AI into their solutions. Whilst this brings welcome opportunities for efficiency and innovation it also fuels anxieties new vulnerabilities and unknowns in the supply chain.

The discussions conveyed a widespread acceptance that the use of shadow AI and AI within line of business applications is increasing, and that this is creating an accumulation of risk that is difficult to monitor, let alone control.

Yet AI is not just a threat - it has also emerged as a powerful defensive opportunity.

Leading edge cyber security suppliers like Zscaler are embedding AI into their solutions. And such AI-powered deployments have demonstrated immense value in anomaly detection within vast amounts of data - enabling human-like response at inhuman speed - monitoring network activity in real time, analysing generative AI prompts to block risky use, preventing data loss at the edge as it happens and microsegmenting workflows and applications.

It can also enhance and reinforce zero trust strategies, preventing lateral movement and automating cyber deception techniques. Zero trust was seen as a foundational approach, albeit difficult to deploy at times in a sector beset by legacy infrastructure and systems. However, the latest solutions such as Zscaler’s Zero Trust Exchange platform, can extend into all corners of an organisation’s digital estate to strengthen the application of zero trust throughout. It enables secure connectivity across users, applications, devices, clouds, and office locations with better visibility and experience - no matter how complex or distributed the environment. It can effectively make an organisation ‘invisible’ to bad actors whilst ensuring that there can be no lateral movement through the organisation if there was an attack.

People, governance and education remain central to ensuring resilience. The skills gap persists in line with the public sector’s budgetary constraints, and there is a view that training and nurturing skills in house is key across the sector. Alongside this is the need to raise AI literacy across the workforce - backed by creation and socialisation of robust acceptable AI use policies.

To defend against data loss it is relatively easy to block entirely the use of any AI tooling deemed a risk, but leaders are mindful of the enormous benefits AI can bring to the transformation of public services. Increasingly the aim therefore is to encourage exploration but to provide a safety net as outlined above to monitor prompts and prevent data loss.

Another human factor, collaboration, was seen as the force multiplier. The Government’s Defend as One strategy, in particular the approach taken by the Ministry of Housing Communities and Local Government for councils, underlines how communication, shared intelligence and best practice can strengthen resilience – ensuring that newly identified threats and lessons learned in one organisation can quickly benefit others.

AI then is neither silver bullet nor existential threat. It is a capability that must be managed, integrated and overseen. The public sector’s challenge therefore is to strike the balance - encouraging innovation and exploration of AI’s potential to transform public services whilst keeping control, and embedding it into the mix of technology, governance and human judgement that underpins cyber resilience.

UKAuthorITy and Zscaler have published the findings from their research in a new report, Public sector cyber security in the age of AI . It provides a clear-eyed assessment from the front line today of the risks and opportunities, and of the approach needed to sustain trust in public services in this era of AI.

Extracted Entities

Attack Types (1)

Industries (1)

Platforms (1)